CVE-2020-3280 | Cisco Unified CCXÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-05-22

0x00 Îó²î¸ÅÊö


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


0x01 Îó²îÏêÇé

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



Cisco Unified Contact Center Express£¨Unified CCX£©ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»¿îͳһͨѶ½â¾ö¼Æ»®ÖеĿͻ§¹ØÏµÖÎÀí×é¼þ ¡£¸Ã×é¼þÖ§³Ö×ÔÖúÓïÒô·þÎñ¡¢ºô½Ð·ÖÅɺͿͻ§»á¼û¿ØÖƵȹ¦Ð§ ¡£

2020Äê5ÔÂ20ÈÕ˼¿Æ£¨Cisco£©¹Ù·½Ðû²¼Í¨¸æ £¬ÐÞ¸´ÁËÒ»¸öUnified Contact Center Express£¨Unified CCX£©ÖеÄÑÏÖØÎó²î£¨CVE-2020-3280£© ¡£¸ÃÎó²îÔ´ÓÚCisco Unified CCX ÔÚÖ´Ðз´ÐòÁл¯²Ù×÷ʱ £¬JavaÔ¶³ÌÖÎÀí½çÃæÃ»ÓжÔÓû§ÊäÈë¾ÙÐÐÑéÖ¤ £¬µ¼Ö¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏ·¢ËÍÒ»¸ö¶ñÒâµÄJava¹¤¾ß £¬²¢ÔÚÊÜÓ°Ïì×°±¸ÉÏÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë ¡£


0x02 ´¦Öóͷ£½¨Òé


˼¿Æ¹Ù·½ÒѾ­Ðû²¼Ð°汾ÐÞ¸´ÁËÕâЩÎó²î £¬ÇëÏà¹ØÓû§¾¡¿ìÉý¼¶¾ÙÐзÀ»¤ £¬ÆäÖÐCiscoUnified CCX 12.0(1)ES03ºÍCisco Unified CCX 12.5°æ±¾²»ÊܸÃÎó²îÓ°Ïì ¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN


0x03 Ïà¹ØÐÂÎÅ


https://www.zdnet.com/article/cisco-critical-java-flaw-strikes-call-center-in-a-box-patch-urgently/#ftag=RSSbaffb68


0x04 ²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN


0x05 ʱ¼äÏß


2020-05-20 Cisco¹Ù·½Ðû²¼Í¨¸æ

2020-05-22 VSRCÐû²¼Îó²îͨ¸æ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!