˼¿Æ½¨¸´ÑϳÁµÄIOx·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-27·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12648£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
˼¿Æ1000ϵÁÐConnected Grid Routers (CGR 1000)ºÍ˼¿Æ800ϵÁÐIndustrial Integrated Services Routers£¬×°ÖÃÁ˿ͻ§»ú²Ù×÷ϵͳµÄIOS SoftwareÒ×Êܹ¥»÷°æ±¾
·ì϶¸ÅÊö
˼¿Æ°ä²¼°²È«¸üУ¬½â¾öÁË˼¿ÆIOS Software IOxÀûÓ÷¨Ê½»·¾³ÖеÄÒ»¸öÑϳÁ·ì϶¡£¸Ã·ì϶¿Éµ¼Ö¾ÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔ¸ùÓû§Éí·Ý½Ó¼û¿Í»§»ú²Ù×÷ϵͳ (Guest OS)¡£
µ±µÍȨÏÞÓû§ÒªÇó½Ó¼û±¾Ó¦±»ÏÞ¶ÈΪÖÎÀíÔ¹ØË»§ÄÜÁ¦½Ó¼ûµÄ¿Í»§»ú²Ù×÷ϵͳʱ£¬»áÒý·¢ÃýÎóµÄ»ùÓÚ½ÇÉ«µÄ½Ó¼û½ÚÔ죨RBAC£©ÆÀ¹À¡£¹¥»÷Õß¿ÉÄÜʹÓõÍȨÏÞÓû§Æ¾Ö¤ÑéÖ¤¿Í»§»ú²Ù×÷ϵͳ£¬´Ó¶øÀûÓø÷ì϶¡£
¿Í»§»ú²Ù×÷ϵͳÊÇÔ̺¬Hypervisor¡¢IOSºÍGuest OSÓ³ÏñµÄ°ó¸¿IOSÓ³ÏñµÄÒ»²¿ÃÅ¡£Í¨¹ý˼¿ÆIOS SoftwareÓ³Ïñ°üÖ´ÐгõʼװÖûòÈí¼þÉý¼¶µÄ¿Í»§½«ÔÚÈí¼þÓ³Ïñ°ü×°Öùý³ÌÖÐ×Ô¶¯×°Öÿͻ§»ú²Ù×÷ϵͳ¡£
ÖÎÀíÔ±¿ÉÔÚÉ豸CLIÖÐʹÓúÅÁîshow iox host list detail²é¿´É豸ÉÏÊÇ·ñÆôÓÃÁ˿ͻ§»ú²Ù×÷ϵͳ¡£Ë¼¿ÆÔÚ°²È«²¼¸æÖÐÌṩÁËÈçÏÂʾÀý£¬ËµÁËÈ»ÆôÓÃÁ˿ͻ§»ú²Ù×÷ϵͳµÄºÅÁîÊä³öÁ˾֣º
´Ë±í£¬Ë¼¿Æ°ä²¼Á˰ëÄê¶ÈCisco IOSºÍIOS XEÈí¼þ°²È«²¼¸æ£¨²¹¶¡ÈÕ£©£ºhttps://tools.cisco.com/security/center/viewErp.x?alertId=ERP-72547£¬ÆäÖÐÔ̺¬ËµÁËÈ»13¸ö°²È«È±µãµÄ12¸ö˼¿Æ°²È«²¼¸æ£¬ËùÓеÄÕâ13¸ö·ì϶¾ùδ¸ßΣ·ì϶£¬CVSSÆÀ·ÖΪ7.5µ½9.9¡£±¾ÎÄÌáµ½µÄ·ì϶ҲÊÇÆäÖеÄ×é³É²¿ÃÅ¡£Ë¼¿ÆÒѰ䲼½â¾öËùÓÐÕâЩ·ì϶µÄ°²È«¸üУ¬ÒÔ×èÖ¹¹¥»÷ÕßÀûÓÃ佨¸´É豸¡°»ñȡԽȨ½Ó¼ûȨÏÞ¡¢½øÐкÅÁî×¢Èë¹¥»÷»òÒý·¢»Ø¾ø·þÎñǰÌᡱ¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth ¡£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth


¾©¹«Íø°²±¸11010802024551ºÅ