˼¿Æ½¨¸´ÑϳÁµÄIOx·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-27

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12648£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


˼¿Æ1000ϵÁÐConnected Grid Routers (CGR 1000)ºÍ˼¿Æ800ϵÁÐIndustrial Integrated Services Routers£¬×°ÖÃÁ˿ͻ§»ú²Ù×÷ϵͳµÄIOS SoftwareÒ×Êܹ¥»÷°æ±¾


·ì϶¸ÅÊö


˼¿Æ°ä²¼°²È«¸üУ¬½â¾öÁË˼¿ÆIOS Software IOxÀûÓ÷¨Ê½»·¾³ÖеÄÒ»¸öÑϳÁ·ì϶¡£¸Ã·ì϶¿Éµ¼Ö¾­ÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔ¸ùÓû§Éí·Ý½Ó¼û¿Í»§»ú²Ù×÷ϵͳ (Guest OS)¡£


µ±µÍȨÏÞÓû§ÒªÇó½Ó¼û±¾Ó¦±»ÏÞ¶ÈΪÖÎÀíÔ¹ØË»§ÄÜÁ¦½Ó¼ûµÄ¿Í»§»ú²Ù×÷ϵͳʱ£¬»áÒý·¢ÃýÎóµÄ»ùÓÚ½ÇÉ«µÄ½Ó¼û½ÚÔ죨RBAC£©ÆÀ¹À¡£¹¥»÷Õß¿ÉÄÜʹÓõÍȨÏÞÓû§Æ¾Ö¤ÑéÖ¤¿Í»§»ú²Ù×÷ϵͳ£¬´Ó¶øÀûÓø÷ì϶¡£


¿Í»§»ú²Ù×÷ϵͳÊÇÔ̺¬Hypervisor¡¢IOSºÍGuest OSÓ³ÏñµÄ°ó¸¿IOSÓ³ÏñµÄÒ»²¿ÃÅ¡£Í¨¹ý˼¿ÆIOS SoftwareÓ³Ïñ°üÖ´ÐгõʼװÖûòÈí¼þÉý¼¶µÄ¿Í»§½«ÔÚÈí¼þÓ³Ïñ°ü×°Öùý³ÌÖÐ×Ô¶¯×°Öÿͻ§»ú²Ù×÷ϵͳ¡£


ÖÎÀíÔ±¿ÉÔÚÉ豸CLIÖÐʹÓúÅÁîshow iox host list detail²é¿´É豸ÉÏÊÇ·ñÆôÓÃÁ˿ͻ§»ú²Ù×÷ϵͳ¡£Ë¼¿ÆÔÚ°²È«²¼¸æÖÐÌṩÁËÈçÏÂʾÀý£¬ËµÁËÈ»ÆôÓÃÁ˿ͻ§»ú²Ù×÷ϵͳµÄºÅÁîÊä³öÁ˾֣º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



´Ë±í£¬Ë¼¿Æ°ä²¼Á˰ëÄê¶ÈCisco IOSºÍIOS XEÈí¼þ°²È«²¼¸æ£¨²¹¶¡ÈÕ£©£ºhttps://tools.cisco.com/security/center/viewErp.x?alertId=ERP-72547£¬ÆäÖÐÔ̺¬ËµÁËÈ»13¸ö°²È«È±µãµÄ12¸ö˼¿Æ°²È«²¼¸æ£¬ËùÓеÄÕâ13¸ö·ì϶¾ùδ¸ßΣ·ì϶£¬CVSSÆÀ·ÖΪ7.5µ½9.9¡£±¾ÎÄÌáµ½µÄ·ì϶ҲÊÇÆäÖеÄ×é³É²¿ÃÅ¡£Ë¼¿ÆÒѰ䲼½â¾öËùÓÐÕâЩ·ì϶µÄ°²È«¸üУ¬ÒÔ×èÖ¹¹¥»÷ÕßÀûÓÃ佨¸´É豸¡°»ñȡԽȨ½Ó¼ûȨÏÞ¡¢½øÐкÅÁî×¢Èë¹¥»÷»òÒý·¢»Ø¾ø·þÎñǰÌᡱ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth ¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth