¡¾Îó²îͨ¸æ¡¿Cisco FMC RADIUS Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-20265)
Ðû²¼Ê±¼ä 2025-08-19Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Cisco FMC RADIUS Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-20265 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-08-19 |
Îó²îÆÀ·Ö | 10 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Cisco Secure Firewall Management Center (FMC)ÊÇÒ»¿îÓÃÓÚ¼¯ÖÐÖÎÀíºÍÉèÖÃCisco Secure Firewall²úÆ·µÄÇå¾²ÖÎÀíÆ½Ì¨¡£ËüÌṩ»ùÓÚWeb»òSSHµÄ½çÃæ£¬ÔÊÐíÖÎÀíÔ±ÉèÖᢷÀ»¤¡¢¼à¿ØºÍ¸üзÀ»ðǽװ±¸¡£FMCÖ§³ÖÕ½ÂÔÖÎÀí¡¢ÊÂÎñ¼à¿Ø¡¢Á÷Á¿ÆÊÎö¼°±¨¸æ¹¦Ð§£¬×ÊÖúÆóÒµ¼¯ÖÐÖÎÀí¶à¸ö·À»ðǽװ±¸£¬ÌáÉýÍøÂçÇå¾²·À»¤ÄÜÁ¦¡£¸ÃÈí¼þ»¹Ö§³Ö¼¯³ÉµÄÉí·ÝÑéÖ¤¡¢Íþв¼ì²âÓëÏìÓ¦¹¦Ð§£¬ÊÊÓÃÓÚÆóÒµºÍÕþ¸®ÍøÂçÇéÐÎÖеļ¯Öл¯ÖÎÀíÐèÇó¡£
2025Äê8ÔÂ19ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½Cisco Secure Firewall Management Center (FMC)Èí¼þµÄRADIUS×Óϵͳ±£´æÔ¶³Ì´úÂëÖ´ÐÐ(RCE)Îó²î¡£¸ÃÎó²îÔ´ÓÚÉí·ÝÑéÖ¤Àú³ÌδÄÜ׼ȷ´¦Öóͷ£Óû§ÊäÈ룬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËÍÈ«ÐĽṹµÄƾ֤ÊäÈ룬עÈë²¢Ö´ÐÐí§ÒâµÄshellÏÂÁî¡£ÀÖ³ÉʹÓøÃÎó²îºó£¬¹¥»÷Õ߿ɻñµÃ¸ßȨÏÞÖ´ÐÐÏÂÁî¡£¸ÃÎó²î½öÓ°ÏìÆôÓÃRADIUSÈÏÖ¤µÄFMC°æ±¾7.0.7ºÍ7.7.0£¬ÇÒ½öÔÚÉèÖÃÁËWebÖÎÀí½çÃæ¡¢SSHÖÎÀí»òÁ½ÕßµÄÇéÐÎÏ¿ɱ»Ê¹Óá£Îó²îÆÀ·Ö10£¬Îó²î¼¶±ðÑÏÖØ¡£
¶þ¡¢Ó°Ïì¹æÄ£
7.0.7 <= FMC <= 7.7.0 (½öÔÚÆôÓÃRADIUSÈÏ֤ʱ)¡£
Èý¡¢Çå¾²²½·¥
Cisco¹Ù·½ÒÑÐû²¼Çå¾²²¹¶¡£¬ÇëÉý¼¶ÖÁCisco FMC7.7.0ÒÔÉϰ汾
3.2 ÔÝʱ²½·¥
ÈôÊÇÎÞ·¨Á¬Ã¦Éý¼¶£¬Çë½ûÓÃRADIUSÈÏÖ¤£¬²¢Ê¹ÓÃÆäËûÉí·ÝÑéÖ¤·½·¨£¬ÈçÍâµØÓû§ÕË»§¡¢ÍⲿLDAPÈÏÖ¤»òSAMLµ¥µãµÇ¼(SSO)¡£


¾©¹«Íø°²±¸11010802024551ºÅ