Cisco IOS XEÈí¼þWeb UI¿çÕ¾µãÒªÇóαÔì·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-14

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1904£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ºÏÓÃÓÚCisco IOS XEÈí¼þ°æ±¾ÇÒÆôÓÃÁËHTTP ServerÖ°ÄܵÄCiscoÉ豸¡£


·ì϶¸ÅÊö


Cisco IOS XEÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ΪÆäÍøÂçÉ豸¿ª·¢µÄ²Ù×÷ϵͳ¡£Cisco IOS XE SoftwareÖеÄWeb UI´æÔÚCSRF·ì϶£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶ÔÊÜÓ°ÏìµÄϵͳ½øÐпçÕ¾µãÒªÇóαÔ죨CSRF£©¹¥»÷¡£


¸Ã·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìÉ豸ÉϵÄWeb UIµÄCSRF±£»¤²»¼°¡£¹¥»÷ÕßÄܹ»Í¨¹ý˵·þ½Ó¿ÚµÄÓû§×ñÑ­¶ñÒâÁ´½ÓÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÓÃÊÜÓ°ÏìÓû§µÄȨÏÞ¼¶±ðÖ´ÐÐËÁÒâ²Ù×÷¡£ÈôÊÇÓû§ÓµÓÐÖÎÀíȨÏÞ£¬Ôò¹¥»÷ÕßÄܹ»¸ü¸ÄÅäÖã¬Ö´ÐкÅÁî»ò³ÁмÓÔØÊÜÓ°ÏìµÄÉ豸¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


½ûÓÃHTTP ServerÖ°Äܿɽâ³ý´Ë·ì϶µÄ¹¥»÷ý½é£¬²¢ÇÒ¿ÉÄÜÊÇÊʵ±µÄ»º½â´ëÊ©£¬Ö±µ½Äܹ»Éý¼¶ÊÜÓ°ÏìµÄÉ豸¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190612-iosxe-csrf