¡¾Îó²îͨ¸æ¡¿Cisco FMC RADIUS Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-20265)

Ðû²¼Ê±¼ä 2025-08-19

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Cisco FMC RADIUS Ô¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2025-20265

Îó²îÀàÐÍ

RCE

·¢Ã÷ʱ¼ä

2025-08-19

Îó²îÆÀ·Ö

10

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Cisco Secure Firewall Management Center (FMC)ÊÇÒ»¿îÓÃÓÚ¼¯ÖÐÖÎÀíºÍÉèÖÃCisco Secure Firewall²úÆ·µÄÇå¾²ÖÎÀíÆ½Ì¨¡£¡£¡£¡£¡£¡£ËüÌṩ»ùÓÚWeb»òSSHµÄ½çÃæ£¬£¬£¬£¬ÔÊÐíÖÎÀíÔ±ÉèÖᢷÀ»¤¡¢¼à¿ØºÍ¸üзÀ»ðǽװ±¸¡£¡£¡£¡£¡£¡£FMCÖ§³ÖÕ½ÂÔÖÎÀí¡¢ÊÂÎñ¼à¿Ø¡¢Á÷Á¿ÆÊÎö¼°±¨¸æ¹¦Ð§£¬£¬£¬£¬×ÊÖúÆóÒµ¼¯ÖÐÖÎÀí¶à¸ö·À»ðǽװ±¸£¬£¬£¬£¬ÌáÉýÍøÂçÇå¾²·À»¤ÄÜÁ¦¡£¡£¡£¡£¡£¡£¸ÃÈí¼þ»¹Ö§³Ö¼¯³ÉµÄÉí·ÝÑéÖ¤¡¢Íþв¼ì²âÓëÏìÓ¦¹¦Ð§£¬£¬£¬£¬ÊÊÓÃÓÚÆóÒµºÍÕþ¸®ÍøÂçÇéÐÎÖеļ¯Öл¯ÖÎÀíÐèÇ󡣡£¡£¡£¡£¡£


2025Äê8ÔÂ19ÈÕ£¬£¬£¬£¬°ÙÀÖ²©¼¯ÍÅVSRC¼à²âµ½Cisco Secure Firewall Management Center (FMC)Èí¼þµÄRADIUS×Óϵͳ±£´æÔ¶³Ì´úÂëÖ´ÐÐ(RCE)Îó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚÉí·ÝÑéÖ¤Àú³ÌδÄÜ׼ȷ´¦Öóͷ£Óû§ÊäÈ룬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËÍÈ«ÐĽṹµÄƾ֤ÊäÈ룬£¬£¬£¬×¢Èë²¢Ö´ÐÐí§ÒâµÄshellÏÂÁî¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²îºó£¬£¬£¬£¬¹¥»÷Õ߿ɻñµÃ¸ßȨÏÞÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£¸ÃÎó²î½öÓ°ÏìÆôÓÃRADIUSÈÏÖ¤µÄFMC°æ±¾7.0.7ºÍ7.7.0£¬£¬£¬£¬ÇÒ½öÔÚÉèÖÃÁËWebÖÎÀí½çÃæ¡¢SSHÖÎÀí»òÁ½ÕßµÄÇéÐÎÏ¿ɱ»Ê¹Óᣡ£¡£¡£¡£¡£Îó²îÆÀ·Ö10£¬£¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


7.0.7 <= FMC <= 7.7.0 (½öÔÚÆôÓÃRADIUSÈÏ֤ʱ)¡£¡£¡£¡£¡£¡£


Èý¡¢Çå¾²²½·¥





Cisco¹Ù·½ÒÑÐû²¼Çå¾²²¹¶¡£¬£¬£¬£¬ÇëÉý¼¶ÖÁCisco FMC7.7.0ÒÔÉϰ汾


ÏÂÔØÁ´½Ó£º
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79


3.2 ÔÝʱ²½·¥


ÈôÊÇÎÞ·¨Á¬Ã¦Éý¼¶£¬£¬£¬£¬Çë½ûÓÃRADIUSÈÏÖ¤£¬£¬£¬£¬²¢Ê¹ÓÃÆäËûÉí·ÝÑéÖ¤·½·¨£¬£¬£¬£¬ÈçÍâµØÓû§ÕË»§¡¢ÍⲿLDAPÈÏÖ¤»òSAMLµ¥µãµÇ¼(SSO)¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/cisco-warns-of-max-severity-flaw-in-firewall-management-center/
https://nvd.nist.gov/vuln/detail/CVE-2025-20265
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79