¡¾Îó²îͨ¸æ¡¿Cisco 1Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-01-210x00 Îó²î¸ÅÊö
2021Äê01ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬¹ûÕæÁËCisco SD-WAN¡¢DNA CenterºÍSmart Software Manager SatelliteµÈ¶à¸ö²úÆ·ÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
Cisco SD-WANÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1260¡¢CVE-2021-1261¡¢CVE-2021-1262¡¢CVE-2021-1263¡¢CVE-2021-1298ºÍCVE-2021-1299£©
Cisco SD-WAN²úÆ·Öб£´æ¶à¸öÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖУ¬£¬£¬£¬£¬£¬£¬CVE-2021-1260¡¢CVE-2021-1261¡¢CVE-2021-1262¡¢CVE-2021-1263ºÍCVE-2021-1298µÄCVSSÆÀ·ÖÔÚ5.3-7.8Ö®¼ä£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¶ÔÊÜÓ°ÏìµÄ×°±¸Ö´ÐÐÏÂÁî×¢Èë¹¥»÷£¬£¬£¬£¬£¬£¬£¬×îÖÕ¹¥»÷Õß¿ÉÒÔÔÚ×°±¸ÉÏÒÔrootȨÏÞÖ´ÐÐijЩ²Ù×÷¡£¡£¡£¡£¡£¡£¡£
ÖµµÃ×¢ÖØµÄÊÇCisco SD-WAN vManageÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1299£©£¬£¬£¬£¬£¬£¬£¬Æä±£´æÓÚ»ùÓÚWebµÄÖÎÀí½çÃæÖУ¬£¬£¬£¬£¬£¬£¬ÊÇÓû§¶Ô×°±¸Ä£°åÉèÖÃÌṩµÄÐÅÏ¢µÄÊäÈëÑéÖ¤²»×¼È·Ôì³ÉµÄ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.9¡£¡£¡£¡£¡£¡£¡£
¹¥»÷Õß¿ÉÒÔͨ¹ýÏò×°±¸Ä£°åÉèÖÃÌá½»¶ñÒâÐÅÏ¢À´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÊÜÓ°ÏìϵͳµÄrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
ÈôÊÇÕýÔÚÔËÐÐÒ×ÊÜÓ°ÏìµÄCisco SD-WAN°æ±¾£¬£¬£¬£¬£¬£¬£¬ÔòÕâЩÎó²î»áÓ°ÏìÒÔÏÂCisco²úÆ·£º
SD-WAN vBond OrchestratorÈí¼þ
SD-WAN vEdgeÔÆÂ·ÓÉÆ÷
SD-WAN vEdge·ÓÉÆ÷
SD-WAN vManageÈí¼þ
SD-WAN vSmart¿ØÖÆÆ÷Èí¼þ
ÐÞ¸´°æ±¾
Cisco SD-WAN°æ±¾ | ÕâЩÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ת´ï¼¯ÖÐÐÎòµÄËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
ÔçÓÚ18.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
18.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
18.4 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
19.2 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
19.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
20.1 | 20.1.2 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
20.3 | 20.3.2 | 20.3.2 |
20.4 | 20.4.1 | 20.4.1 |
Cisco SD-WAN»º³åÇøÒç³öÎó²î£¨CVE-2021-1300£©
¸ÃÎó²îÊǶÔIPÁ÷Á¿µÄ²»×¼È·´¦Öóͷ£Ôì³ÉµÄ£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâIPÁ÷Á¿À´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬×îÖÕµ¼Ö»º³åÇøÒç³ö¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔrootȨÏÞÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬Cisco SD-WANµÄNETCONF×ÓϵͳÖл¹±£´æÁíÒ»¸ö»º³åÇøÒç³öÎó²î£¨CVE-2021-1301£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔÚÊÜÓ°ÏìµÄ×°±¸»òϵͳÉϵ¼Ö¾ܾøÐ§ÀÍ£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.5¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
ÈôÊÇÕýÔÚÔËÐÐÒ×ÊÜÓ°ÏìµÄCisco SD-WAN°æ±¾£¬£¬£¬£¬£¬£¬£¬ÔòÕâЩÎó²î»áÓ°ÏìÒÔÏÂCisco²úÆ·£º
IOS XE SD-WANÈí¼þ
SD-WAN vBond OrchestratorÈí¼þ
SD-WAN vEdgeÔÆÂ·ÓÉÆ÷
SD-WAN vEdge·ÓÉÆ÷
SD-WAN vManageÈí¼þ
SD-WAN vSmart¿ØÖÆÆ÷Èí¼þ
ÐÞ¸´°æ±¾
SD-WAN
Cisco SD-WAN°æ±¾ | Îó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
ÔçÓÚ18.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
18.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
18.4 | 18.4.5 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
19.2 | 19.2.2 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
19.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
20.1 | 20.1.1 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
20.3 | 20.3.1 | 20.3.2 |
20.4 | 20.4.1 | 20.4.1 |
IOS XE SD-WAN
Cisco IOS XE SD-WAN°æ±¾ | Îó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
16.9 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
16.10 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
16.11 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
16.12 | 16.12.4 | 16.12.4 |
IOS XE
Cisco IOS XEͨÓð汾 | Îó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
17.2 | 17.2.1 | 17.2.2 |
17.3 | 17.3.1 | 17.3.1 |
17.4 | 17.4.1 | 17.4.1 |
Cisco DNA Center Command Runner ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1264£©
¸ÃÎó²î±£´æÓÚCisco DNA CenterµÄCommand Runner¹¤¾ßÖУ¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.6¡£¡£¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇCommand Runner¹¤¾ßÊäÈëÑé֤ȱ·¦µ¼Öµġ£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÏÂÁîÖ´ÐÐʱ´úʹÓöñÒâÊäÈë»òŲÓÃÏÂÁîÔËÐгÌÐòAPIÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬×îÖÕÄܹ»ÔÚCisco DNA CenterÖÎÀíµÄ×°±¸ÉÏÖ´ÐÐí§ÒâCLIÏÂÁî¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Cisco DNA Center Software < 1.3.1.0
ÐÞ¸´°æ±¾
Cisco DNA Center Software >= 1.3.1.0
Cisco Smart Software Manager Satellite Web UIÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1138¡¢CVE-2021-1140ºÍCVE-2021-1142£©
Õâ3¸öÎó²î¶¼ÊÇCiscoÖÇÄÜÈí¼þÖÎÀíÆ÷SatelliteµÄWeb UIÖеÄÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬ËüÃǶ¼ÊÇÊäÈëÑé֤ȱ·¦µ¼Öµģ¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâHTTPÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÉÏÔËÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬CiscoÖÇÄÜÈí¼þÖÎÀíÆ÷SatelliteµÄWeb UIÖл¹±£´æÆäËü2¸öÊäÈëÑé֤ȱ·¦µ¼ÖµÄÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1139ºÍCVE-2021-1141£©£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¾ùΪ8.8¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâHTTPÇëÇóÀ´Ê¹ÓÃËüÃÇ£¬£¬£¬£¬£¬£¬£¬×îÖÕ¿ÉÒÔÒÔrootÓû§µÄÉí·ÝÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Cisco Smart Software Manager Satellite <= 5.1.0
ÐÞ¸´°æ±¾
Cisco Smart Software Manager On-Prem >= 6.3.0
×¢£ºÔÚ6.3.0°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬Cisco Smart Software Manager Satellite±»ÖØÃüÃûΪCisco Smart Software Manager On-Prem¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
½¨Òé²Î¿¼Cisco¹Ù·½Ðû²¼µÄÇ徲ͨ¸æÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-cmdinjm-9QMSmgcn
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-pre-auth-bugs-in-sd-wan-cloud-license-manager/
0x04 ʱ¼äÏß
2021-01-20 CiscoÐû²¼Ç徲ͨ¸æ
2021-01-21 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/