¡¾Îó²îͨ¸æ¡¿Cisco¶à¸ö²úÆ·¸ßΣÎó²îͨ¸æ
2020-11-20
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½CiscoÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´Æä¶à¸ö²úÆ·ºÍ×é¼þÖеÄÇå¾²Îó²î¡£±¾´Î¸üÐÂÐÞ¸´µÄÇå¾²Îó²îÒ»¹²19¸ö£¬ÆäÖÐÓÐ3¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬3¸öÎó²îÆÀ¼¶Îª¸ßΣ£¬13¸öÎó²îÆÀ¼¶ÎªÖÐΣ¡£3¸öÑÏÖØÎó²îÐÎòÈçÏ£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
Cisco IMCÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3470£©£º
˼¿Æ¼¯³ÉÖÎÀí¿ØÖÆÆ÷£¨IMC£©µÄAPIÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î,ÓÉÓÚ¶ÔÓû§ÊäÈëÄÚÈÝd Ñé֤ȱ·¦Ëùµ¼Ö£»Î´¾ÊÚȨµÄ¹¥»÷Õß¿Éͨ¹ýÏòÊÜÓ°ÏìµÄϵͳ·¢ËÍÌØÖÆµÄHTTPÇëÇó£¬ÀÖ³ÉʹÓôËÎó²î¿ÉʹÓÃÖÎÀíԱȨÏÞÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
Cisco IoT FND REST APIÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-3531£©:
Cisco IoT Field Network Director£¨FND£©µÄREST APIÖб£´æÑéÖ¤ÈÆ¹ýÎó²î¡£Î´¾ÊÚȨµÄ¹¥»÷Õßͨ¹ý»ñÈ¡¿çÕ¾µãÇëÇóαÔ죨CSRF£©ÁîÅÆ²¢·¢ËÍÌØÖÆÊý¾Ý°ü£¬¿É»á¼ûÊÜÓ°ÏìϵͳµÄºó¶ËÊý¾Ý½Ó¿Ú£¬´Ó¶ø»ñÈ¡Ãô¸ÐÊý¾Ý¼°×°±¸²Ù×÷ȨÏÞ¡£
Cisco DNA Spaces ConnectorÏÂÁî×¢ÈëÎó²î£¨CVE-2020-3586£©£º
˼¿ÆDNA¿Õ¼äÅþÁ¬Æ÷µÄWebÖÎÀíÒ³Ãæ±£´æÏÂÁî×¢ÈëÎó²î£¬ÓÉÓÚϵͳ¶ÔÓû§ÊäÈëµÄÑé֤ȱ·¦Ëùµ¼Ö£¬Î´¾ÊÚȨµÄÔ¶³Ì¹¥»÷Õßͨ¹ýÏòÊÜÓ°ÏìµÄ·þÎñÆ÷·¢ËÍÌØÖÆµÄHTTPÇëÇó£¬ÀÖ³ÉʹÓôËÎó²îÄܹ»ÔÚÄ¿µÄ²Ù×÷ϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£
²Î¿¼Á´½Ó£º
https://tools.cisco.com/security/center/publicationListing.x
¶þ. Ó°Ïì¹æÄ£
Cisco IMCÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3470£©
ÊÜÓ°Ïì°æ±¾
5000 Series Enterprise Network Compute System (ENCS)ƽ̨
Standalone mode쵀UCS C-Series Rack Servers
UCS E-Series Servers
Standalone mode쵀UCS S-Series Servers
Cisco IoT FND REST APIÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-3531£©
ÊÜÓ°Ïì°æ±¾
Cisco IoT FND < 4.6.1
²»ÊÜÓ°Ïì°æ±¾
Cisco IoT FND >= 4.6.1
Cisco DNA Spaces ConnectorÏÂÁî×¢ÈëÎó²î£¨CVE-2020-3586£©
ÊÜÓ°Ïì°æ±¾
Cisco DNA Spaces Connector <= 2.2
²»ÊÜÓ°Ïì°æ±¾
Cisco DNA Spaces Connector >= 2.3
Èý. Îó²î·À»¤
3.1 ¹Ù·½Éý¼¶
ÏÖÔÚ˼¿Æ¹Ù·½ÒÑÕë¶Ô´Ë´Îͨ¸æµÄÎó²îÐû²¼ÁËÐÞ¸´°æ±¾£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£ºhttps://software.cisco.com/download/find
3.2 ÔÝʱ»º½â²½·¥
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨Í¨¹ýÉý¼¶¶ÔCVE-2020-3470¾ÙÐзÀ»¤£¬¿É½ûÓÃCisco IMC WebÖÎÀí½çÃæ¾ÙÐлº½â£º
ÒÔÏÂΪUCS C-Series ServerµÄÉèÖÃʾÀý£º
|
xxxxxx-bmc# scope http xxxxxx-bmc /http # set enabled no SSH is in enabled state. Disabling HTTP service xxxxxx-bmc /http *# commit xxxxxx-bmc /http # show detail HTTP Settings: HTTP Port: 80 HTTPS Port: 443 Timeout: 1800 Max Sessions: 4 Active Sessions: 0 Enabled: no HTTP Redirected: yes xxxxxx-bmc /http # exit |
×¢£º½«“enabled”ÉèÖÃΪ“no”½«¶Ï¿ªËùÓÐÔËÐÐÖеÄHTTPÅþÁ¬£¬ÇÒÎÞ·¨Í¨¹ýWebUI¾ÙÐеǼ¡£
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ40¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







