˼¿ÆÎå¸ö¸ßΣ·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-06

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-3120 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3119 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3118 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3111 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3110 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


·ÓÉÆ÷£º


ASR 9000ϵÁоۺϷþÎñ·ÓÉÆ÷

ÔËÓªÉÌ·ÓÉϵͳ£¨CRS£©

Firepower 1000ϵÁÐ

Firepower 2100ϵÁÐ

Firepower 4100ϵÁÐ

Firepower 9300°²È«É豸

IOS XRv 9000·ÓÉÆ÷

ÔËÐÐ˼¿ÆIOS XRµÄ°×ºÐ·ÓÉÆ÷


»¥»»»ú£º


Nexus 1000Ðé¹¹±ßÔµ

Nexus 1000V»¥»»»ú

Nexus 3000ϵÁл¥»»»ú

Nexus 5500ϵÁл¥»»»ú

Nexus 5600ϵÁл¥»»»ú

Nexus 6000ϵÁл¥»»»ú

Nexus 7000ϵÁл¥»»»ú

Nexus 9000ϵÁйâÏË»¥»»»ú

MDS 9000ϵÁжà²ã»¥»»»ú

ÍøÂçÈÚºÏϵͳ£¨NCS£©1000ϵÁÐ

ÍøÂçÈÚºÏϵͳ£¨NCS£©5000ϵÁÐ

ÍøÂçÈÚºÏϵͳ£¨NCS£©540·ÓÉÆ÷

ÍøÂçÈÚºÏϵͳ£¨NCS£©5500ϵÁÐ

ÍøÂçÈÚºÏϵͳ£¨NCS£©560·ÓÉÆ÷

ÍøÂçÈÚºÏϵͳ£¨NCS£©6000ϵÁÐ

UCS 6200ϵÁл¥»»¾ØÕó»¥Áª

UCS 6300ϵÁл¥»»¾ØÕó»¥Áª

UCS 6400ϵÁл¥»»¾ØÕó»¥Áª


IPµç»°»ú£º


IPȇ񎵍ȡȜ7832

IPȇ񎵍ȡȜ8832

IPµç»°»ú6800ϵÁÐ

IPµç»°»ú7800ϵÁÐ

IPµç»°»ú8800ϵÁÐ

IPµç»°»ú8851ϵÁÐ

ͳһIP»áÒéµç»°»ú8831

ÎÞÏßIPµç»°»ú8821

ÎÞÏßIPµç»°»ú8821-EX


IPÉãÏñÍ·£º


ÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñÍ·


·ì϶¸ÅÊö


°²È«×êÑÐÔ±Åû¶ÁË¿í·º²¿ÊðÓÚ˼¿Æ·¢ÏÖºÍ̸ (CDP) ÖеÄÎå¸ö¸ßΣ·ì϶¡£ÕâЩ·ì϶ÊÇÓÉÎïÁªÍøÍøÂ簲ȫ¹«Ë¾ Armis ·¢ÏÖµÄ £¬±»¶¨ÃûΪ¡°CDPwn¡± £¬Ó°ÏìµÄÊÇ˼¿Æ×¨ÓкÍ̸ CDP¡£¸ÃºÍ̸¿ÉÔÊÐí˼¿ÆÉ豸ͨ¹ý¶à²¥ÐÂÎÅÏ໥·ÖÏíÐÂÎÅ £¬ËüʵÏÖÓÚ´óÁ¿Ö÷Á÷˼¿Æ²úÆ·ÖÐ £¬×Ô20ÊÀ¼Í90Äê´úÆð±»Ê¹Ó᣸úÍ̸²¢Î´¹ãΪÈËÖª £¬ÓÉÓÚËü²¢Î´Â¶³öÔÚ»¥ÁªÍøÉϲ¢ÇÒ½öÔÚ±¾µØÍøÂçÖÐÔËÐС£


ÒªÀûÓÃÕâЩ·ì϶ £¬¹¥»÷ÕßÊ×ÏȱØÒªÔÚ±¾µØÍøÂçÖа²Éí¡£Èë¿Úµã¿ÉËùÒÔÈκÎÊÂÎïÈçÎïÁªÍøÉ豸¡£ºÚ¿Í¿ÉÄÜʹÓÃÕâ¸öÈë¿ÚÉ豸²¥±¨¶ñÒâ CDP ÐÅÏ¢²¢ÊÕÊÜ˼¿ÆÉ豸¡£ÕâÀïµÄÖØÒªÖ¸±êÊÇ˼¿ÆÂ·ÓÉÆ÷¡¢»¥»»»úºÍ·À»ðǽ £¬ËüÃdzÖÓÐ˼¿ÆÕû¸öÍøÂçµÄÃÜÔ¿ £¬Ä¬ÈÏÆôÓà CDP¡£


ÕâЩ CDPwn ·ì϶¹ÌÈ»ÎÞ·¨ÓÃÓÚ´Ó»¥ÁªÍøÔ¶³ÌÆÆ½â×éÖ¯»ú¹¹µÄ°²È«ÍøÂç £¬Ëü¿É±»ÓÃÓÚÌáÉý³õʼ½Ó¼ûȨÏÞ¡¢ÊÕÊܹؼüµãÈç·ÓÉÆ÷ºÍ»¥»»»úÀ´É¾³ýÍøÂç·Ö¶Î²¢ÔÚ¹«Ë¾ÍøÂçºáÏòÒÆ¶¯ÒÔ¹¥»÷ÆäËüÉ豸¡£CDP »¹ÔÚÆäËü˼¿Æ²úÆ·Öн»¸¶²¢Ä¬ÈÏÆôÓÃÈç VoIP µç»°ºÍ IP ÉãÏñÍ·¡£CDPwn ¹¥»÷Ò²¿É±»ÓÃÓÚ¹¥»÷ÕâЩÉ豸¡£¹¥»÷Õß»¹¿ÉÄÜÀûÓà CDPwn ÊÕÊÜÒ×Êܹ¥»÷µÄÉ豸Èçµç»°ºÍ°²È«ÉãÏñÍ·¡¢×°ÖöñÒâÈí¼þ¡¢ÌáÈ¡Êý¾Ý»òÉõÖÁÇÔÌýͨ»°ºÍÊÓÆµÄÚÈÝ¡£


CDPwnÓÉÎå¸ö·ì϶×é³É £¬Ô̺¬ËĸöÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶ £¬µÚÎå¸ö·ì϶Êǻؾø·þÎñ£¨DoS£©·ì϶ £¬¸ÅÊöÈçÏ£º


˼¿ÆNX-OSÈí¼þ¡ªË¼¿Æ·¢ÏÖºÍ̸Զ³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-3119£©


¸Ã·ì϶ÊÇÒ»¸ö²Ö¿âÒç¶Âí½Å £¬´æÔÚÓÚIOS XRÖ´ÐеÄCDPÖнâÎöº¬ÓжÔÒÔÌ«Íø¹©µç£¨PoE£©ÒªÇó×ֶνøÐÐЭÉ̵ÄÐÅÏ¢µÄCDPÊý¾Ý°üÕâ¸ö»·½Ú¡£º¬ÓÐÌ«¶àPoEÒªÇó×ֶεÄCDPÊý¾Ý°ü½«ÔÚÊÜÓ°ÏìµÄÉ豸ÉÏ´¥·¢¸Ã·ì϶¡£¹¥»÷ÕßÄܹ»Ê¹ÓúϷ¨µÄCDPÊý¾Ý°üÀ´ÀûÓø÷ì϶ £¬Ö»ÓкϷ¨Êý¾Ý°üµÄ¹¦Âʼ¶±ð¸ßÓÚ»¥»»»ú±¾¸ÃÊÕµ½µÄ×ܹ¦Âʼ¶±ð £¬´Ó¶øµ¼Ö²ֿâÒç³ö¡£Í¨¹ýÀûÓø÷ì϶ £¬¹¥»÷ÕßÄܹ»È«Ãæ½ÚÔ컥»»»ú¼°ÆäÕÆ¹ÜµÄÄDz¿ÃÅÍøÂç»ù´¡ÉèÊ© £¬´Ó¶ø·ÛËé·Ö¶Î £¬²¢ÔÊÐíÔÚVLANÖ®¼ä½øÐÐÌøÔ¾¡£


˼¿ÆIOS-XR¡ªCDPÌåʽ×Ö·û´®·ì϶£¨CVE-2020-3118£©


¸Ã·ì϶ÊÇÒ»ÖÖÌåʽ×Ö·û´®·ì϶ £¬´æÔÚÓÚIOS XRÖ´ÐеÄCDPÖнâÎöÈëÕ¾CDPÊý¾Ý°üµÄijЩ×Ö·û´®×ֶΣ¨É豸IDºÍ¶Ë¿ÚIDµÈ£©Õâ¸ö»·½Ú¡£Õâ¸ö·ì϶ʹ¹¥»÷ÕßÄܹ»½ÚÔì´«µÝ¸øsprintfº¯ÊýµÄÌåʽ×Ö·û´®²ÎÊý¡£Ê¹ÓÃijЩµÄÌåʽ×Ö·û´®×Ö·û £¬¹¥»÷ÕßÄܹ»½«ÊÜ¿Ø×Ö½ÚдÈëÔ½½ç²Ö¿â£¨out-of-bounds stack£©±äÁ¿ £¬ÕâÏÖʵÉϵ¼Ö²ֿâÒç³ö¡£¶øºó £¬ÕâÖÖÀàÐ͵ÄÒç³öµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£Ê¹Óø÷ì϶ £¬¹¥»÷ÕßÄܹ»È«Ãæ½ÚÔìÖ¸±ê·ÓÉÆ÷ £¬ÔÚÍø¶ÎÖ®¼ä´«ÊäÁ÷Á¿ £¬²¢Ê¹Ó÷ÓÉÆ÷³¢ÊÔºóÐø¹¥»÷¡£


˼¿ÆIPÓïÒôµç»°»ú¡ªCDPÔ¶³ÌÖ´Ðкͻؾø·þÎñ·ì϶£¨CVE-2020-3111£©


˼¿ÆIPµç»°»úÀûÓÃCDP½øÐÐÖÎÀí £¬Ô̺¬ÅäÖõ绰»úÓ¦Ïνӵ½ÄĸöVLAN¡£µç»°»ú»¹Äܹ»ÒªÇóÌØ¶¨µÄPoE²ÎÊý £¬ÓëËüÏàÏνӵĻ¥»»»úÄܹ»Ê¹ÓÃCDPÆôÓûò½ûÓÃÄÇЩ²ÎÊý¡£Ôڸ÷ì϶ÖÐ £¬Äܹ»ÀûÓö˿ÚID½âÎöº¯ÊýÖеIJֿâÒç³ö £¬Ôڵ绰»úÉÏÖ´ÐдúÂë¡£¹ÌÈ»CDPÊý¾Ý°üÓÉÍøÂçÖÐÿ¸öÖ§³ÖCDPµÄ»¥»»»úÖÕÖ¹ £¬µ«IPµç»°»úÖ´ÐеÄCDP´æÔÚÁíÒ»¸öbug£ºµ¥²¥ºÍ¹ã²¥CDPÊý¾Ý°üÒ²±»ÊÓΪºÏ·¨µÄCDPÊý¾Ý°ü¡£


Ö»Óб»·¢Ë͵½Ò»¸öÖ¸¶¨µÄ¶à²¥MACµØÖ· £¬ÆäËûËùÓÐ˼¿ÆÍøÂçÉ豸²Å»á½«ÒÔÌ«ÍøÊý¾Ý°ü½â¶ÁΪºÏ·¨µÄCDPÊý¾Ý°ü¡£ÕâÒâζ×Å £¬ÎªÁËÔÚIPµç»°»úÉÏ´¥·¢¸Ã·ì϶ £¬¹¥»÷ÕßÄܹ»´¦ÓÚ±¾µØÍøÂçÖеÄÈκεØÎ» £¬¶ø²»½öÏÞÓÚÖ±½Ó´ÓÖ¸±êÉ豸ÏàÏνӵĽÓÈ뻥»»»úÄÚ²¿·¢ËͶñÒâÔì×÷µÄCDPÊý¾Ý°ü¡£


´Ë±í £¬ÓÉÓÚIPµç»°»ú»¹½«¹ã²¥CDPÊý¾Ý°ü½â¶ÁΪºÏ·¨µÄCDPÊý¾Ý°ü £¬¹¥»÷Õß¾ÍÄܹ»·¢ËÍÒÔÌ«Íø¹ã²¥Êý¾Ý°ü £¬Õâ»á´¥·¢¸Ã·ì϶ £¬Í¬Ê±¶Ôͳһ¸öLANÉϵÄËùÓиßΣÉ豸·¢ÆðDoS¹¥»÷¡£


˼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñÍ·¡ªË¼¿Æ·¢ÏÖºÍ̸Զ³Ì´úÂëÖ´Ðкͻؾø·þÎñ·ì϶£¨CVE-2020-3110£©


¸Ã·ì϶ÊÇÒ»¸ö¶ÑÒç¶Âí½Å £¬´æÔÚÓÚ˼¿Æ8000ϵÁÐIPÉãÏñÍ·Ö´ÐеÄCDPÖнâÎöCDPÊý¾Ý°üÕâ¸ö»·½Ú¡£ÈëÕ¾CDPÊý¾Ý°üÖÐÌṩ¹ý´óµÄ¶Ë¿ÚID×Ö¶Îʱ £¬»áÒý·¢Õâ¸ö¶ÑÒç³ö¡£¶ÑÒç³öº¬Óй¥»÷Õß½ÚÔìµÄ×Ö½Ú £¬¿ÉÓɹ¥»÷ÕßÂŴδ¥·¢¡£´Ë±í £¬IPÉãÏñÍ·ÖÐʹÓõÄCDPÊØ»¤·¨Ê½ÊÇÓëµØÎ»Î޹صĶþ½øÔìÎļþ £¬ÕâÒâζ×ÅËü²¢²»Ê¹ÓÃASLR£¨µØÖ·¿Õ¼ä²¼¾ÖËæ»ú»¯£©»º½â´ëÊ©¡£ÓÉÓÚÉÏÊöÇé¾° £¬¹¥»÷ÕßÄܹ»ÀûÓøÃÒç³ö¡¢ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£


˼¿ÆFXOS¡¢IOS XRºÍNX-OSÈí¼þ¡ªË¼¿Æ·¢ÏÖºÍ̸»Ø¾ø·þÎñ·ì϶£¨CVE-2020-3120£©


Ö»ÓÐʹ·ÓÉÆ÷»ò»¥»»»úµÄCDPÊØ»¤·¨Ê½·ÖÅäµ¼Ö¹ý³Ì±ÀÀ£µÄ´ó¶ÎÄÚ´æ £¬¿É´¥·¢¸Ã·ì϶¡£½èÖú¸Ã·ì϶ £¬¹¥»÷Õ߿ɵ¼ÖÂCDP¹ý³Ì·´¸´±ÀÀ£ £¬½ø¶øµ¼Ö·ÓÉÆ÷³ÁÆô¡£ÕâÒâζ׏¥»÷ÕßÄܹ»ÀûÓø÷ì϶¶ÔÖ¸±ê·ÓÉÆ÷Ö´ÐÐÈ«ÃæµÄDoS¹¥»÷ £¬½ø¶øÆëÈ«·ÛËéÖ¸±êÍøÂç¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://tools.cisco.com/security/center/publicationListing.x¡£


²Î¿¼Á´½Ó


https://www.armis.com/cdpwn/