¡¾·ì϶¹«¸æ¡¿Cisco 10Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-10-28


0x00 ·ì϶¸ÅÊö

2021Äê10ÔÂ27ÈÕ£¬Cisco°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËCisco Firepower Íþв·ÀÓù (FTD)¡¢Cisco˼¿Æ×ÔÊÊÓ¦°²È«É豸 (ASA)ºÍFirepower ÖÎÀíÖÐÐÄ (FMC)ÖеĶà¸ö°²È«·ì϶¡£

 

0x01 ·ì϶ÏêÇé

image.png

ÔÚ±¾´Î½¨¸´µÄ¸ßΣ·ì϶ÖУ¬9¸öΪ»Ø¾ø·þÎñ·ì϶£¬3¸öΪºÅÁî×¢Èë·ì϶£¬ÒÔ¼°1¸öĿ¼±éÀú·ì϶£º

l  CVE-2021-40116£º¶à¸ö Cisco ²úÆ· Snort ¹æ¶¨»Ø¾ø·þÎñ·ì϶£¨CVSSÆÀ·Ö£º8.6£©

l  CVE-2021-34783£ºË¼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍ Firepower Íþв·ÀÓùÈí¼þ»ùÓÚÈí¼þµÄ SSL/TLS »Ø¾ø·þÎñ·ì϶£¨CVSSÆÀ·Ö£º8.6£©

l  CVE-2021-34781£ºË¼¿Æ Firepower Íþв·ÀÓùÈí¼þ SSH Ïνӻؾø·þÎñ·ì϶£¨CVSSÆÀ·Ö£º8.6£©

l  CVE-2021-34752¡¢CVE-2021-34755ºÍCVE-2021-34756£ºË¼¿Æ Firepower Íþв·ÀÓùÈí¼þºÅÁî×¢Èë·ì϶£¨CVSSÆÀ·Ö£º7.8£©

l  CVE-2021-34762£ºË¼¿Æ Firepower ÖÎÀíÖÐÐÄÈí¼þÉí·ÝÑé֤Ŀ¼±éÀú·ì϶£¨CVSSÆÀ·Ö£º8.1£©

l  CVE-2021-40117£ºË¼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍ Firepower Íþв·ÀÓùÈí¼þ SSL/TLS »Ø¾ø·þÎñ·ì϶£¨CVSSÆÀ·Ö£º8.6£©

l  CVE-2021-1573¡¢CVE-2021-34704ºÍCVE-2021-40118£ºË¼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍ Firepower Íþв·ÀÓùÈí¼þ Web ·þÎñ»Ø¾ø·þÎñ·ì϶£¨CVSSÆÀ·Ö£º8.6£©

l  CVE-2021-34792£ºË¼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍ Firepower Íþв·ÀÓùÈí¼þ×ÊÔ´ºÄ¾¡»Ø¾ø·þÎñ·ì϶£¨CVSSÆÀ·Ö£º8.6£©

l  CVE-2021-34793£ºË¼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍ Firepower Íþв·ÀÓùÈí¼þͨÃ÷ģʽ»Ø¾ø·þÎñ·ì϶£¨CVSSÆÀ·Ö£º8.6£©

ÆäÖУ¬CVE-2021-34755 ¡¢CVE-2021-34756ºÍCVE-2021-34752¶¼ÊÇCisco FTD ÖеĺÅÁî×¢Èë·ì϶¡£ÓÉÓÚ¶ÔÓû§ÌṩµÄºÅÁî²ÎÊýÑéÖ¤²»¼°£¬¹¥»÷ÕßÄܹ»Ìá·´Ä¿ÒâÊäÈëÀ´ÀûÓÃÕâЩ·ì϶£¬Ç°2¸ö·ì϶Äܹ»µ¼Ö¾­¹ýÉí·ÝÑéÖ¤µÄ±¾µØ¹¥»÷ÕßÒÔrootȨÏÞÔÚÊÜÓ°ÏìÉ豸µÄϵͳÉÏÖ´ÐÐËÁÒâºÅÁCVE-2021-34752Äܹ»µ¼Ö¾­¹ýÉí·ÝÑéÖ¤ÇÒÓµÓÐÖÎÀíȨÏ޵ı¾µØ¹¥»÷ÕßÒÔrootȨÏÞÔÚÊÜÓ°ÏìÉ豸µÄϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£

CVE-2021-34762ÊÇÓÉÓÚ˼¿Æ Firepower ÖÎÀíÖÐÐÄ (FMC) »ùÓÚWeb µÄÖÎÀí½çÃæ¶Ô HTTPS URL µÄÊäÈëÑéÖ¤²»¼°£¬¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËÍÔ̺¬Ä¿Â¼±éÀú×Ö·ûÐòÁеĶñÒâ HTTPS ÒªÇóÀ´ÀûÓô˷ì϶£¬×îÖÕÄܹ»ÔÚÉ豸É϶ÁÈ¡»òдÈëËÁÒâÎļþ¡£

 

0x02 ´ëÖý¨Òé

ĿǰCiscoÒѾ­°ä²¼ÁËÓйز¹¶¡£¬½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶¸üС£

¾ßÌåÊÜÓ°Ïì²úÆ·¼°Æä°æ±¾ºÍ½¨¸´°æ±¾ÐÅÏ¢Ïê¼ûCisco¹Ù·½°²È«²¼¸æ£º

https://tools.cisco.com/security/center/publicationListing.x

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/publicationListing.x

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-cmdinject-FmzsLN8

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-dir-traversal-95UyW5tk

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-10-28

³õ´Î°ä²¼

 

0x05 ¸½Â¼

GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×¹«Ë¾³ÉÁ¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐÓ×°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·ºÍ°²È«ÖÎÀíÆ½Ì¨¡¢°²È«·þÎñÓë½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ £»²¢ÔÚ»ª±±¡¢»ª¶«¡¢Î÷ÄϺͻªÄϲ¼¾ÖËÄ´óÑз¢ÖÐÐÄ£¬±ðÀëΪ±±¾©Ñз¢×ܲ¿¡¢ÉϺ£Ñз¢ÖÐÐÄ¡¢³É¶¼Ñз¢ÖÐÐĺ͹ãÖÝÑз¢ÖÐÐÄ¡£

¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£


¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png