Cisco | Security Manager¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-11-170x00 ·ì϶¸ÅÊö
2020Äê11ÔÂ16ÈÕ£¬Cisco°ä²¼°²È«¹«¸æ£¬Security ManagerÖдæÔÚ¶à¸ö°²È«·ì϶¡£·ì϶׷×ÙΪCVE-2020-27125¡¢CVE-2020-27130ºÍCVE-2020-27131¡£
0x01 ·ì϶ÏêÇé

Cisco Security ManagerΪCisco°²È«ÖÎÀíÆ÷£¬Ëü¿É½«Õ½ÊõÅäÖù¤×÷ºÍÕë¶ÔCisco°²È«ÊýÊðµÄ½ÚÔì´ëÊ©½øÐм¯Öд¦Ö㬴Ӷø¸ßЧµØÖÎÀíÆóÒµ°²È«¡£
±¾´Î°ä²¼µÄ·ì϶ÏêÇéÈçÏ£º
²úÆ· | CVE ID | ·ìϼûû³Æ | ÆÀ·Ö | ÑϳÁˮƽ |
Cisco Security Manager | CVE-2020-27125 | Cisco Security Manager¾²Ì¬Ö¤Êé·ì϶ | 7.4 | ¸ßΣ |
CVE-2020-27130 | Cisco Security Managerõè¾¶±éÀú·ì϶ | 9.1 | ÑϳÁ | |
CVE-2020-27131 | Cisco Security Manager Java·´ÐòÁл¯·ì϶ | 8.1 | ¸ßΣ |
Ó°ÏìÁìÓò£º
Cisco Security Manager 4.21¼°Ö®Ç°°æ±¾¡£
Cisco Security Manager¾²Ì¬Ö¤Êé·ì϶£¨CVE-2020-27125£©
¸Ã·ì϶ÊǾ²Ì¬Í´´¦Ã»ÓÐÌṩ×ã¹»µÄ±£»¤Ôì³ÉµÄ£¬¹¥»÷ÕßÄܹ»Í¨¹ý²é¿´Ô´´úÂëÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»²é¿´¾²Ì¬Í´´¦µÈÃô¸ÐÐÅÏ¢£¬²¢ÀûÓÃÍ´´¦½øÐй¥»÷¡£
·ì϶ÏêÇéÈçÏ£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csm-rce-8gjUz9fW
Cisco Security Managerõè¾¶±éÀú·ì϶£¨CVE-2020-27130£©
¸Ã·ì϶ÊÇÉ豸¶ÔÒªÇóÖеÄĿ¼±éÀú×Ö·ûÐòÁеÄÑéÖ¤²»ÕýÈ·Ôì³ÉµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶¿ÉÄÜʹ¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸¸ßµÍÔØËÁÒâÎļþ¡£
·ì϶ÏêÇéÈçÏ£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csm-path-trav-NgeRnqgR
Cisco Security Manager Java·´ÐòÁл¯·ì϶£¨CVE-2020-27131£©
Cisco Security ManagerʹÓõÄJava·´ÐòÁл¯Ö°ÄÜÖдæÔÚ¶à¸ö°²È«·ì϶¡£ÕâЩ·ì϶ʹµÃÓû§ÌṩµÄÄÚÈݱ»²»°²È«µØ·´ÐòÁл¯¡£¹¥»÷ÕßÄܹ»Í¨¹ý½«¶ñÒâµÄÐòÁл¯Java¶ÔÏó·¢Ë͸øÊÜÓ°ÏìµÄϵͳÉϵÄÌØ¶¨ÕìÌýÆ÷À´ÀûÓÃÕâЩ·ì϶¡£³É¹¦ÀûÓô˷ì϶¿ÉÄÜʹ¹¥»÷ÕßÔÚÖ¸±êWindowsÖ÷»úÉÏʹÓÃNT AUTHORITY\SYSTEM£¨ÄÚÖÃϵͳÖÎÀíÕË»§£©È¨ÏÞÔÚÉ豸ÉÏÖ´ÐÐËÁÒâºÅÁî¡£
·ì϶ÏêÇéÈçÏ£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csm-java-rce-mWJEedcD?
0x02 ´ëÖý¨Òé
ĿǰCiscoÒÑÔÚCisco Security Manager 4.22Öн¨¸´ÁËCVE-2020-27125ºÍCVE-2020-27130£¬½¨Òéʵʱ¸üС£
Cisco´òËãÔÚCisco Security Manager 4.23Öн¨¸´CVE-2020-27131¼°ÆäËüJava·´ÐòÁл¯Ö°ÄÜÖеķì϶¡£
ÏÂÔØµØÖ·£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27131
0x04 ¹¦·òÏß
2020-11-16 Cisco°ä²¼°²È«²¼¸æ
2020-11-17 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ