¡¾·ì϶¹«¸æ¡¿Cisco FMC RADIUS Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-20265)

°ä²¼¹¦·ò 2025-08-19

Ò»¡¢·ì϶¸ÅÊö


·ì϶Ãû³Æ

Cisco FMC RADIUS Ô¶³Ì´úÂëÖ´Ðзì϶

CVE   ID

CVE-2025-20265

·ì϶ÀàÐÍ

RCE

·¢ÏÖ¹¦·ò

2025-08-19

·ì϶ÆÀ·Ö

10

·ì϶µÈ¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


Cisco Secure Firewall Management Center (FMC)ÊÇÒ»¿îÓÃÓÚ¼¯ÖÐÖÎÀíºÍÅäÖÃCisco Secure Firewall²úÆ·µÄ°²È«ÖÎÀíÆ½Ì¨¡£¡£¡£¡£¡£ËüÌṩ»ùÓÚWeb»òSSHµÄ½çÃæ£¬£¬£¬ÔÊÐíÖÎÀíÔ±ÅäÖᢷÀ»¤¡¢¼à¿ØºÍ¸üзÀ»ðǽÉ豸¡£¡£¡£¡£¡£FMCÖ§³ÖÕ½ÊõÖÎÀí¡¢ÊÂÎñ¼à¿Ø¡¢Á÷Á¿·ÖÎö¼°»ã±¨Ö°ÄÜ£¬£¬£¬Ô®ÊÖÆóÒµ¼¯ÖÐÖÎÀí¶à¸ö·À»ðǽÉ豸£¬£¬£¬ÌáÉýÍøÂ簲ȫ·À»¤ÄÜÁ¦¡£¡£¡£¡£¡£¸ÃÈí¼þ»¹Ö§³Ö¼¯³ÉµÄÉí·ÝÑéÖ¤¡¢Íþв¼ì²âÓëÏìÓ¦Ö°ÄÜ£¬£¬£¬ºÏÓÃÓÚÆóÒµºÍµ±¾ÖÍøÂç»·¾³Öеļ¯Öл¯ÖÎÀíÐèÒª¡£¡£¡£¡£¡£


2025Äê8ÔÂ19ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Cisco Secure Firewall Management Center (FMC)Èí¼þµÄRADIUS×Óϵͳ´æÔÚÔ¶³Ì´úÂëÖ´ÐÐ(RCE)·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚÉí·ÝÑéÖ¤¹ý³ÌδÄÜÕýÈ·´¦ÖÃÓû§ÊäÈ룬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý·¢Ë;«ÐÄ»ú¹ØµÄƾ֤ÊäÈ룬£¬£¬×¢Èë²¢Ö´ÐÐËÁÒâµÄshellºÅÁî¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶ºó£¬£¬£¬¹¥»÷Õ߿ɻñµÃ¸ßȨÏÞÖ´ÐкÅÁî¡£¡£¡£¡£¡£¸Ã·ì϶½öÓ°ÏìÆôÓÃRADIUSÈÏÖ¤µÄFMC°æ±¾7.0.7ºÍ7.7.0£¬£¬£¬ÇÒ½öÔÚÅäÖÃÁËWebÖÎÀí½çÃæ¡¢SSHÖÎÀí»òÁ½ÕßµÄÇé¿öÏ¿ɱ»ÀûÓᣡ£¡£¡£¡£·ì϶ÆÀ·Ö10£¬£¬£¬·ì϶¼¶±ðÑÏÖØ¡£¡£¡£¡£¡£


¶þ¡¢Ó°ÏìÁìÓò


7.0.7 <= FMC <= 7.7.0 (½öÔÚÆôÓÃRADIUSÈÏ֤ʱ)¡£¡£¡£¡£¡£


Èý¡¢°²È«´ëÊ©





Cisco¹Ù·½ÒѰ䲼°²È«²¹¶¡£¬£¬£¬ÇëÉý¼¶ÖÁCisco FMC7.7.0ÒÔÉϰ汾


ÏÂÔØÁ´½Ó£º
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79


3.2 һʱ´ëÊ©


ÈôÊÇÎÞ·¨Á¢¼´Éý¼¶£¬£¬£¬Çë½ûÓÃRADIUSÈÏÖ¤£¬£¬£¬²¢Ê¹ÓÃÆäËûÉí·ÝÑéÖ¤·½Ê½£¬£¬£¬Èç±¾µØÓû§ÕË»§¡¢ÍⲿLDAPÈÏÖ¤»òSAMLµ¥µãµÇ¼(SSO)¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÖÆ£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬¹Ø±Õ·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÖÆºÍ×îСȨÏÞ×¼Ôò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/cisco-warns-of-max-severity-flaw-in-firewall-management-center/
https://nvd.nist.gov/vuln/detail/CVE-2025-20265
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79