{"id":25586,"date":"2022-03-09T19:59:15","date_gmt":"2022-03-09T21:59:15","guid":{"rendered":"https:\/\/teknomers.com\/fr\/bogues-rce-critiques-trouves-dans-le-systeme-telephonique-cloud-pascom-utilise-par-les-entreprises\/"},"modified":"2022-03-09T19:59:21","modified_gmt":"2022-03-09T21:59:21","slug":"bogues-rce-critiques-trouves-dans-le-systeme-telephonique-cloud-pascom-utilise-par-les-entreprises","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/bogues-rce-critiques-trouves-dans-le-systeme-telephonique-cloud-pascom-utilise-par-les-entreprises\/","title":{"rendered":"Bogues RCE critiques trouv\u00e9s dans le syst\u00e8me t\u00e9l\u00e9phonique cloud Pascom utilis\u00e9 par les entreprises"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Les chercheurs ont r\u00e9v\u00e9l\u00e9 trois vuln\u00e9rabilit\u00e9s de s\u00e9curit\u00e9 affectant Pascom Cloud Phone System (<a rel=\"nofollow noopener\" href=\"https:\/\/www.pascom.net\/en\/cloud-phone-system\/\" target=\"_blank\">SCS<\/a>) qui pourraient \u00eatre combin\u00e9s pour obtenir une ex\u00e9cution compl\u00e8te du code \u00e0 distance pr\u00e9-authentifi\u00e9 des syst\u00e8mes concern\u00e9s.<\/p>\n<p>Daniel Eshetu, chercheur en s\u00e9curit\u00e9 Kerbit <a rel=\"nofollow noopener\" href=\"https:\/\/kerbit.io\/research\/read\/blog\/4\" target=\"_blank\">mentionn\u00e9<\/a> les lacunes, lorsqu&#8217;elles sont encha\u00een\u00e9es, peuvent conduire \u00e0 &#8220;un attaquant non authentifi\u00e9 prenant racine sur ces appareils&#8221;.<\/p>\n<p>Pascom Cloud Phone System est une solution int\u00e9gr\u00e9e de collaboration et de communication qui permet aux entreprises d&#8217;h\u00e9berger et de configurer des r\u00e9seaux t\u00e9l\u00e9phoniques priv\u00e9s sur diff\u00e9rentes plates-formes, ainsi que de faciliter la surveillance, la maintenance et les mises \u00e0 jour associ\u00e9es aux syst\u00e8mes t\u00e9l\u00e9phoniques virtuels.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-d1\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/1645701000_960_Dridex-Malware-Deploiement-Entropy-Ransomware-sur-des-ordinateurs-pirates.png\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>L&#8217;ensemble de trois failles comprend celles provenant d&#8217;une travers\u00e9e de chemin arbitraire dans l&#8217;interface Web, une falsification de requ\u00eate c\u00f4t\u00e9 serveur (<a rel=\"nofollow noopener\" href=\"https:\/\/owasp.org\/www-community\/attacks\/Server_Side_Request_Forgery\" target=\"_blank\">SSRF<\/a>) en raison d&#8217;une d\u00e9pendance tierce obsol\u00e8te (<a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2019-18394\" target=\"_blank\">CVE-2019-18394<\/a>), et une injection de commande post-authentification \u00e0 l&#8217;aide d&#8217;un service d\u00e9mon (&#8220;exd.pl&#8221;).<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"217\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/Bogues-RCE-critiques-trouves-dans-le-systeme-telephonique-cloud-Pascom.gif\" \/><\/div>\n<p>En d&#8217;autres termes, les vuln\u00e9rabilit\u00e9s peuvent \u00eatre encha\u00een\u00e9es \u00e0 la mani\u00e8re d&#8217;une cha\u00eene pour acc\u00e9der aux points de terminaison non expos\u00e9s en envoyant des requ\u00eates GET arbitraires pour obtenir le mot de passe administrateur, puis l&#8217;utiliser pour obtenir l&#8217;ex\u00e9cution de code \u00e0 distance \u00e0 l&#8217;aide de la t\u00e2che planifi\u00e9e.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646326908_645_Correctifs-critiques-publies-pour-la-gamme-Cisco-Expressway-les-produits.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>La cha\u00eene d&#8217;exploitation peut \u00eatre utilis\u00e9e &#8220;pour ex\u00e9cuter des commandes en tant que root&#8221;, a d\u00e9clar\u00e9 Eshetu, ajoutant que &#8220;cela nous donne un contr\u00f4le total de la machine et un moyen facile d&#8217;\u00e9lever les privil\u00e8ges&#8221;.  Les failles ont \u00e9t\u00e9 signal\u00e9es \u00e0 Pascom le 3 janvier 2022, apr\u00e8s quoi des correctifs ont \u00e9t\u00e9 publi\u00e9s.<\/p>\n<p>Les clients qui h\u00e9bergent eux-m\u00eames CPS plut\u00f4t que sur le cloud sont invit\u00e9s \u00e0 mettre \u00e0 jour vers la derni\u00e8re version (<a rel=\"nofollow noopener\" href=\"https:\/\/www.pascom.net\/doc\/en\/release-notes\/pascom19\/\" target=\"_blank\">serveur pascom 19.21<\/a>) d\u00e8s que possible pour contrer toute menace potentielle.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/critical-rce-bugs-found-in-pascom-cloud.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Les chercheurs ont r\u00e9v\u00e9l\u00e9 trois vuln\u00e9rabilit\u00e9s de s\u00e9curit\u00e9 affectant Pascom Cloud Phone System (SCS) qui pourraient \u00eatre combin\u00e9s pour obtenir une ex\u00e9cution compl\u00e8te du code \u00e0 distance pr\u00e9-authentifi\u00e9 des syst\u00e8mes concern\u00e9s. Daniel Eshetu, chercheur en s\u00e9curit\u00e9 Kerbit mentionn\u00e9 les lacunes, lorsqu&#8217;elles sont encha\u00een\u00e9es, peuvent conduire \u00e0 &#8220;un attaquant non authentifi\u00e9 prenant racine sur ces appareils&#8221;. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":25587,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[14862,22780,4168,5729,4158,4165,4161,429,3244,4157,4159,4171,4170,65,4167,4160,4163,4162,164,22781,22778,4172,4169,2622,11803,22779,1282,4166,4164],"class_list":["post-25586","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-bogues","tag-cloud","tag-comment-pirater","tag-critiques","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dans","tag-entreprises","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-les","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-par","tag-pascom","tag-rce","tag-securite-informatique","tag-securite-internet","tag-systeme","tag-telephonique","tag-trouves","tag-utilise","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/25586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=25586"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/25586\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/25587"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=25586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=25586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=25586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}