¡¾·ì϶¹«¸æ¡¿Juniper Networks SBRÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-0276£©

°ä²¼¹¦·ò 2021-07-19

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2021-0276

ʱ    ¼ä

2021-07-19

Àà    ÐÍ

RCE

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

 

2021Äê7ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬Juniper Networks°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬ÆäSteel-Belted Radius Carrier Edition£¨SBRÔËÓªḚ́棩ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-0276£©£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£ ¡£¡£

µçÐÅÔËÓªÉÌͨ¹ýSBRÖÎÀíÓû§½Ó¼ûÆäÍøÂçµÄÕ½Êõ£¬£¬£¬£¬£¬£¬Í¨¹ý¼¯ÖÐÓû§ÈÏÖ¤¡¢ÌṩÊʵ±µÄ½Ó¼û¼¶±ð²¢È·±£×ñÊØ°²È«Õ½Êõ¡£¡£¡£¡£¡£¡£ ¡£¡£ËüʹÔËÓªÉÌ¿ÉÄÜÌṩ²î¾à»¯µÄ·þÎñˮƽ£¬£¬£¬£¬£¬£¬²¢ÖÎÀíÍøÂç×ÊÔ´¡£¡£¡£¡£¡£¡£ ¡£¡£

ÓÉÓÚÅäÖÃÁËEAP£¨¿ÉÀ©´óÈÏÖ¤ºÍ̸£©Éí·ÝÈÏÖ¤µÄJuniper Networks SBRÖдæÔÚÒ»¸ö»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶·¢ËÍÌØ¶¨µÄÊý¾Ý°ü£¬£¬£¬£¬£¬£¬µ¼ÖÂradiusÊØ»¤¹ý³Ì±ÀÀ££¬£¬£¬£¬£¬£¬´Ó¶øÔì³É»Ø¾ø·þÎñ£¨DoS£©»òÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¡£¡£¡£ ¡£¡£

³É¹¦ÀûÓô˷ì϶½«µ¼ÖµçÐÅÌṩÉÌ£¨Ô̺¬ÎÞÏßÔËÓªÉÌ£©Ãæ¶ÔÍøÂç·þÎñÖжϻòÆäËü·çÏÕ¡£¡£¡£¡£¡£¡£ ¡£¡£µ«¸Ã·ì϶½öÔÚʹÓüÓÇ¿ÐÍ EAP ÈÕÖ¾ºÍ TraceLevel ÉèÖÃΪ 2 ʱӰÏìÅäÖÃÁË EAP Éí·ÝÑéÖ¤µÄ SBR¡£¡£¡£¡£¡£¡£ ¡£¡£

<SBR_Installed_Directory>/JNPRsbr/radius/radius.ini

[Logging]

LogLevel=2

TraceLevel=2

EnhancedEAPLogging = yes

 

Ó°ÏìÁìÓò

8.4.1 °æ±¾£º< 8.4.1R19

8.5.0 °æ±¾£º< 8.5.0R10

8.6.0 °æ±¾£º< 8.6.0R4

 

0x02 ´ëÖý¨Òé

Ŀǰ´Ë·ì϶ÒѾ­½¨¸´£¬£¬£¬£¬£¬£¬½¨Òéʵʱ¸üÐÂÖÁSBR Carrier 8.4.1R19¡¢8.5.0R10¡¢8.6.0R4»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£ ¡£¡£

ÏÂÔØÁ´½Ó£º

https://support.juniper.net/support/downloads/

 

0x03 ²Î¿¼Á´½Ó

https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11180&cat=SIRT_1&actp=LIST

https://threatpost.com/critical-juniper-bug-dos-rce-carrier/167869/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0276

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-07-19

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

 

0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png      image.png