˼¿Æ½¨¸´ÆäSD-WAN½â¾ö¹æ»®ÖеĶà¸ö·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-03-19·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-3265£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.0£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3266£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3264£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÔËÐÐ×ÅCisco SD-WAN Solution Release 19.2.2֮ǰ°æ±¾µÄÒÔϲúÆ·£º
vBond Orchestrator Software
vEdge 100 Series Routers
vEdge 1000 Series Routers
vEdge 2000 Series Routers
vEdge 5000 Series Routers
vEdge Cloud Router Platform
vManage Network Management Software
vSmart Controller Software
·ì϶¸ÅÊö
Cisco SD-WAN SolutionÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ÍøÂçÀ©´ó½â¾ö¹æ»®¡£
½üÈÕ£¬Ë¼¿Æ°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËÆäSD-WAN½â¾ö¹æ»®ÖеÄÎå¸ö·ì϶£¬ÆäÖÐÔ̺¬Èý¸ö¸ßΣ·ì϶£¬¸ÅÊöÈçÏ£º
CVE-2020-3265
Cisco SD-WAN Solution software Release 19.2.2֮ǰ°æ±¾ÖдæÔÚȨÏÞÐí¿ÉºÍ½Ó¼û½ÚÔìÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»Óгä·Ö½øÐÐÊäÈëÑéÖ¤¡£±¾µØ¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄÒªÇóÀûÓø÷ì϶»ñÈ¡rootȨÏÞ¡£
CVE-2020-3266
Cisco SD-WAN Solution software Release 19.2.2֮ǰ°æ±¾ÖеÄCLI´æÔÚºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»Óгä·Ö½øÐÐÊäÈëÑéÖ¤¡£±¾µØ¹¥»÷Õß¿Éͨ¹ý½øÐÐÉí·ÝÑéÖ¤²¢Ìá½»ÌØÔìµÄÊäÈëÀûÓø÷ì϶ÒÔrootȨÏÞÖ´ÐкÅÁî¡£
CVE-2020-3264
Cisco SD-WAN Solution software Release 19.2.2֮ǰ°æ±¾ÖдæÔÚ»º³åÇøÃýÎó·ì϶£¬¸Ã·ì϶ԴÓÚ²»³ä·ÖµÄÊäÈëÑéÖ¤¡£±¾µØ¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄÁ÷Á¿ÀûÓø÷ì϶½Ó¼ûûÓÐÊÚȨµÄÐÅÏ¢»ò¶Ôϵͳ½øÐÐδÊÚȨµÄÅú¸Ä¡£
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwpresc-ySJGvE9
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwclici-cvrQpH9v
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwanbo-QKcABnS2
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x


¾©¹«Íø°²±¸11010802024551ºÅ