?Cisco | IOS ºÍ IOS XE¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-09-250x00 ·ì϶¸ÅÊö
CiscoÔÚ2020Äê09ÔÂ24ÈÕÖÜËİ䲼ÁË42¸ö°²È«¸üÐÂÀ´½¨¸´Æä¶à¸ö²úÆ·Öеݲȫ·ì϶¡£ÕâЩ·ì϶¿ÉÄܻᵼÖ»ؾø·þÎñ¡¢Îļþ¸²¸Ç¡¢ÊäÈëÑéÖ¤¹¥»÷ºÍËÁÒâ´úÂëÖ´Ðеȡ£ÆäÖÐÓÐ29¸ö·ì϶µÄµÈ¼¶Îª¸ßΣ£¬Áí±í13¸öÊÇÖÐΣ¡£
0x01 ·ì϶ÏêÇé

CiscoÕâ´Î°ä²¼µÄ°²È«·ì϶ÈçÏ£º
·ì϶±àºÅ | ·ìϼûû³Æ | ÑϳÁˮƽ | °ä²¼ÈÕÆÚ |
CVE-2020-3421 | »ùÓÚCisco IOS XEÈí¼þÇøÓòµÄ·À»ðǽ»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3417 | Cisco IOS XEÈí¼þËÁÒâ´úÂëÖ´Ðзì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3429 | Catalyst 9000ϵÁÐWPA»Ø¾ø·þÎñ·ì϶µÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3400 | Cisco IOS XEÈí¼þWeb UIÊÚÈ¨ÈÆ¹ý·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3408 | Cisco IOSºÍIOS XEÈí¼þ²ð·ÖDNS»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3524 | Cisco IOS XE ROM¼à¶½Æ÷Èí¼þ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3409 | Cisco IOSºÍIOS XEÈí¼þPROFINET»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3359 | Catalyst 9800ϵÁÐÎÞÏß½ÚÔìÆ÷µÄCisco IOS XEÈí¼þ¶à²¥DNS»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3465 | Cisco IOS XEÈí¼þÒÔÌ«Íø¿ò¼Ü»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3422 | Cisco IOS XEÈí¼þIP·þÎñ¼¶±ðºÍ̸»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3492 | Catalyst 9800ϵÁеÄCisco IOS XEÈí¼þºÍCisco WLC Flexible NetFlow°æ±¾9µÄCisco AireOSÈí¼þ»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3510 | Catalyst 9200ϵÁл¥»»»úµÄCisco IOS XEÈí¼þÉ¡ÏÎ½ÓÆ÷»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3416 | ÓÃÓÚCisco ASR 900ϵÁзÓÉ»¥»»»ú´¦ÖÃÆ÷µÄCisco IOS XEÈí¼þ3ËÁÒâ´úÂëÖ´Ðзì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3511 | Cisco IOSºÍIOS XEÈí¼þISDN Q.931»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3390 | Catalyst 9000ϵÁÐSNMPÏÝÚ廨¾ø·þÎñ·ì϶µÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3509 | ÓÃÓÚCisco cBR-8ÈںϿíÒý·ÓÉÆ÷µÄCisco IOS XEÈí¼þDHCP»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3141 | Cisco IOS XEÈí¼þÌØÈ¨Éý¼¶·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3512 | Cisco IOSºÍIOS XEÈí¼þPROFINETÁ´Â·²ã·¢ÏÖºÍ̸»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3426 | ÓÃÓÚCisco¹¤ÒµÂ·ÓÉÆ÷µÄCisco IOSÈí¼þVirtual-LPWAδ¾ÊÚȨµÄ½Ó¼û·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3508 | ÓÃÓÚCisco ASR 1000ϵÁÐ20 GbpsǶÈëʽ·þÎñ´¦ÖÃÆ÷IP ARP»Ø¾ø·þÎñ·ì϶µÄCisco IOS XEÈí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3428 | Catalyst 9000ϵÁÐWLAN±¾µØ·ÖÎö»Ø¾ø·þÎñ·ì϶µÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3407 | Cisco IOS XEÈí¼þRESTCONFºÍNETCONF-YANG½Ó¼û½ÚÔìÁÐ±í»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3486 | Catalyst 9000ϵÁÐCAPWAP»Ø¾ø·þÎñ·ì϶µÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3399 | Catalyst 9000ϵÁÐCAPWAP»Ø¾ø·þÎñ·ì϶µÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3552 | Cisco Aironet½ÓÈëµãÒÔÌ«ÍøÓÐÏ߿ͻ§¶Ë»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3560 | Cisco Aironet½ÓÈëµãUDP·ººé»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3527 | Cisco Catalyst 9200ϵÁл¥»»»ú³¬´óÖ¡»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3414 | ÓÃÓÚCisco 4461¼¯³É·þÎñ·ÓÉÆ÷µÄCisco IOS XEÈí¼þ»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3526 | Cisco IOS XEÈí¼þͨÓÃÊ¢¿ªÕ½Êõ·þÎñÒýÇæ»Ø¾ø·þÎñ·ì϶ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3503 | Cisco IOS XEÈí¼þÀ´±öShellδ¾ÊÚȨµÄÎļþϵͳ½Ó¼û·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3396 | Cisco IOS XEÈí¼þIOx·Ã¿Í±í¿ÇUSB SSD¶¨Ãû¿Õ¼ä±£»¤ÌØÈ¨Éý¼¶·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3393 | Cisco IOS XEÈí¼þIOxÀûÓ÷¨Ê½ÍйÜÌØÈ¨Éý¼¶·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3404 | Cisco IOS XEÈí¼þÔÞ³ÉÁîÅÆÈÆ¹ý·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3403 | Cisco IOS XEÈí¼þºÅÁî×¢Èë·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3474 | Cisco IOS XEÈí¼þWebÖÎÀí¿ò¼Ü·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3423 | Cisco IOS XEÈí¼þËÁÒâ´úÂëÖ´Ðзì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3479 | Cisco IOSºÍIOS XEÈí¼þMP-BGP EVPN»Ø¾ø·þÎñ·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3477 | Cisco IOSºÍIOS XEÈí¼þÐÅϢй¶·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3476 | Cisco IOS XEÈí¼þËÁÒâÎļþ¸²¸Ç·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3418 | Catalyst 9000ϵÁеÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ²»µ±µÄ½Ó¼û½ÚÔì·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3559 | Cisco Aironet½ÓÈëµãÉí·ÝÑéÖ¤ºéË®»Ø¾ø·þÎñ·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3516 | Cisco IOS XEÈí¼þWeb UIÊäÈëÑéÖ¤²»µ±·ì϶ | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
²¿ÃÅ·ì϶ÏêÇéÈçÏ£º
Cisco IOS XE»ùÓÚÈí¼þÇøÓòµÄ·À»ðǽ»Ø¾ø·þÎñ·ì϶£¨CVE-2020-3421£©
¸Ã·ì϶ÊÇÓÉÓÚͨ¹ýÉ豸δÆëÈ«´¦ÖõÚ4²ãÊý¾Ý°üËùÖ£¬¹¥»÷ÕßÄܹ»Í¨¹ýÉ豸·¢ËͿ϶¨°¤´ÎµÄÁ÷Á¿Ä£Ê½À´ÀûÓô˷ì϶¡£
³É¹¦ÀûÓø÷ì϶¿ÉÄÜʹ¹¥»÷Õß³ÁмÓÔØÉ豸£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£¸Ã·ì϶CVSSÆÀ·Ö8.6·Ö£¬·ì϶ӰÏìµÈ¼¶¸ß¡£Ä¿Ç°Ë¼¿ÆÒѾ°ä²¼Ïàʶ¾ö´Ë·ì϶µÄÈí¼þ¸üС£
·ì϶ϸ½Ú£º
Cisco IOS XE»ùÓÚÈí¼þÇøÓòµÄ·À»ðǽ»Ø¾ø·þÎñ·ì϶ÈôÊÇÔڲ鳲ÎÊýÓ³ÉäÏÂÅäÖÃÁËlog dropped-packetsÖ°ÄÜ£¬ÔòÉ豸»áÊܵ½Ó°Ïì¡£Äܹ»Í¨¹ýµÇ¼É豸²¢Ê¹ÓÃshow run | section parameter-map²ÎÊýÓ³ÉäºÅÁîÀ´ÑéÖ¤ÊÇ·ñÅäÖÃÁËlog dropped-packetsÖ°ÄÜ¡£ÈôÊÇÊä³öÔ̺¬ÈκδøÓÐlog dropped-packetsµÄÐУ¬Ôò°µÊ¾É豸Ò×Êܹ¥»÷¡£
ÒÔÏÂʾÀýÏÔʾÁËÒ×Êܹ¥»÷µÄÉ豸ÅäÖã¬ÆäÖÐÔÚÈ«¾Ö²é³Õ½Êõ»ò×Ô½ç˵¶¨ÃûµÄ²é³Õ½ÊõÉÏÆôÓÃÁËlog dropped-packetsÖ°ÄÜ£¨ÈôÊÇÅäÖÃÖгöÏÖÁËÆäÖÐÈκÎÒ»¸ö£¬ÔòÉ豸Ò×Êܹ¥»÷£©£º

Cisco IOS XE»ùÓÚÈí¼þÇøÓòµÄ·À»ðǽ»Ø¾ø·þÎñ·ì϶£¨CVE-2020-3480£©
¸Ã·ì϶ÊÇÓÉÓÚͨ¹ýÉ豸δÆëÈ«´¦ÖõÚ4²ãÊý¾Ý°üËùÖ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÉ豸·¢ËͿ϶¨°¤´ÎµÄÁ÷Á¿Ä£Ê½À´ÀûÓô˷ì϶¡£
³É¹¦ÀûÓø÷ì϶¿ÉÄÜʹ¹¥»÷Õßµ¼ÖÂÉ豸ÖÕ³¡Í¨¹ý·À»ðǽת·¢Á÷Á¿£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£¸Ã·ì϶CVSSÆÀ·Ö8.6·Ö£¬·ì϶ӰÏìµÈ¼¶¸ß¡£Ä¿Ç°Ë¼¿ÆÒѾ°ä²¼Ïàʶ¾ö´Ë·ì϶µÄÈí¼þ¸üС£
·ì϶ϸ½Ú£º
ÈôÊÇÔڲ鳲ÎÊýͼÏÂÅäÖÃone-minute highÖ°ÄÜ£¬ÔòÉ豸»áÊܵ½Ó°Ïì¡£ÖÎÀíÔ±Äܹ»Í¨¹ýµÇ¼É豸²¢Ê¹ÓÃshow run | section parameter-map ºÅÁîÀ´ÑéÖ¤´Ë·ì϶¡£ÈôÊÇÊä³öÔ̺¬one-minute highµÄÈκÎÐУ¬ÔòÉ豸Ò×Êܹ¥»÷¡£ÈçÏÂËùʾ£º

Cisco IOS XEËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-3417£©
´Ë·ì϶ÊÇÓÉÓÚÆô¶¯¾ç±¾ÔÚÉèÖÃÌØ¶¨ROM monitor (ROMMON)±äÁ¿Ê±²»ÕýÈ·µÄÑéÖ¤¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔڵײãϵͳ(OS)µÄÌØ¶¨Ä¿Â¼ÖÐ×°ÖôúÂë²¢ÉèÖÃÌØ¶¨µÄROMMON±äÁ¿À´ÀûÓô˷ì϶¡£ÒªÀûÓÃÕâ¸ö·ì϶£¬¹¥»÷Õß±ØÒªÔ¶³Ì½Ó¼ûÉ豸£¬»òÕß¶ÔÉ豸ӵÓÐÎïÀí½Ó¼ûȨÏÞ¡£
³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔڵײãϵͳÉÏÖ´ÐдúÂë¡£¸Ã·ì϶CVSSÆÀ·Ö6.8·Ö£¬·ì϶ӰÏìµÈ¼¶¸ß¡£Ä¿Ç°Ë¼¿ÆÒѾ°ä²¼Ïàʶ¾ö´Ë·ì϶µÄÈí¼þ¸üС£
0x02 ´ëÖý¨Òé
ĿǰCisco¹Ù·½ÒѰ䲼Óйطì϶µÄ°²È«¸üУ¬ÎªÔ®ÊÖÈ·¶¨Cisco IOSºÍIOS XEÈí¼þÖеķì϶·çÏÕ£¬CiscoÌṩÁËCisco Software Checker¹¤¾ßÀ´¼ø±ðÓ°ÏìÌØ¶¨Èí¼þ°æ±¾µÄËùÓÐCisco°²È«·ì϶£¬ÒÔ¼°Ã¿¸ö²¼¸æÖÐËùÊö·ì϶µÄ¿É½¨¸´µÄ×îÔç°æ±¾¡£ÈôÊǺÏÓ㬸ù¤¾ß»¹»á·µ»Ø×îÔçµÄ¿¯Ðа棬¸Ã¿¯Ðа潨¸´ÁËËùÓÐÒÑÈ·¶¨µÄ´«µÝÖÐÃèÊöµÄËùÓзì϶¡£
Äܹ»Ê¹ÓÃCisco Software Checker¹¤¾ß£º
1. Ñ¡ÔñÒ»¸öϵͳµÄÒ»¸ö»òÕß¶à¸ö°æ±¾½øÐзì϶²éÎÊ¡££¨¿Éƾ¾Ý·ì϶µÄÑϳÁµÈ¼¶½øÐвéÎÊ£©
2. ÉÏ´«°æ±¾ÎļþÁÐ±í£¨.txtÎļþ£©½øÐзì϶²éÎÊ¡£
3. ÊäÈëshow versionºÅÁîÊä³ö¡£
Èçͼ£º

Cisco Software Checker¹¤¾ßÁ´½Ó£º
https://tools.Cisco.com/security/center/softwarechecker.x
°²È«°æ±¾ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find/
0x03 ²Î¿¼Á´½Ó
https://tools.Cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=50#~Vulnerabilities
https://tools.Cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-sa-zbfw-94ckG4G#fs
https://tools.Cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-sa-xbace-OnCEbyS
https://threatpost.com/Cisco-patches-bugs/159537/
0x04 ¹¦·òÏß
2020-09-24 Cisco°ä²¼°²È«²¼¸æ
2020-09-25 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ