Cisco | 11Ô¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-11-190x00 Îó²î¸ÅÊö
2020Äê11ÔÂ18ÈÕ£¬£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬Æä¶à¸ö²úÆ·ºÍ×é¼þÖб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¡£±¾´ÎÐû²¼µÄÇå¾²Îó²î¹²¼Æ19¸ö£¬£¬£¬£¬£¬ÆäÖÐÓÐ3¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬£¬3¸öÎó²îÆÀ¼¶Îª¸ßΣ£¬£¬£¬£¬£¬13¸öÎó²îÆÀ¼¶ÎªÖÐΣ¡£¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
±¾´ÎÐû²¼µÄÇå¾²Îó²îÈçÏ£º
Îó²îÃû³Æ | ÆÀ¼¶ | CVE ID | Ðû²¼Ê±¼ä | °æ±¾ |
Cisco IMCÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ | CVE-2020-3470 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco DNA Spaces ConnectorÏÂÁî×¢ÈëÎó²î | ÑÏÖØ | CVE-2020-3586 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND REST APIÑéÖ¤ÈÆ¹ýÎó²î | ÑÏÖØ | CVE-2020-3531 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco Çå¾²Web×°±¸È¨ÏÞÉý¼¶Îó²î | ¸ßΣ | CVE-2020-3367 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND SOAP APIÊÚÈ¨ÈÆ¹ýÎó²î | ¸ßΣ | CVE-2020-26072 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FNDȱÉÙAPIÉí·ÝÑéÖ¤Îó²î | ¸ßΣ | CVE-2020-3392 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco Webex Meetings API¿çÕ¾¾ç±¾Îó²î | ÖÐΣ | CVE-2020-27126 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco Webex MeetingsºÍCisco Webex Meetings ServerÐÅϢй¶Îó²î | ÖÐΣ | CVE-2020-3441 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco Webex MeetingsºÍCisco Webex Meetings Serverδ¾ÊÚȨµÄÒôƵÐÅϢй¶Îó²î | ÖÐΣ | CVE-2020-3471 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco Webex MeetingsºÍCisco Webex Meetings Server GhostÅþÁ¬Îó²î | ÖÐΣ | CVE-2020-3419 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco ÍøÕæCEÈí¼þºÍRoomOSÈí¼þδ¾ÊÚȨµÄÁîÅÆÌìÉúÎó²î | ÖÐΣ | CVE-2020-26068 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND¿çÕ¾µã¾ç±¾Îó²î | ÖÐΣ | CVE-2020-26081 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FNDÓò»á¼û¿ØÖƲ»µ±Îó²î | ÖÐΣ | CVE-2020-26080 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FNDÐÅϢй¶Îó²î | ÖÐΣ | CVE-2020-26076 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND REST APIÊäÈëÑéÖ¤Îó²îȱ·¦ | ÖÐΣ | CVE-2020-26075 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FNDδÊܱ£»£»£»¤µÄƾ֤´æ´¢Îó²î | ÖÐΣ | CVE-2020-26079 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FNDÎļþÁýÕÖÎó²î | ÖÐΣ | CVE-2020-26078 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND»á¼û¿ØÖƲ»µ±Îó²î | ÖÐΣ | CVE-2020-26077 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco ExpresswayÐÅϢй¶Îó²î | ÖÐΣ | CVE-2020-3482 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
ÑÏÖØÎó²îÈçÏ£º
Cisco IMCÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3470£©
¸ÃÎó²îÊǶÔÓû§µÄÊäÈëÑéÖ¤¹ýʧµ¼Öµģ¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍ¿ÉÄܵ¼Ö»º³åÇøÒç³öµÄ¶ñÒâHTTPÇëÇóµ½ÊÜÓ°ÏìϵͳÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÖÎÀíԱȨÏÞÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ££º
5000 Series Enterprise Network Compute System (ENCS)ƽ̨
Standalone mode쵀UCS C-Series Rack Servers
UCS E-Series Servers
Standalone mode쵀UCS S-Series Servers
»º½â²½·¥£º
½ûÓÃCisco IMC WebÖÎÀí½çÃæ¡£¡£¡£¡£¡£¡£¡£¡£ÒÔÏÂÊÇUCS C-Series ServerÉϵÄÉèÖÃʾÀý£º
xxxxxx-bmc# scope http
xxxxxx-bmc /http # set enabled no
SSH is in enabled state. Disabling HTTP service
xxxxxx-bmc /http *# commit
xxxxxx-bmc /http # show detail
HTTP Settings:
HTTP Port: 80
HTTPS Port: 443
Timeout: 1800
Max Sessions: 4
Active Sessions: 0
Enabled: no
HTTP Redirected: yes
xxxxxx-bmc /http # exit
×¢ÖØ£º½«¡°enabled¡±ÉèÖÃΪ¡°no¡±½«¶Ï¿ªËùÓÐÔËÐÐÖеÄHTTPÅþÁ¬£¬£¬£¬£¬£¬²¢ÎÞ·¨Í¨¹ýWebUIµÇ¼¡£¡£¡£¡£¡£¡£¡£¡£
ÏêÇéÁ´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-api-rce-UXwpeDHd
Cisco DNA Spaces ConnectorÏÂÁî×¢ÈëÎó²î£¨CVE-2020-3586£©
¸ÃÎó²îÊÇ»ùÓÚWebµÄÖÎÀí½çÃæÁÙÓû§ÊäÈëÑé֤ȱ·¦Ôì³ÉµÄ£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.4¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏò»ùÓÚWebµÄÖÎÀí½çÃæ·¢ËͶñÒâHTTPÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»Ôڵײã²Ù×÷ϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ££º
Cisco DNA Spaces Connector 2.2¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺
¸üÐÂÖÁCisco DNA Spaces Connector 2.3¼°¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
ÏêÇéÁ´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dna-cmd-injection-rrAYzOwc
Cisco IoT FND REST APIÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-3531£©
¸ÃÎó²îÊÇÎÞ·¨×¼È·ÑéÖ¤REST APIŲÓõ¼Öµģ¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý»ñÈ¡¿çÕ¾µãÇëÇóαÔ죨CSRF£©ÁîÅÆ²¢Á¬ÏµREST APIÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»»á¼ûÊÜÓ°Ïì×°±¸µÄÊý¾Ý¿â²¢¶ÁÈ¡¡¢¸ü¸Ä»òɾ³ýÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ££º
Cisco IoT FND 4.6.1֮ǰµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺
¸üÐÂÖÁCisco IoT FND 4.6.1¼°¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
ÏêÇéÁ´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-FND-BCK-GHkPNZ5F
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚCiscoÒѾÐû²¼ÁËÏà¹Ø¸üУ¬£¬£¬£¬£¬½¨Òé²Î¿¼¹Ù·½Í¨¸æÊµÊ±ÐÞ¸´¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØµØµã£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3531
0x04 ʱ¼äÏß
2020-11-18 CiscoÐû²¼Ç徲ͨ¸æ
2020-11-19 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ