˼¿ÆÐÞ¸´ÑÏÖØµÄIOxÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-27

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12648£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


˼¿Æ1000ϵÁÐConnected Grid Routers (CGR 1000)ºÍ˼¿Æ800ϵÁÐIndustrial Integrated Services Routers£¬×°ÖÃÁ˿ͻ§»ú²Ù×÷ϵͳµÄIOS SoftwareÒ×Êܹ¥»÷°æ±¾


Îó²î¸ÅÊö


˼¿ÆÐû²¼Çå¾²¸üУ¬½â¾öÁË˼¿ÆIOS Software IOxÓ¦ÓóÌÐòÇéÐÎÖеÄÒ»¸öÑÏÖØÎó²î¡£¸ÃÎó²î¿Éµ¼ÖÂÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔ¸ùÓû§Éí·Ý»á¼û¿Í»§»ú²Ù×÷ϵͳ (Guest OS)¡£


µ±µÍȨÏÞÓû§ÇëÇó»á¼û±¾Ó¦±»ÏÞÖÆÎª¹ÜÀíÔ±ÕË»§²Å»ª»á¼ûµÄ¿Í»§»ú²Ù×÷ϵͳʱ£¬»áÒý·¢¹ýʧµÄ»ùÓÚ½ÇÉ«µÄ»á¼û¿ØÖÆ£¨RBAC£©ÆÀ¹À¡£¹¥»÷ÕßÄܹ»Ê¹ÓõÍȨÏÞÓû§Æ¾Ö¤ÑéÖ¤¿Í»§»ú²Ù×÷ϵͳ£¬´Ó¶øÊ¹ÓøÃÎó²î¡£


¿Í»§»ú²Ù×÷ϵͳÊǰüÀ¨Hypervisor¡¢IOSºÍGuest OSÓ³ÏñµÄÀ¦°óIOSÓ³ÏñµÄÒ»²¿·Ö¡£Í¨¹ý˼¿ÆIOS SoftwareÓ³Ïñ°üÖ´ÐгõʼװÖûòÈí¼þÉý¼¶µÄ¿Í»§½«ÔÚÈí¼þÓ³Ïñ°ü×°ÖÃÀú³ÌÖÐ×Ô¶¯×°Öÿͻ§»ú²Ù×÷ϵͳ¡£


¹ÜÀíÔ±¿ÉÔÚ×°±¸CLIÖÐʹÓÃÏÂÁîshow iox host list detailÉó²é×°±¸ÉÏÊÇ·ñÆôÓÃÁ˿ͻ§»ú²Ù×÷ϵͳ¡£Ë¼¿ÆÔÚÇ徲ͨ¸æÖÐÌṩÁËÈçÏÂʾÀý£¬ËµÃ÷ÎúÆôÓÃÁ˿ͻ§»ú²Ù×÷ϵͳµÄÏÂÁîÊä³öЧ¹û£º


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!



±ðµÄ£¬Ë¼¿ÆÐû²¼Á˰ëÄê¶ÈCisco IOSºÍIOS XEÈí¼þÇ徲ͨ¸æ£¨²¹¶¡ÈÕ£©£ºhttps://tools.cisco.com/security/center/viewErp.x?alertId=ERP-72547£¬ÆäÖаüÀ¨ËµÃ÷Îú13¸öÇ徲ȱÏݵÄ12¸ö˼¿ÆÇ徲ͨ¸æ£¬ËùÓеÄÕâ13¸öÎó²î¾ùδ¸ßΣÎó²î£¬CVSSÆÀ·ÖΪ7.5µ½9.9¡£±¾ÎÄÌáµ½µÄÎó²îÒ²ÊÇÆäÖеÄ×é³É²¿·Ö¡£Ë¼¿ÆÒÑÐû²¼½â¾öËùÓÐÕâЩÎó²îµÄÇå¾²¸üУ¬ÒÔ×èÖ¹¹¥»÷ÕßʹÓÃδÐÞ¸´×°±¸¡°»ñȡԽȨ»á¼ûȨÏÞ¡¢¾ÙÐÐÏÂÁî×¢Èë¹¥»÷»òÒý·¢¾Ü¾ø·þÎñÌõ¼þ¡±¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!



Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth ¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth