¡¾Îó²îͨ¸æ¡¿Cisco 1Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-01-210x00 Îó²î¸ÅÊö
2021Äê01ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬¹ûÕæÁËCisco SD-WAN¡¢DNA CenterºÍSmart Software Manager SatelliteµÈ¶à¸ö²úÆ·ÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé

Cisco SD-WANÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1260¡¢CVE-2021-1261¡¢CVE-2021-1262¡¢CVE-2021-1263¡¢CVE-2021-1298ºÍCVE-2021-1299£©
Cisco SD-WAN²úÆ·Öб£´æ¶à¸öÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬CVE-2021-1260¡¢CVE-2021-1261¡¢CVE-2021-1262¡¢CVE-2021-1263ºÍCVE-2021-1298µÄCVSSÆÀ·ÖÔÚ5.3-7.8Ö®¼ä£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¶ÔÊÜÓ°ÏìµÄ×°±¸Ö´ÐÐÏÂÁî×¢Èë¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕ¹¥»÷Õß¿ÉÒÔÔÚ×°±¸ÉÏÒÔrootȨÏÞÖ´ÐÐijЩ²Ù×÷¡£¡£¡£¡£¡£¡£¡£¡£
ÖµµÃ×¢ÖØµÄÊÇCisco SD-WAN vManageÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1299£©£¬£¬£¬£¬£¬£¬£¬£¬Æä±£´æÓÚ»ùÓÚWebµÄÖÎÀí½çÃæÖУ¬£¬£¬£¬£¬£¬£¬£¬ÊÇÓû§¶Ô×°±¸Ä£°åÉèÖÃÌṩµÄÐÅÏ¢µÄÊäÈëÑéÖ¤²»×¼È·Ôì³ÉµÄ£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.9¡£¡£¡£¡£¡£¡£¡£¡£
¹¥»÷Õß¿ÉÒÔͨ¹ýÏò×°±¸Ä£°åÉèÖÃÌá½»¶ñÒâÐÅÏ¢À´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÊÜÓ°ÏìϵͳµÄrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
ÈôÊÇÕýÔÚÔËÐÐÒ×ÊÜÓ°ÏìµÄCisco SD-WAN°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÔòÕâЩÎó²î»áÓ°ÏìÒÔÏÂCisco²úÆ·£º
SD-WAN vBond OrchestratorÈí¼þ
SD-WAN vEdgeÔÆÂ·ÓÉÆ÷
SD-WAN vEdge·ÓÉÆ÷
SD-WAN vManageÈí¼þ
SD-WAN vSmart¿ØÖÆÆ÷Èí¼þ
ÐÞ¸´°æ±¾
Cisco SD-WAN°æ±¾ | ÕâЩÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ת´ï¼¯ÖÐÐÎòµÄËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
ÔçÓÚ18.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
18.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
18.4 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
19.2 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
19.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
20.1 | 20.1.2 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
20.3 | 20.3.2 | 20.3.2 |
20.4 | 20.4.1 | 20.4.1 |
Cisco SD-WAN»º³åÇøÒç³öÎó²î£¨CVE-2021-1300£©
¸ÃÎó²îÊǶÔIPÁ÷Á¿µÄ²»×¼È·´¦Öóͷ£Ôì³ÉµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâIPÁ÷Á¿À´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕµ¼Ö»º³åÇøÒç³ö¡£¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔrootȨÏÞÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Cisco SD-WANµÄNETCONF×ÓϵͳÖл¹±£´æÁíÒ»¸ö»º³åÇøÒç³öÎó²î£¨CVE-2021-1301£©£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔÚÊÜÓ°ÏìµÄ×°±¸»òϵͳÉϵ¼Ö¾ܾøÐ§ÀÍ£¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.5¡£¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
ÈôÊÇÕýÔÚÔËÐÐÒ×ÊÜÓ°ÏìµÄCisco SD-WAN°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÔòÕâЩÎó²î»áÓ°ÏìÒÔÏÂCisco²úÆ·£º
IOS XE SD-WANÈí¼þ
SD-WAN vBond OrchestratorÈí¼þ
SD-WAN vEdgeÔÆÂ·ÓÉÆ÷
SD-WAN vEdge·ÓÉÆ÷
SD-WAN vManageÈí¼þ
SD-WAN vSmart¿ØÖÆÆ÷Èí¼þ
ÐÞ¸´°æ±¾
SD-WAN
Cisco SD-WAN°æ±¾ | Îó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
ÔçÓÚ18.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
18.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
18.4 | 18.4.5 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
19.2 | 19.2.2 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
19.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
20.1 | 20.1.1 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
20.3 | 20.3.1 | 20.3.2 |
20.4 | 20.4.1 | 20.4.1 |
IOS XE SD-WAN
Cisco IOS XE SD-WAN°æ±¾ | Îó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
16.9 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
16.10 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
16.11 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ |
16.12 | 16.12.4 | 16.12.4 |
IOS XE
Cisco IOS XEͨÓð汾 | Îó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
17.2 | 17.2.1 | 17.2.2 |
17.3 | 17.3.1 | 17.3.1 |
17.4 | 17.4.1 | 17.4.1 |
Cisco DNA Center Command Runner ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1264£©
¸ÃÎó²î±£´æÓÚCisco DNA CenterµÄCommand Runner¹¤¾ßÖУ¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.6¡£¡£¡£¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇCommand Runner¹¤¾ßÊäÈëÑé֤ȱ·¦µ¼Öµġ£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÏÂÁîÖ´ÐÐʱ´úʹÓöñÒâÊäÈë»òŲÓÃÏÂÁîÔËÐгÌÐòAPIÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕÄܹ»ÔÚCisco DNA CenterÖÎÀíµÄ×°±¸ÉÏÖ´ÐÐí§ÒâCLIÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Cisco DNA Center Software < 1.3.1.0
ÐÞ¸´°æ±¾
Cisco DNA Center Software >= 1.3.1.0
Cisco Smart Software Manager Satellite Web UIÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1138¡¢CVE-2021-1140ºÍCVE-2021-1142£©
Õâ3¸öÎó²î¶¼ÊÇCiscoÖÇÄÜÈí¼þÖÎÀíÆ÷SatelliteµÄWeb UIÖеÄÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ËüÃǶ¼ÊÇÊäÈëÑé֤ȱ·¦µ¼Öµģ¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâHTTPÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÉÏÔËÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬CiscoÖÇÄÜÈí¼þÖÎÀíÆ÷SatelliteµÄWeb UIÖл¹±£´æÆäËü2¸öÊäÈëÑé֤ȱ·¦µ¼ÖµÄÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1139ºÍCVE-2021-1141£©£¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¾ùΪ8.8¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâHTTPÇëÇóÀ´Ê¹ÓÃËüÃÇ£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕ¿ÉÒÔÒÔrootÓû§µÄÉí·ÝÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Cisco Smart Software Manager Satellite <= 5.1.0
ÐÞ¸´°æ±¾
Cisco Smart Software Manager On-Prem >= 6.3.0
×¢£ºÔÚ6.3.0°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬£¬Cisco Smart Software Manager Satellite±»ÖØÃüÃûΪCisco Smart Software Manager On-Prem¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
½¨Òé²Î¿¼Cisco¹Ù·½Ðû²¼µÄÇ徲ͨ¸æÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-cmdinjm-9QMSmgcn
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-pre-auth-bugs-in-sd-wan-cloud-license-manager/
0x04 ʱ¼äÏß
2021-01-20 CiscoÐû²¼Ç徲ͨ¸æ
2021-01-21 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ