¡¾·ì϶¹«¸æ¡¿Ruckus Wireless AdminÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-25717£©

°ä²¼¹¦·ò 2023-05-15

Ò»¡¢·ì϶¸ÅÊö

CVE   ID

CVE-2023-25717

·¢ÏÖ¹¦·ò

2023-05-10

Àà    ÐÍ

RCE

µÈ    ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

¹¥»÷¸´ÔÓ¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

ÊÇ

 

5ÔÂ10ÈÕ£¬GA»Æ½ð¼×VSRC¼à²âµ½FortiGuard Labs°ä²¼Íþв²¼¸æ£¬Åû¶ÁËRuckus Wireless Admin RCE·ì϶£¨CVE-2023-25717£¬CVSSv3ÆÀ·Ö9.8£©ÔÚ±»AndoryuBot½©Ê¬ÍøÂç»ý¼«ÀûÓã¬ÒÔÌáÒéÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷¡£

ÓÅ¿ÆÎÞÏß¹«Ë¾£¨Ruckus Wireless£©ÊÇÒÆ¶¯ÍøÂçÊг¡ÉϳÛÃûµÄÎÞÏßϵͳ¹©¸øÉÌ¡£¸Ã¹«Ë¾ÃæÏòÈ«ÇòÒÆ¶¯ÔËÓªÉÌ¡¢¿í´ø·þÎñÌṩÉÌºÍÆóÒµÓû§£¬Ôì×÷¡¢ÏúÊÛ¸÷ÀàÊÒÄÚºÍÊÒ±íÐÍ¡°ÖÇÄÜWi-Fi¡±²úÆ·¡£

Ruckus Wireless Admin Ãæ°å°æ±¾<=10.4ÖдæÔÚRCE/CSRF·ì϶£¨CVE-2023-25717£©£¬Äܹ»Í¨¹ýÏòÒ×Êܹ¥»÷µÄÉ豸·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄHTTP GETÒªÇóÀ´Ö´ÐдúÂ룬»òÀûÓÃCSRF·ì϶ÔÚÖ¸±êÉ豸ÉÏÖ´ÐдúÂ룬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼Ö½ÚÔì»ò·ÛËéÒ×Êܹ¥»÷µÄRuckus Wireless APÉ豸¡£Ä¿Ç°¸Ã·ì϶µÄPoCÒѾ­¹«¿ªÅû¶¡£


¶þ¡¢Ó°ÏìÁìÓò

¸Ã·ì϶ӰÏìÁËÒÔÏÂRUCKUS APÐͺţ¨²¿ÃÅÊÜÓ°Ïì²úÆ·ÒѾ­ÖÕ³¡Ö§³Ö£©£º

RUCKUS H350

RUCKUS H550

RUCKUS R350

RUCKUS T350c

RUCKUS T350d

RUCKUS T350se

RUCKUS T811-CM (Non-SFP)

Ruckus E510

Ruckus H320

Ruckus H500

Ruckus H510

Ruckus M510

Ruckus M510-JP

Ruckus P300

Ruckus Q410

Ruckus Q710

Ruckus Q910

Ruckus R300

Ruckus R310

Ruckus R320

Ruckus R500

Ruckus R510

Ruckus R550

Ruckus R560

Ruckus R600

Ruckus R610

Ruckus R650

Ruckus R700

Ruckus R710

Ruckus R720

Ruckus R730

Ruckus R750

Ruckus R760

Ruckus R850

Ruckus T300

Ruckus T301n

Ruckus T301s

Ruckus T310c

Ruckus T310d

Ruckus T310n

Ruckus T310s

Ruckus T504

Ruckus T610

Ruckus T710

Ruckus T710s

Ruckus T750

Ruckus T750SE

Ruckus T811-CM

SmartZone 100 (SZ-100)

SmartZone 144 (SZ-144)

SmartZone 144 (SZ-144) - Federal

SmartZone 300 (SZ300)

SmartZone 300 (SZ300) - Federal

ZoneDirector 1000

ZoneDirector 1100

ZoneDirector 1200

ZoneDirector 3000

ZoneDirector 5000

 

Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

RuckusÒÑÓÚ2Ô½¨¸´½¨¸´Á˸÷ì϶£¬¼øÓڸ÷ì϶ÀûÓÃÄѶȽϵÍ£¬ÇÒ·ì϶PoCÒѾ­¹«¿ªÅû¶£¬½¨ÒéÈÔ佨¸´¸Ã·ì϶µÄÓû§¿É²Î¿¼¹Ù·½²¼¸æ»ñÈ¡ÏàÓ¦²¹¶¡ÒÔ½¨¸´¸Ã·ì϶¡£

ÏÂÔØÁ´½Ó£º

https://support.ruckuswireless.com/security_bulletins/315

3.2 һʱ´ëÊ©

²»Ê¹ÓÃʱÄܹ»½ûÓÃRUCKUS APÉ豸µÄÔ¶³ÌÖÎÀíÃæ°å½Ó¼û¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£

3.4 ²Î¿¼Á´½Ó

https://support.ruckuswireless.com/security_bulletins/315

https://www.fortiguard.com/threat-signal-report/5151/exploitation-spike-observed-for-ruckus-wireless-admin-rce-vulnerability-cve-2023-25717

https://cybir.com/2023/cve/proof-of-concept-ruckus-wireless-admin-10-4-unauthenticated-remote-code-execution-csrf-ssrf/

https://www.bleepingcomputer.com/news/security/critical-ruckus-rce-flaw-exploited-by-new-ddos-botnet-malware/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-05-15

³õ´Î°ä²¼

  

Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png