¡¾Ç徲ͨ¸æ¡¿Cisco SD-WAN¸ßΣÎó²î £¨CVE-2020-3374£¬CVE-2020-3375£©
2020-07-31
×ÛÊö
¿ËÈÕ£¬Ë¼¿Æ£¨Cisco£©¹Ù·½Ðû²¼Í¨¸æ³ÆÐÞ¸´ÁËCisco SD-WAN vManager Software£¨CVE-2020-3374£©ºÍSD-WAN Solution Software(CVE-2020-3375)µÄ2¸ö¸ßΣÎó²î¡£
Cisco SD-WANÊÇÒ»ÖÖÇå¾²µÄÔÆ¹æÄ£¼Ü¹¹£¬¾ßÓпª·ÅÐÔ£¬¿É±à³ÌÐԺͿÉÀ©Õ¹ÐÔ¡£ ͨ¹ýCisco vManage¿ØÖÆÌ¨£¬Äú¿ÉÒÔ¿ìËÙ½¨ÉèSD-WANÁýÕֽṹÒÔÅþÁ¬Êý¾ÝÖÐÐÄ£¬·ÖÖ§»ú¹¹£¬Ô°ÇøºÍÖ÷»úÍйÜÉèÊ©£¬ÒÔÌá¸ßÍøÂçËÙÂÊ£¬Çå¾²ÐÔºÍЧÂÊ¡£
Îó²î¸ÅÊö
1. CVE-2020-3374
Cisco SD-WAN vManageÈí¼þ»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÊÚȨ£¬Ê¹ËûÃÇÄܹ»»á¼ûÃô¸ÐÐÅÏ¢£¬ÐÞ¸ÄϵͳÉèÖûòÓ°ÏìÊÜÓ°ÏìϵͳµÄ¿ÉÓÃÐÔ¡£
Base 9.9 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:X
Îó²îÏêϸÐÅÏ¢£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uabvman-SYGzt8Bv
2. CVE-2020-3375
Cisco SD-WAN½â¾ö¼Æ»®Èí¼þÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÔì³É»º³åÇøÒç³ö¡£
¸ÃÎó²îÊÇÓÉÓÚÊäÈëÑé֤ȱ·¦ËùÖ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ý½«ÌØÖÆÁ÷Á¿·¢Ë͵½ÊÜÓ°ÏìµÄ×°±¸À´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓøÃÎó²î¿ÉÄÜʹ¹¥»÷Õß»ñµÃ¶Ô×°±¸µÄ»á¼ûȨ£¬¿ÉÒÔ¸ü¸ÄϵͳµÄȨÏÞ£¬²¢ÒÔrootȨÏÞÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐÏÂÁî¡£
Base 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X
Îó²îÏêϸÐÅÏ¢£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdbufof-h5f5VSeL
ÊÜÓ°ÏìµÄ²úÆ·
CVE-2020-3374
ËùÓÐʹÓÃÁËSD-WAN vManager SoftwareµÄ²úÆ·
CVE-2020-3375
ËùÓÐʹÓÃÁËSD-WAN Solution SoftwareµÄ²úÆ·£¬°üÀ¨£º
IOS XE SD-WAN Software
SD-WAN vBond Orchestrator Software
SD-WAN vEdge Cloud Routers
SD-WAN vEdge Routers
SD-WAN vManage Software
SD-WAN vSmart Controller Software
ÏêϸµÄÊÜÓ°Ïì°æ±¾Çë²Î¿¼Ïà¹ØÎó²îµÄ¹Ù·½Í¨¸æ¡£
½â¾ö¼Æ»®
˼¿Æ¹Ù·½ÒѾÐû²¼Ð°汾ÐÞ¸´ÁËÕâЩÎó²î£¬ÇëÓû§¾¡¿ìÉý¼¶¾ÙÐзÀ»¤¡£
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







