?Cisco | IOS ºÍ IOS XE¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-09-25

0x00 ·ì϶¸ÅÊö

CiscoÔÚ2020Äê09ÔÂ24ÈÕÖÜËİ䲼ÁË42¸ö°²È«¸üÐÂÀ´½¨¸´Æä¶à¸ö²úÆ·Öеݲȫ·ì϶¡£ÕâЩ·ì϶¿ÉÄܻᵼÖ»ؾø·þÎñ¡¢Îļþ¸²¸Ç¡¢ÊäÈëÑéÖ¤¹¥»÷ºÍËÁÒâ´úÂëÖ´ÐеÈ¡£ÆäÖÐÓÐ29¸ö·ì϶µÄµÈ¼¶Îª¸ßΣ£¬Áí±í13¸öÊÇÖÐΣ¡£

0x01 ·ì϶ÏêÇé

ͼƬ.png

 

CiscoÕâ´Î°ä²¼µÄ°²È«·ì϶ÈçÏ£º

 

·ì϶±àºÅ

·ìϼûû³Æ

ÑϳÁˮƽ

°ä²¼ÈÕÆÚ

CVE-2020-3421
  CVE-2020-3480

»ùÓÚCisco IOS XEÈí¼þÇøÓòµÄ·À»ðǽ»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3417

Cisco IOS XEÈí¼þËÁÒâ´úÂëÖ´Ðзì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3429

Catalyst 9000ϵÁÐWPA»Ø¾ø·þÎñ·ì϶µÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3400

Cisco IOS XEÈí¼þWeb UIÊÚÈ¨ÈÆ¹ý·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3408

Cisco IOSºÍIOS XEÈí¼þ²ð·ÖDNS»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3524

Cisco IOS XE ROM¼à¶½Æ÷Èí¼þ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3409

Cisco IOSºÍIOS XEÈí¼þPROFINET»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3359

Catalyst 9800ϵÁÐÎÞÏß½ÚÔìÆ÷µÄCisco IOS XEÈí¼þ¶à²¥DNS»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3465

Cisco IOS XEÈí¼þÒÔÌ«Íø¿ò¼Ü»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3422

Cisco IOS XEÈí¼þIP·þÎñ¼¶±ðºÍ̸»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3492

Catalyst 9800ϵÁеÄCisco IOS XEÈí¼þºÍCisco WLC Flexible NetFlow°æ±¾9µÄCisco AireOSÈí¼þ»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3510

Catalyst 9200ϵÁл¥»»»úµÄCisco IOS XEÈí¼þÉ¡ÏÎ½ÓÆ÷»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3416
  CVE-2020-3513

ÓÃÓÚCisco ASR 900ϵÁзÓÉ»¥»»»ú´¦ÖÃÆ÷µÄCisco IOS XEÈí¼þ3ËÁÒâ´úÂëÖ´Ðзì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3511

Cisco IOSºÍIOS XEÈí¼þISDN Q.931»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3390

Catalyst 9000ϵÁÐSNMPÏÝÚ廨¾ø·þÎñ·ì϶µÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3509

ÓÃÓÚCisco cBR-8ÈںϿíÒý·ÓÉÆ÷µÄCisco   IOS XEÈí¼þDHCP»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3141
  CVE-2020-3425

Cisco IOS XEÈí¼þÌØÈ¨Éý¼¶·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3512

Cisco IOSºÍIOS XEÈí¼þPROFINETÁ´Â·²ã·¢ÏÖºÍ̸»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3426

ÓÃÓÚCisco¹¤ÒµÂ·ÓÉÆ÷µÄCisco   IOSÈí¼þVirtual-LPWAδ¾­ÊÚȨµÄ½Ó¼û·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3508

ÓÃÓÚCisco ASR 1000ϵÁÐ20   GbpsǶÈëʽ·þÎñ´¦ÖÃÆ÷IP ARP»Ø¾ø·þÎñ·ì϶µÄCisco   IOS XEÈí¼þ

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3428

Catalyst 9000ϵÁÐWLAN±¾µØ·ÖÎö»Ø¾ø·þÎñ·ì϶µÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3407

Cisco IOS XEÈí¼þRESTCONFºÍNETCONF-YANG½Ó¼û½ÚÔìÁÐ±í»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3486
  CVE-2020-3487

Catalyst 9000ϵÁÐCAPWAP»Ø¾ø·þÎñ·ì϶µÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3399

Catalyst 9000ϵÁÐCAPWAP»Ø¾ø·þÎñ·ì϶µÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3552

Cisco Aironet½ÓÈëµãÒÔÌ«ÍøÓÐÏ߿ͻ§¶Ë»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3560

Cisco Aironet½ÓÈëµãUDP·ººé»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3527

Cisco Catalyst 9200ϵÁл¥»»»ú³¬´óÖ¡»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3414

ÓÃÓÚCisco 4461¼¯³É·þÎñ·ÓÉÆ÷µÄCisco   IOS XEÈí¼þ»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3526

Cisco IOS XEÈí¼þͨÓÃÊ¢¿ªÕ½Êõ·þÎñÒýÇæ»Ø¾ø·þÎñ·ì϶

¸ß

2020Äê9ÔÂ24ÈÕ

CVE-2020-3503

Cisco IOS XEÈí¼þÀ´±öShellδ¾­ÊÚȨµÄÎļþϵͳ½Ó¼û·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3396

Cisco IOS XEÈí¼þIOx·Ã¿Í±í¿ÇUSB SSD¶¨Ãû¿Õ¼ä± £»¤ÌØÈ¨Éý¼¶·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3393

Cisco IOS XEÈí¼þIOxÀûÓ÷¨Ê½ÍйÜÌØÈ¨Éý¼¶·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3404

Cisco IOS XEÈí¼þÔÞ³ÉÁîÅÆÈÆ¹ý·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3403

Cisco IOS XEÈí¼þºÅÁî×¢Èë·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3474
  CVE-2020-3475

Cisco IOS XEÈí¼þWebÖÎÀí¿ò¼Ü·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3423

Cisco IOS XEÈí¼þËÁÒâ´úÂëÖ´Ðзì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3479

Cisco IOSºÍIOS XEÈí¼þMP-BGP EVPN»Ø¾ø·þÎñ·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3477

Cisco IOSºÍIOS XEÈí¼þÐÅϢй¶·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3476

Cisco IOS XEÈí¼þËÁÒâÎļþ¸²¸Ç·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3418

Catalyst 9000ϵÁеÄCisco IOS XEÎÞÏß½ÚÔìÆ÷Èí¼þ²»µ±µÄ½Ó¼û½ÚÔì·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3559

Cisco Aironet½ÓÈëµãÉí·ÝÑéÖ¤ºéË®»Ø¾ø·þÎñ·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ

CVE-2020-3516

Cisco IOS XEÈí¼þWeb UIÊäÈëÑéÖ¤²»µ±·ì϶

ÖÐ

2020Äê9ÔÂ24ÈÕ


²¿ÃÅ·ì϶ÏêÇéÈçÏ£º

Cisco IOS XE»ùÓÚÈí¼þÇøÓòµÄ·À»ðǽ»Ø¾ø·þÎñ·ì϶£¨CVE-2020-3421£©

¸Ã·ì϶ÊÇÓÉÓÚͨ¹ýÉ豸δÆëÈ«´¦ÖõÚ4²ãÊý¾Ý°üËùÖ£¬¹¥»÷ÕßÄܹ»Í¨¹ýÉ豸·¢ËͿ϶¨°¤´ÎµÄÁ÷Á¿Ä£Ê½À´ÀûÓô˷ì϶¡£

³É¹¦ÀûÓø÷ì϶¿ÉÄÜʹ¹¥»÷Õß³ÁмÓÔØÉ豸£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£¸Ã·ì϶CVSSÆÀ·Ö8.6·Ö£¬·ì϶ӰÏìµÈ¼¶¸ß¡£Ä¿Ç°Ë¼¿ÆÒѾ­°ä²¼Ïàʶ¾ö´Ë·ì϶µÄÈí¼þ¸üС£

·ì϶ϸ½Ú£º

Cisco IOS XE»ùÓÚÈí¼þÇøÓòµÄ·À»ðǽ»Ø¾ø·þÎñ·ì϶ÈôÊÇÔڲ鳭²ÎÊýÓ³ÉäÏÂÅäÖÃÁËlog dropped-packetsÖ°ÄÜ£¬ÔòÉ豸»áÊܵ½Ó°Ïì¡£Äܹ»Í¨¹ýµÇ¼É豸²¢Ê¹ÓÃshow run | section parameter-map²ÎÊýÓ³ÉäºÅÁîÀ´ÑéÖ¤ÊÇ·ñÅäÖÃÁËlog dropped-packetsÖ°ÄÜ¡£ÈôÊÇÊä³öÔ̺¬ÈκδøÓÐlog dropped-packetsµÄÐУ¬Ôò°µÊ¾É豸Ò×Êܹ¥»÷¡£

ÒÔÏÂʾÀýÏÔʾÁËÒ×Êܹ¥»÷µÄÉ豸ÅäÖã¬ÆäÖÐÔÚÈ«¾Ö²é³­Õ½Êõ»ò×Ô½ç˵¶¨ÃûµÄ²é³­Õ½ÊõÉÏÆôÓÃÁËlog dropped-packetsÖ°ÄÜ£¨ÈôÊÇÅäÖÃÖгöÏÖÁËÆäÖÐÈκÎÒ»¸ö£¬ÔòÉ豸Ò×Êܹ¥»÷£©£º

ͼƬ.png

 

Cisco IOS XE»ùÓÚÈí¼þÇøÓòµÄ·À»ðǽ»Ø¾ø·þÎñ·ì϶£¨CVE-2020-3480£©

¸Ã·ì϶ÊÇÓÉÓÚͨ¹ýÉ豸δÆëÈ«´¦ÖõÚ4²ãÊý¾Ý°üËùÖ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÉ豸·¢ËͿ϶¨°¤´ÎµÄÁ÷Á¿Ä£Ê½À´ÀûÓô˷ì϶¡£

³É¹¦ÀûÓø÷ì϶¿ÉÄÜʹ¹¥»÷Õßµ¼ÖÂÉ豸ÖÕ³¡Í¨¹ý·À»ðǽת·¢Á÷Á¿£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£¸Ã·ì϶CVSSÆÀ·Ö8.6·Ö£¬·ì϶ӰÏìµÈ¼¶¸ß¡£Ä¿Ç°Ë¼¿ÆÒѾ­°ä²¼Ïàʶ¾ö´Ë·ì϶µÄÈí¼þ¸üС£

·ì϶ϸ½Ú£º

ÈôÊÇÔڲ鳭²ÎÊýͼÏÂÅäÖÃone-minute highÖ°ÄÜ£¬ÔòÉ豸»áÊܵ½Ó°Ïì¡£ÖÎÀíÔ±Äܹ»Í¨¹ýµÇ¼É豸²¢Ê¹ÓÃshow run | section parameter-map ºÅÁîÀ´ÑéÖ¤´Ë·ì϶¡£ÈôÊÇÊä³öÔ̺¬one-minute highµÄÈκÎÐУ¬ÔòÉ豸Ò×Êܹ¥»÷¡£ÈçÏÂËùʾ£º

ͼƬ.png

Cisco IOS XEËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-3417£©

´Ë·ì϶ÊÇÓÉÓÚÆô¶¯¾ç±¾ÔÚÉèÖÃÌØ¶¨ROM monitor (ROMMON)±äÁ¿Ê±²»ÕýÈ·µÄÑéÖ¤¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔڵײãϵͳ(OS)µÄÌØ¶¨Ä¿Â¼ÖÐ×°ÖôúÂë²¢ÉèÖÃÌØ¶¨µÄROMMON±äÁ¿À´ÀûÓô˷ì϶¡£ÒªÀûÓÃÕâ¸ö·ì϶£¬¹¥»÷Õß±ØÒªÔ¶³Ì½Ó¼ûÉ豸£¬»òÕß¶ÔÉ豸ӵÓÐÎïÀí½Ó¼ûȨÏÞ¡£

³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔڵײãϵͳÉÏÖ´ÐдúÂë¡£¸Ã·ì϶CVSSÆÀ·Ö6.8·Ö£¬·ì϶ӰÏìµÈ¼¶¸ß¡£Ä¿Ç°Ë¼¿ÆÒѾ­°ä²¼Ïàʶ¾ö´Ë·ì϶µÄÈí¼þ¸üС£

 

0x02 ´ëÖý¨Òé

ĿǰCisco¹Ù·½ÒѰ䲼Óйطì϶µÄ°²È«¸üУ¬ÎªÔ®ÊÖÈ·¶¨Cisco IOSºÍIOS XEÈí¼þÖеķì϶·çÏÕ£¬CiscoÌṩÁËCisco Software Checker¹¤¾ßÀ´¼ø±ðÓ°ÏìÌØ¶¨Èí¼þ°æ±¾µÄËùÓÐCisco°²È«·ì϶£¬ÒÔ¼°Ã¿¸ö²¼¸æÖÐËùÊö·ì϶µÄ¿É½¨¸´µÄ×îÔç°æ±¾¡£ÈôÊǺÏÓ㬸ù¤¾ß»¹»á·µ»Ø×îÔçµÄ¿¯Ðаæ£¬¸Ã¿¯Ðа潨¸´ÁËËùÓÐÒÑÈ·¶¨µÄ´«µÝÖÐÃèÊöµÄËùÓзì϶¡£

Äܹ»Ê¹ÓÃCisco Software Checker¹¤¾ß£º

1.   Ñ¡ÔñÒ»¸öϵͳµÄÒ»¸ö»òÕß¶à¸ö°æ±¾½øÐзì϶²éÎÊ¡££¨¿Éƾ¾Ý·ì϶µÄÑϳÁµÈ¼¶½øÐвéÎÊ£©

2.   ÉÏ´«°æ±¾ÎļþÁÐ±í£¨.txtÎļþ£©½øÐзì϶²éÎÊ¡£

3.   ÊäÈëshow versionºÅÁîÊä³ö¡£

Èçͼ£º

ͼƬ.png

Cisco Software Checker¹¤¾ßÁ´½Ó£º

https://tools.Cisco.com/security/center/softwarechecker.x

°²È«°æ±¾ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/find/

 

0x03 ²Î¿¼Á´½Ó

https://tools.Cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=50#~Vulnerabilities

https://tools.Cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-sa-zbfw-94ckG4G#fs

https://tools.Cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-sa-xbace-OnCEbyS

https://threatpost.com/Cisco-patches-bugs/159537/

0x04 ¹¦·òÏß

2020-09-24  Cisco°ä²¼°²È«²¼¸æ

2020-09-25  VSRC°ä²¼°²È«¹«¸æ

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



ͼƬ.png