˼¿ÆÐÞ¸´ÆäSD-WAN½â¾ö¼Æ»®ÖеĶà¸öÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-19

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-3265£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.0£¬£¬£¬ £¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3266£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬£¬£¬ £¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3264£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1£¬£¬£¬ £¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÔËÐÐ×ÅCisco SD-WAN Solution Release 19.2.2֮ǰ°æ±¾µÄÒÔϲúÆ·£º


vBond Orchestrator Software

vEdge 100 Series Routers

vEdge 1000 Series Routers

vEdge 2000 Series Routers

vEdge 5000 Series Routers

vEdge Cloud Router Platform

vManage Network Management Software

vSmart Controller Software


Îó²î¸ÅÊö


Cisco SD-WAN SolutionÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ÍøÂçÀ©Õ¹½â¾ö¼Æ»®¡£¡£¡£ ¡£¡£¡£¡£


¿ËÈÕ£¬£¬£¬ £¬£¬£¬Ë¼¿ÆÐû²¼Ç徲ͨ¸æ£¬£¬£¬ £¬£¬£¬ÐÞ¸´ÁËÆäSD-WAN½â¾ö¼Æ»®ÖеÄÎå¸öÎó²î£¬£¬£¬ £¬£¬£¬ÆäÖаüÀ¨Èý¸ö¸ßΣÎó²î£¬£¬£¬ £¬£¬£¬¸ÅÊöÈçÏ£º


CVE-2020-3265

Cisco SD-WAN Solution software Release 19.2.2֮ǰ°æ±¾Öб£´æÈ¨ÏÞÔÊÐíºÍ»á¼û¿ØÖÆÎÊÌâÎó²î£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓгä·Ö¾ÙÐÐÊäÈëÑéÖ¤¡£¡£¡£ ¡£¡£¡£¡£ÍâµØ¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄÇëÇóʹÓøÃÎó²î»ñÈ¡rootȨÏÞ¡£¡£¡£ ¡£¡£¡£¡£


CVE-2020-3266

Cisco SD-WAN Solution software Release 19.2.2֮ǰ°æ±¾ÖеÄCLI±£´æÏÂÁî×¢ÈëÎó²î£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓгä·Ö¾ÙÐÐÊäÈëÑéÖ¤¡£¡£¡£ ¡£¡£¡£¡£ÍâµØ¹¥»÷Õß¿Éͨ¹ý¾ÙÐÐÉí·ÝÑéÖ¤²¢Ìá½»ÌØÖÆµÄÊäÈëʹÓøÃÎó²îÒÔrootȨÏÞÖ´ÐÐÏÂÁî¡£¡£¡£ ¡£¡£¡£¡£


CVE-2020-3264

Cisco SD-WAN Solution software Release 19.2.2֮ǰ°æ±¾Öб£´æ»º³åÇø¹ýʧÎó²î£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚ²»³ä·ÖµÄÊäÈëÑéÖ¤¡£¡£¡£ ¡£¡£¡£¡£ÍâµØ¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄÁ÷Á¿Ê¹ÓøÃÎó²î»á¼ûûÓÐÊÚȨµÄÐÅÏ¢»ò¶Ôϵͳ¾ÙÐÐδÊÚȨµÄÐ޸ġ£¡£¡£ ¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£ ¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬ £¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwpresc-ySJGvE9

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwclici-cvrQpH9v

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwanbo-QKcABnS2


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/publicationListing.x