˼¿Æ°ä²¼¶à¸ö¸ßΣ·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-27·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-3173£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3168£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3175£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3167£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3171£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3172£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
|
CVE񅧏 |
Ó°Ïì²úÆ· |
|
CVE-2020-3173 |
UCS 6200 Series Fabric Interconnects UCS 6300 Series Fabric Interconnects UCS 6400 Series Fabric Interconnects |
|
CVE-2020-3168 |
ʹÓÃVMware vSphere Virtual SupervisorµÄCisco Nexus 1000V»¥»»»ú |
|
CVE-2020-3175 |
Cisco MDS 9000ϵÁжà²ã»¥»»»ú |
|
CVE-2020-3167 |
Firepower 1000 Series Firepower 2100 Series Firepower 4100 Series Firepower 9300 Security Appliances UCS 6200 Series Fabric Interconnects UCS 6300 Series Fabric Interconnects UCS 6400 Series Fabric Interconnects |
|
CVE-2020-3171 |
Firepower 2100 Series Firepower 4100 Series Firepower 9300 Security Appliances UCS 6200 Series Fabric Interconnects UCS 6300 Series Fabric Interconnects UCS 6400 Series Fabric Interconnects |
|
CVE-2020-3172 |
ÈôÊÇÒÔÏÂCisco²úÆ·ÔËÐÐÒ×Êܹ¥»÷µÄCisco FXOSÈí¼þ»òCisco NX-OSÈí¼þ°æ±¾£¬²¢ÇÒÅäÖÃΪʹÓÃCisco·¢ÏÖºÍ̸£¬Ôò´Ë·ì϶»áÓ°ÏìÕâЩ²úÆ·£º Firepower 4100 Series (CSCvr37151) Firepower 9300 Security Appliances (CSCvr37151) MDS 9000 Series Multilayer Switches (CSCux07556) Nexus 1000 Virtual Edge for VMware vSphere (CSCvr37146) Nexus 1000V Switch for Microsoft Hyper-V (CSCvr37146) Nexus 1000V Switch for VMware vSphere (CSCvr37146) Nexus 3000 Series Switches (CSCux58226) Nexus 5500 Platform Switches (CSCvr37148) Nexus 5600 Platform Switches (CSCvr37148) Nexus 6000 Series Switches (CSCvr37148) Nexus 7000 Series Switches (CSCux07556) Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode (CSCvr31410) Nexus 9000 Series Switches in standalone NX-OS mode (CSCux58226) UCS 6200 Series Fabric Interconnects (CSCvr37150) UCS 6300 Series Fabric Interconnects (CSCvr37150) |
·ì϶¸ÅÊö
2ÔÂ26ÈÕµ½27ÈÕ˼¿Æ¹²°ä²¼ÁË12¸ö·ì϶µÄ²¹¶¡·¨Ê½£¬ÆäÖУ¬Ô̺¬6¸ö¸ßΣ·ì϶£¬Ó°Ïì·ÓÉÆ÷¡¢»¥»»»úµÈÉ豸¡£¸ßΣ·ì϶¸ÅÊöÈçÏ£º
CVE-2020-3173
Cisco UCS ManagerÈí¼þ±¾µØÖÎÀíCLIºÅÁî×¢Èë·ì϶¡£¸Ã·ì϶ÊÇÓÉÓÚºÅÁî²ÎÊýµÄÊäÈëÑéÖ¤²»¼°ËùÖ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚ±¾µØÖÎÀíCLIÉÏÔ̺¬¶ñÒâ²ÎÊýÀ´ÀûÓô˷ì϶¡£³É¹¦µÄÀûÓÿÉÄܻᵼÖ¹¥»÷ÕßÄܹ»Ê¹Óõ±Ç°µÇ¼Óû§µÄÌØÈ¨Ôڵײã²Ù×÷ϵͳÉÏÕë¶Ô³ýCisco UCS 6400 Series Fabric InterconnectsÖ®±íµÄËùÓÐÊÜÓ°ÏìÆ½Ì¨Ö´ÐÐÌØÈ¨ºÅÁî¡£
CVE-2020-3168
ʹÓÃVMware vSphereµÄCisco Nexus 1000V»¥»»»ú°²È«µÇ¼¼ÓǿְÄܻؾø·þÎñ·ì϶¡£¸Ã·ì϶ÊÇÓÉÓÚÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÅäÖÃÁË×÷Ϊ°²È«µÇ¼¼ÓǿְÄܵÄÒ»²¿ÃŵĵǼ²ÎÊýʱ£¬ÔÚʧ°ÜµÄCLIµÇ¼³¢ÊÔÆÚ¼ä×ÊÔ´·ÖÅä²»ÕýÈ·Ôì³ÉµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ý¶ÔÊÜÓ°ÏìµÄÉ豸ִÐдóÁ¿µÇ¼³¢ÊÔÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼Ö»ؾø·þÎñ£¨DoS£©¡£
CVE-2020-3175
Cisco MDS 9000ϵÁжà²ã»¥»»»ú»Ø¾ø·þÎñ·ì϶¡£¸Ã·ì϶ÊÇÓÉÓÚ×ÊԴʹÓýÚÔì²»µ±Ôì³ÉµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÒԺܸߵĿìÂʽ«Á÷Á¿·¢Ë͵½ÊÜÓ°ÏìÉ豸µÄÖÎÀí½Ó¿Ú£¨mgmt0£©À´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶¿ÉÄܻᵼÖ»ؾø·þÎñ¡£
CVE-2020-3167
Cisco FXOSºÍUCS ManagerÈí¼þCLIºÅÁî×¢Èë·ì϶¡£¸Ã·ì϶ÊÇÓÉÓÚÊäÈëÑéÖ¤²»¼°ËùÖ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚºÅÁîÖÐÔ̺¬¶ñÒâ²ÎÊýÀ´ÀûÓô˷ì϶¡£³É¹¦µÄÀûÓÿÉÄÜʹ¹¥»÷ÕßÄܹ»Ê¹Óõ±Ç°µÇ¼Óû§µÄÌØÈ¨Ôڵײã²Ù×÷ϵͳÉÏÕë¶Ô³ýCisco UCS 6400 Series Fabric InterconnectsÖ®±íµÄËùÓÐÊÜÓ°ÏìÆ½Ì¨Ö´ÐÐÌØÈ¨ºÅÁî¡£ÔÚCisco UCS 6400 Series Fabric InterconnectsÉÏ£¬ÒÔrootÌØÈ¨Ö´ÐкÅÁî¡£
CVE-2020-3171
Cisco FXOSºÍUCS ManagerÈí¼þ±¾µØÖÎÀíCLIºÅÁî×¢Èë·ì϶¡£¸Ã·ì϶ÊÇÓÉÓÚÊäÈëÑéÖ¤²»¼°ËùÖ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚºÅÁîÖÐÔ̺¬¶ñÒâ²ÎÊýÀ´ÀûÓô˷ì϶¡£³É¹¦µÄÀûÓÿÉÄÜʹ¹¥»÷ÕßÄܹ»Ê¹Óõ±Ç°µÇ¼Óû§µÄÌØÈ¨Ôڵײã²Ù×÷ϵͳÉÏÕë¶Ô³ýCisco UCS 6400 Series Fabric InterconnectsÖ®±íµÄËùÓÐÊÜÓ°ÏìÆ½Ì¨Ö´ÐÐÌØÈ¨ºÅÁî¡£ÔÚCisco UCS 6400 Series Fabric InterconnectsÉÏ£¬ÒÔrootÌØÈ¨Ö´ÐÐ×¢ÈëµÄºÅÁî¡£
CVE-2020-3172
Cisco FXOSÈí¼þºÍCisco NX-OSÈí¼þʵÏÖµÄCDPºÍ̸´æÔÚËÁÒâ´úÂëÖ´Ðкͻؾø·þÎñ·ì϶¡£¸Ã·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þ´¦ÖÃCDPºÍ̸ÐÂÎÅʱ¶Ìȱ²é³ËùÖ¡£¹¥»÷ÕßÄܹ»Í¨¹ý½«¶ñÒâµÄCDPÊý¾Ý°ü·¢Ë͵½ÊÜÓ°ÏìµÄÉ豸À´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶¿ÉÄÜÒÔrootÓû§Éí·ÝÖ´ÐÐËÁÒâ´úÂë»òµ¼Ö»ؾø·þÎñ£¨DoS£©¡£
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-ucs-cli-cmdinj
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-nexus-1000v-dos
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-mds-ovrld-dos
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-fxos-ucs-cmdinj
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-fxos-ucs-cli-cmdinj
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-fxos-nxos-cdp
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x


¾©¹«Íø°²±¸11010802024551ºÅ