CVE-2020-3161| Cisco IP PhonesÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-21

0x00 ·ì϶¸ÅÊö


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website




4ÔÂ15ÈÕ£¬£¬ £¬£¬ £¬£¬Ë¼¿Æ°ä²¼°²È«²¼¸æ£¬£¬ £¬£¬ £¬£¬³ÆÆä IP µç»°µÄ web ·þÎñÆ÷ÖдæÔÚÒ»¸öÑϳÁȱµã£¬£¬ £¬£¬ £¬£¬¿Éµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐдúÂë»ò·¢Æð»Ø¾ø·þÎñ¹¥»÷ ¡£¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÓÃÓÚÖÐÓׯóÒµµÄ¶à¸ö˼¿Æ IP µç»°°æ±¾£¬£¬ £¬£¬ £¬£¬CVSSÆÀ·Ö9.8 ¡£¡£ ¡£¡£¡£¡£¡£

¸Ã·ì϶ÊÇÓÉÓÚ²»×ã¶ÔHTTPÒªÇóµÄÕýÈ·ÊäÈëÑéÖ¤ËùÖ ¡£¡£ ¡£¡£¡£¡£¡£ ¹¥»÷Õß½«Ò»¸öÌØÊâ»ú¹ØµÄ HTTP ÒªÇó·¢Ë͵½ /deviceconfig/setActivationCode¶Ëµã£¨ÔÚÖ¸±êÉ豸µÄ web ·þÎñÆ÷ÉÏ£©£¬£¬ £¬£¬ £¬£¬ÔÚ libHTTPService.so ÖУ¬£¬ £¬£¬ £¬£¬/deviceconfig/setActivationCode Ö®ºóµÄ²ÎÊýÓÃÓÚͨ¹ýÒ»¸ö sprint º¯ÊýŲÓô´½¨Ð嵀 URI£¬£¬ £¬£¬ £¬£¬¸Ã²ÎÊý×Ö·û´®µÄ³¤¶È²¢Î´µÃµ½²é³­ ¡£¡£ ¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶ʹ¹¥»÷Õß¿ÉÄÜÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬£¬ £¬£¬ £¬£¬»òµ¼Ö³ÁмÓÔØÊÜÓ°ÏìµÄIPµç»°£¬£¬ £¬£¬ £¬£¬µ¼Ö»ؾø·þÎñ ¡£¡£ ¡£¡£¡£¡£¡£

EXP: https://cxsecurity.com/issue/WLB-2020040100


0x02 ´ëÖý¨Òé


Éý¼¶²¹¶ ¡£¡£ ¡£¡£¡£¡£¡£¬£¬ £¬£¬ £¬£¬ÏÂÔØÁ´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs

һʱ´ëÊ©£º½ûÓà IP µç»°É쵀 web ½Ó¼ûȨÏÞ ¡£¡£ ¡£¡£¡£¡£¡£

ĬÈÏÇé¿öÏ£¬£¬ £¬£¬ £¬£¬Web½Ó¼ûÊǽûÓÃµÄ ¡£¡£ ¡£¡£¡£¡£¡£ ÖÎÀíÔ±Äܹ»Í¨¹ýÒÔϲ½Öè´ÓCisco Unified Communications ManagerÖв鳭Web½Ó¼ûÅäÖãºÑ¡ÔñDevice > Phone > Select a Phone£¬£¬ £¬£¬ £¬£¬¶øºó²é³­Web ½Ó¼ûÊÇ·ñÉèÖÃΪ¡°ÆôÓá±»ò¡°½ûÓá± ¡£¡£ ¡£¡£¡£¡£¡£ ÈôÊǽ«ÆäÉèÖÃΪ¡°½ûÓá±£¬£¬ £¬£¬ £¬£¬ÔòIPµç»°²»»áÊܵ½¹¥»÷ ¡£¡£ ¡£¡£¡£¡£¡£


0x03 ÓйØÐÂÎÅ


https://threatpost.com/critical-cisco-ip-phone-rce-flaw/154864/


0x04 ²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202004-1099


0x05 ¹¦·òÏß


2020-04-15 Cisco°ä²¼²¼¸æ

2020-04-15 CVE°ä²¼¸Ã·ì϶



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website