Cisco IOS XE¼°Ð¡ÐÍÆóҵ·ÓÉÆ÷¶à¸öÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-29Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2017-3823£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½£º8.8
CVE±àºÅ£ºCVE-2019-1653£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2019-1652£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.2£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2019-1742£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1745£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1747£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1749£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1748£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1738£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1739£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1740£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1751£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1752£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1737£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1754£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1753£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1756£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1755£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1750£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1741£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1746£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1743£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1760£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1759£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.3£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1761£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º4.3£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1762£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º4.4£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1757£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.9£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1758£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º4.7£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì²úÆ·
Cisco IOS XE¼°Ð¡ÐÍÆóҵ·ÓÉÆ÷µÈ
Îó²î¸ÅÊö
˼¿ÆÏµÍ³ÖÜÈýÐû²¼Á˶à¸ö²¹¶¡£¬ÓëÆäIOS XE²Ù×÷ϵͳÖеÄÎó²îÏà¹Ø¡£²¢ÖÒÑÔ¿Í»§Á½¸öСÐÍÆóҵ·ÓÉÆ÷£¨RV320ºÍRV325£©ÈÝÒ×Êܵ½¹¥»÷£¬²¢ÇÒÁ½Õß¶¼Ã»ÓпÉÓõIJ¹¶¡¡£Á½¸ö·ÓÉÆ÷ȱÏÝCVE-2019-1652ºÍCVE-2019-1653¶¼ÊÇÔÚ1Ô·ÝÊ״δò²¹¶¡£¬µ«Ë¼¿ÆÖÜÈýÌåÏÖÁ½¸ö²¹¶¡¶¼¡°²»ÍêÕû¡±£¬Á½¸ö·ÓÉÆ÷ÈÔÈ»ÈÝÒ×Êܵ½¹¥»÷¡£¸ÅÊöÈçÏ£º
CVE-2017-3823
Cisco WebExä¯ÀÀÆ÷À©Õ¹ÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃÊÜÓ°ÏìϵͳÉÏÊÜÓ°ÏìµÄä¯ÀÀÆ÷µÄȨÏÞÖ´ÐÐí§Òâ´úÂë¡£ ÔÚMicrosoft WindowsÉÏÔËÐÐʱ£¬´ËÎó²î»áÓ°ÏìCisco WebEx Meetings ServerºÍCisco WebEx Centers£¨¾Û»áÖÐÐÄ£¬Ô˶¯ÖÐÐÄ£¬ÅàѵÖÐÐĺÍÖ§³ÖÖÐÐÄ£©µÄä¯ÀÀÆ÷À©Õ¹¡£
¸ÃÎó²îÊÇÓɲå¼þÖеÄÓ¦ÓóÌÐò±à³Ì½Ó¿Ú£¨API£©ÏìÓ¦ÆÊÎöÆ÷ÖеÄÉè¼ÆÈ±ÏÝÒýÆðµÄ¡£ ¿ÉÒÔ˵·þÊÜÓ°ÏìµÄÓû§»á¼ûÊܹ¥»÷Õß¿ØÖƵÄÍøÒ³»ò¸ú×Ù¹¥»÷ÕßÌṩµÄÊÜÓ°Ïìä¯ÀÀÆ÷Á´½ÓµÄ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î¡£ ÈôÊÇÀֳɣ¬¹¥»÷Õß¿ÉÒÔʹÓÃÊÜÓ°ÏìµÄä¯ÀÀÆ÷µÄȨÏÞÖ´ÐÐí§Òâ´úÂë¡£
Cisco Small Business RV320ºÍRV325˫ǧÕ×WAN VPN·ÓÉÆ÷µÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¼ìË÷Ãô¸ÐÐÅÏ¢¡£
¸ÃÎó²îÊÇÓÉÓÚ¶ÔURLµÄ»á¼û¿ØÖƲ»µ±Ôì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýHTTP»òHTTPSÅþÁ¬µ½ÊÜÓ°ÏìµÄ×°±¸²¢ÇëÇóÌØ¶¨µÄURLÀ´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßÏÂÔØÂ·ÓÉÆ÷ÉèÖûòÏêϸµÄÕï¶ÏÐÅÏ¢¡£
¸üУ¬2019Äê3ÔÂ27ÈÕ£º·¢Ã÷´ËÎó²îµÄ³õʼÐÞ¸´³ÌÐò²»ÍêÕû¡£ ˼¿ÆÏÖÔÚÕýÔÚ¾ÙÐÐÖÜÈ«ÐÞ¸´¡£ Ò»µ©Àο¿´úÂë¿ÉÓ㬸ÃÎĵµ½«¸üС£
Cisco Small Business RV320ºÍRV325˫ǧÕ×WAN VPN·ÓÉÆ÷µÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î¿ÉÄÜÔÊÐí¾ßÓÐÊÜÓ°Ïì×°±¸ÖÎÀíȨÏ޵ľÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§ÒâÏÂÁî¡£
¸ÃÎó²îÊÇÓÉÓÚÓû§ÌṩµÄÊäÈëÑéÖ¤²»×¼È·¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°Ïì×°±¸µÄ»ùÓÚWebµÄÖÎÀí½çÃæ·¢ËͶñÒâHTTP POSTÇëÇóÀ´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßÒÔrootÉí·ÝÔڵײãLinux shellÉÏÖ´ÐÐí§ÒâÏÂÁî¡£
¸üУ¬2019Äê3ÔÂ27ÈÕ£º·¢Ã÷´ËÎó²îµÄ³õʼÐÞ¸´³ÌÐò²»ÍêÕû¡£Ë¼¿ÆÏÖÔÚÕýÔÚ¾ÙÐÐÖÜÈ«ÐÞ¸´¡£Ò»µ©Àο¿´úÂë¿ÉÓ㬸ÃÎĵµ½«¸üС£
Cisco IOS XEÈí¼þµÄWeb UIÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»á¼ûÃô¸ÐÉèÖÃÐÅÏ¢¡£
¸ÃÎó²îÊÇÓÉÓÚ¶ÔWeb UIÖеÄÎļþµÄ²»×¼È·»á¼û¿ØÖÆÔì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓÿÉÒÔʹ¹¥»÷Õß»ñµÃ¶ÔÃô¸ÐÉèÖÃÐÅÏ¢µÄ»á¼ûȨÏÞ¡£
Cisco IOS XEÈí¼þÖеÄÎó²î¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÍâµØ¹¥»÷Õß×¢ÈëÒÔÌáÉýµÄȨÏÞÖ´ÐеÄí§ÒâÏÂÁî¡£
¸ÃÎó²îÊÇÓÉÓÚÓû§ÌṩµÄÏÂÁîµÄÊäÈëÑé֤ȱ·¦¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏò×°±¸¾ÙÐÐÉí·ÝÑéÖ¤²¢ÏòÊÜÓ°ÏìµÄÏÂÁîÌύȫÐÄÉè¼ÆµÄÊäÈëÀ´Ê¹ÓôËÎó²î¡£ ʹÓÃÎó²î¿ÉÄÜÔÊÐí¹¥»÷Õß»ñµÃÊÜÓ°Ïì×°±¸µÄrootȨÏÞ¡£
ʵÑéCisco IOSÈí¼þºÍCisco IOS XEÈí¼þµÄ¶ÌÐÂÎÅ·þÎñ£¨SMS£©´¦Öóͷ£¹¦Ð§µÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏ´¥·¢¾Ü¾ø·þÎñ£¨DoS£©Ìõ¼þ¡£
¸ÃÎó²îÊÇÓÉÓÚʹÓÃÌØÊâ×Ö·û¼¯±àÂëµÄSMSÐÒéÊý¾Ýµ¥Î»£¨PDU£©µÄ²»×¼È·´¦Öóͷ£Ôì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËͶñÒâSMSÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÊÜÓ°ÏìÉè±¹ØÁ¬ÄÎÞÏßWAN£¨WWAN£©·äÎѽӿÚÄ£¿éÍ߽⣬´Ó¶øµ¼ÖÂÐèÒªÊÖ¶¯¸ÉÔ¤ÒÔ»Ö¸´Õý³£²Ù×÷Ìõ¼þµÄDoSÌõ¼þ¡£
ÓÃÓÚCisco¾ÛºÏ·þÎñ·ÓÉÆ÷£¨ASR£©900·Óɽ»Á÷»ú´¦Öóͷ£Æ÷3£¨RSP3£©µÄCisco IOS XEÈí¼þµÄÈë¿ÚÁ÷Á¿ÑéÖ¤ÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÏàÁÚ¹¥»÷Õß´¥·¢ÊÜÓ°Ïì×°±¸µÄÖØÐ¼ÓÔØ£¬´Ó¶øµ¼Ö¾ܾø·þÎñ £¨DoS£©Ìõ¼þ¡£
¸ÃÎó²îµÄ±£´æÊÇÓÉÓÚ¸ÃÈí¼þ²»¿É³ä·ÖÑéÖ¤RSP3ƽ̨ÉÏʹÓõÄASICÉϵÄÈë¿ÚÁ÷Á¿¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍÃûÌùýʧµÄOSPF°æ±¾2£¨OSPFv2£©ÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßÖØÐ¼ÓÔØiosdÀú³Ì£¬´¥·¢ÊÜÓ°Ïì×°±¸µÄÖØÐ¼ÓÔØ²¢µ¼ÖÂDoSÌõ¼þ¡£
Cisco IOSÈí¼þºÍCisco IOS XEÈí¼þµÄ˼¿ÆÍøÂç¼´²å¼´Óã¨PnP£©ÊðÀíÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßδ¾ÊÚȨ»á¼ûÃô¸ÐÊý¾Ý¡£
¸ÃÎó²îµÄ±£´æÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þȱ·¦ÒÔÑéÖ¤Ö¤Êé¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸Ìá¹©ÖÆ×÷µÄÖ¤ÊéÀ´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬ÒÔ½âÃܺÍÐÞ¸ÄÓû§ÓëÊÜÓ°ÏìÈí¼þµÄÅþÁ¬µÄÉñÃØÐÅÏ¢¡£
Cisco IOSÈí¼þºÍCisco IOS XEÈí¼þµÄ»ùÓÚÍøÂçµÄÓ¦ÓóÌÐòʶ±ð£¨NBAR£©¹¦Ð§ÖеĶà¸öÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼ÖÂÊÜÓ°ÏìµÄ×°±¸ÖØÐ¼ÓÔØ¡£ ÕâЩÎó²îÊÇÓÉDNSÆÊÎöÆ÷ÉÏµÄÆÊÎöÎÊÌâÒýÆðµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÔËÐÐÊÜÓ°Ïì°æ±¾ÇÒÆôÓÃÁËNBARµÄ·ÓÉÆ÷·¢ËÍÈ«ÐÄÉè¼ÆµÄDNSÊý¾Ý°üÀ´Ê¹ÓÃÕâЩÎó²î¡£ ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßÖØÐ¼ÓÔØÊÜÓ°ÏìµÄ×°±¸£¬´Ó¶øµ¼Ö¾ܾø·þÎñ£¨DoS£©Ìõ¼þ¡£
Cisco IOSÈí¼þµÄÍøÂçµØµãת»»64£¨NAT64£©¹¦Ð§ÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼Ö½ӿÚÐÐÁÐШÈë»ò×°±¸ÖØÐ¼ÓÔØ¡£
¸ÃÎó²îÊÇÓÉÓÚ¶Ôͨ¹ý×°±¸·¢Ë͵ÄijЩIPv4Êý¾Ý°üÁ÷µÄ¹ýʧ´¦Öóͷ£Ôì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ý×°±¸·¢ËÍÌØ¶¨µÄIPv4Êý¾Ý°üÁ÷À´Ê¹ÓôËÎó²î¡£ ¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷Õßµ¼Ö½ӿÚÐÐÁÐШÈë»ò×°±¸ÖØÐ¼ÓÔØ£¬´Ó¶øµ¼Ö¾ܾø·þÎñ£¨DoS£©Ìõ¼þ¡£
Cisco IOSÈí¼þºÍCisco IOS XEÈí¼þµÄISDN¹¦Ð§ÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼ÖÂ×°±¸ÖØÐ¼ÓÔØ¡£
¸ÃÎó²îÊÇÓÉÓÚQ.931ÐÅÏ¢ÔªËØÖÐÌØ¶¨ÖµµÄ¹ýʧ´¦Öóͷ£Ôì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÌØ¶¨µÄQ.931ÐÅÏ¢ÔªËØÅ²ÓÃÊÜÓ°ÏìµÄ×°±¸À´Ê¹ÓôËÎó²î¡£ ¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷ÕßÖØÐ¼ÓÔØ×°±¸£¬´Ó¶øµ¼ÖÂÊÜÓ°ÏìÉè±¹ØÁ¬Ä¾Ü¾ø·þÎñ£¨DoS£©Ìõ¼þ¡£
Cisco IOSÈí¼þºÍCisco IOS XEÈí¼þ´¦Öóͷ£IP·þÎñˮƽÐÒ飨SLA£©Êý¾Ý°üʱµÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÒýÆð½Ó¿ÚШÈëºÍ×îÖվܾø·þÎñ£¨DoS£©ÇéÐΡ£
¸ÃÎó²îÊÇÓÉÓÚIP SLAÏìÓ¦³ÌÐòÓ¦ÓóÌÐò´úÂëÖеÄÌ×½Ó×Ö×ÊÔ´´¦Öóͷ£²»µ±Ôì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍÈ«ÐÄÉè¼ÆµÄIP SLAÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£ ¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷Õßʹ½Ó¿Ú±äΪШÈ룬´Ó¶øµ¼ÖÂÊÜÓ°ÏìÉè±¹ØÁ¬Ä×îÖվܾø·þÎñ£¨DoS£©Ìõ¼þ¡£
Cisco IOS XEÈí¼þµÄÊÚȨ×ÓϵͳÖеÄÎó²î¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µ«ÎÞÌØÈ¨£¨1¼¶£©µÄÔ¶³Ì¹¥»÷Õßͨ¹ýʹÓÃWeb UIÔËÐÐÌØÈ¨Cisco IOSÏÂÁî¡£
¸ÃÎó²îÊÇÓÉÓÚ¶ÔWeb UIÓû§µÄÓû§È¨Ï޵IJ»×¼È·ÑéÖ¤Ôì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòWeb UIÖеÄÌØ¶¨¶ËµãÌá½»¶ñÒâ¸ºÔØÀ´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓÿÉÒÔÔÊÐí½ÏµÍȨÏ޵Ĺ¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐоßÓиü¸ßȨÏÞµÄí§ÒâÏÂÁî¡£
Cisco IOS XEÈí¼þµÄWeb UIÖеÄÎó²î¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µ«ÎÞÌØÈ¨£¨1¼¶£©µÄÔ¶³Ì¹¥»÷ÕßʹÓÃWeb UIÔËÐÐÌØÈ¨Cisco IOSÏÂÁî¡£
¸ÃÎó²îÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ºÍÕûÀíWeb·þÎñÖÎÀíÊðÀí£¨WSMA£©¹¦Ð§ÖеÄÊäÈë¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°Ïì×°±¸µÄWeb UIÌá½»¶ñÒâ¸ºÔØÀ´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓÿÉÒÔÔÊÐí½ÏµÍȨÏ޵Ĺ¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐоßÓиü¸ßȨÏÞµÄí§ÒâÏÂÁî¡£
Cisco IOS XEÈí¼þÖеÄÎó²î¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃrootȨÏÞÔÚÊÜÓ°Ïì×°±¸µÄµ×²ãLinux shellÉÏÖ´ÐÐÏÂÁî¡£
·ºÆð´ËÎó²îµÄÔµ¹ÊÔÓÉÊÇÊÜÓ°ÏìµÄÈí¼þ²»×¼È·µØÕûÀíÁËÓû§ÌṩµÄÊäÈë¡£ ¾ßÓжÔÊÜÓ°Ïì×°±¸µÄÓÐÓÃÖÎÀíÔ±»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ýÔÚWeb UIÖÐÌṩ¾ßÓжñÒâ¸ºÔØµÄÓû§Ãû²¢ËæºóÏòWeb UIÖеÄÌØ¶¨¶Ëµã·¢³öÇëÇóÀ´Ê¹ÓôËÎó²î¡£ ÀֳɵĹ¥»÷¿ÉÄÜÔÊÐí¹¥»÷ÕßÒÔrootÓû§Éí·ÝÔËÐÐí§ÒâÏÂÁ´Ó¶øÍêÈ«ÆÆËðϵͳ¡£
Cisco IOS XEÈí¼þµÄWeb·þÎñÖÎÀíÊðÀí£¨WSMA£©¹¦Ð§ÖеÄÎó²î¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔÌØÈ¨¼¶±ð15Óû§Éí·ÝÖ´ÐÐí§ÒâCisco IOSÏÂÁî¡£
·ºÆð´ËÎó²îµÄÔµ¹ÊÔÓÉÊÇÊÜÓ°ÏìµÄÈí¼þ²»×¼È·µØÕûÀíÁËÓû§ÌṩµÄÊäÈë¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄÓ¦ÓóÌÐòÌύȫÐÄÉè¼ÆµÄHTTPÇëÇóÀ´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£
Catalyst 4500ϵÁн»Á÷»úÉÏCisco IOS XEÈí¼þµÄdzÒ×ÐéÄâ½»Á÷ϵͳ£¨VSS£©ÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÏàÁÚ¹¥»÷Õßµ¼Ö½»Á÷»úÖØÐ¼ÓÔØ¡£
¸ÃÎó²îÊÇÓÉÓÚ´¦Öóͷ£ÓëEasy Virtual Switching SystemÒ»ÆðʹÓõÄCisco·¢Ã÷ÐÒ飨CDP£©Êý¾Ý°üʱµÄ¹ýʧ´¦Öóͷ£²»ÍêÕû¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÌØÖÆµÄCDPÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£ ¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷ÕßÖØÐ¼ÓÔØ×°±¸£¬´Ó¶øµ¼Ö¾ܾø·þÎñ£¨DoS£©Ìõ¼þ¡£
Cisco IOS XEÈí¼þµÄ˼¿Æ¼ÓÃÜÁ÷Á¿ÆÊÎö£¨ETA£©¹¦Ð§ÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼Ö¾ܾø·þÎñ£¨DoS£©ÇéÐΡ£
¸ÃÎó²îÊÇÓÉÓÚ´¦Öóͷ£ÃûÌùýʧµÄ´«ÈëÊý¾Ý°üʱ±£´æµÄÂß¼¹ýʧµ¼ÖÂÔÚÊͷźó»á¼ûÄÚ²¿Êý¾Ý½á¹¹¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍÈ«ÐÄÉè¼ÆµÄÃûÌùýʧµÄIPÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓù¥»÷¿ÉÄÜ»áʹ¹¥»÷ÕßÖØÐ¼ÓÔØÊÜÓ°ÏìµÄ×°±¸£¬´Ó¶øµ¼ÖÂDoS״̬¡£
Cisco IOSÈí¼þºÍCisco IOS XEÈí¼þÖеÄȺ¼¯ÖÎÀíÐÒ飨CMP£©´¦Öóͷ£´úÂëÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÏàÁÚ¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏ´¥·¢¾Ü¾ø·þÎñ£¨DoS£©Ìõ¼þ¡£
¸ÃÎó²îÊÇÓÉÓÚ´¦Öóͷ£CMPÖÎÀíÊý¾Ý°üʱÊäÈëÑé֤ȱ·¦Ôì³ÉµÄ¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËͶñÒâCMPÖÎÀíÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓÿÉÄܻᵼÖ½»Á÷»úÍ߽⣬´Ó¶øµ¼ÖÂDoSÇéÐΡ£ ½»Á÷»ú½«×Ô¶¯ÖØÐ¼ÓÔØ¡£
Cisco IOS XEÈí¼þµÄWeb UI¿ò¼ÜÖеÄÎó²î¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶ÔÊÜÓ°Ïì×°±¸µÄÎļþϵͳ¾ÙÐÐδ¾ÊÚȨµÄ¸ü¸Ä¡£
¸ÃÎó²îÊÇÓÉÓÚÊäÈëÑéÖ¤²»µ±Ôì³ÉµÄ¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÖÆ×÷¶ñÒâÎļþ²¢½«ÆäÉÏ´«µ½×°±¸À´Ê¹ÓôËÎó²î¡£¹¥»÷¿ÉÒÔÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏ»ñµÃÌáÉýµÄȨÏÞ¡£
Cisco IOS XEÈí¼þµÄÐÔÄÜ·Óɰ汾3£¨PfRv3£©ÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼ÖÂÊÜÓ°ÏìµÄ×°±¸ÖØÐ¼ÓÔØ¡£
¸ÃÎó²îÊÇÓÉÓÚ´¦Öóͷ£ÃûÌùýʧµÄÖÇÄÜ̽²âÊý¾Ý°üËùÖ¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏ·¢ËÍÌØÖÆµÄÖÇÄÜ̽²âÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßÖØÐ¼ÓÔØ×°±¸£¬´Ó¶øµ¼Ö¶ÔÊÜÓ°ÏìϵͳµÄ¾Ü¾ø·þÎñ£¨DoS£©¹¥»÷¡£
Cisco IOS XEÈí¼þµÄǧÕ×ÒÔÌ«ÍøÖÎÀí½Ó¿ÚµÄ»á¼û¿ØÖÆÁÐ±í£¨ACL£©¹¦Ð§ÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»á¼ûǧÕ×ÒÔÌ«ÍøÖÎÀí½Ó¿ÚÉÏÉèÖõÄIPµØµã¡£
¸ÃÎó²îÊÇÓÉCisco IOS XEÈí¼þ16.1.1°æ±¾ÖÐÒýÈëµÄÂß¼¹ýʧÒýÆðµÄ£¬¸Ã¹ýʧ»á×èÖ¹ACLÔÚÓ¦ÓÃÓÚÖÎÀí½Ó¿ÚÊ±ÊÆÇé¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÖÎÀí½çÃæÊµÑé»á¼û×°±¸À´Ê¹ÓôËÎÊÌâ¡£
Cisco IOSºÍIOS XEÈí¼þµÄÈȱ¸Ó÷ÓÉÆ÷ÐÒ飨HSRP£©×ÓϵͳÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÏàÁÚ¹¥»÷Õß´ÓÊÜÓ°ÏìµÄ×°±¸ÎüÊÕDZÔÚµÄÃô¸ÐÐÅÏ¢¡£¸ÃÎó²îÊÇÓÉÓÚÄÚ´æ³õʼ»¯È±·¦Ôì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ý´ÓÏàÁÚHSRP³ÉÔ±ÎüÊÕHSRPv2Á÷Á¿À´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷Õß´ÓÏàÁÚ×°±¸ÎüÊÕDZÔÚµÄÃô¸ÐÐÅÏ¢¡£
Cisco IOSºÍIOS XEÈí¼þµÄÇå¾²´æ´¢¹¦Ð§ÖеÄÎó²î¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÍâµØ¹¥»÷Õß»á¼ûÊÜÓ°ÏìÉè±¹ØÁ¬ÄÃô¸ÐϵͳÐÅÏ¢¡£
¸ÃÎó²îÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þ´¦Öóͷ£ÉèÖøüÐÂʱÔÚ¼ÓÃÜʱִÐеIJ»×¼È·µÄÄÚ´æ²Ù×÷¡£¹¥»÷Õß¿ÉÒÔͨ¹ý¼ìË÷ÊÜÓ°Ïì×°±¸µÄÌØ¶¨ÄÚ´æÎ»ÖõÄÄÚÈÝÀ´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂ×÷Ϊװ±¸ÉèÖõÄÒ»²¿·ÖµÄÃÜÔ¿ÖÊÁϵĹûÕæ£¬Æä¿ÉÓÃÓÚ»Ö¸´Òªº¦ÏµÍ³ÐÅÏ¢¡£
Cisco IOSºÍIOS XEÈí¼þµÄ˼¿ÆÖÇÄܺô½ÐÖ÷Ò³¹¦Ð§ÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃÎÞЧ֤Êé¶ÔÃô¸ÐÊý¾Ý¾ÙÐÐδ¾ÊÚȨµÄ¶ÁÈ¡»á¼û¡£
¸ÃÎó²îÊÇÓÉÊÜÓ°ÏìµÄÈí¼þÑéÖ¤Ö¤Êéȱ·¦Ôì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸Ìá¹©ÖÆ×÷µÄÖ¤ÊéÀ´Ê¹ÓôËÎó²î¡£ ÀֳɵĹ¥»÷¿ÉÄÜÔÊÐí¹¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬ÒÔ½âÃÜÓû§ÓëÊÜÓ°ÏìÈí¼þµÄÅþÁ¬ÉϵÄÉñÃØÐÅÏ¢¡£
Catalyst 6500ϵÁн»Á÷»úÉÏCisco IOSÈí¼þµÄ802.1x¹¦Ð§ÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÏàÁÚ¹¥»÷ÕßÔÚÉí·ÝÑé֤֮ǰ»á¼ûÍøÂç¡£
¸ÃÎó²îÊÇÓÉÓÚÔÚÀú³Ì·¾¶Öд¦Öóͷ£802.1xÊý¾Ý°üµÄ·½·¨¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʵÑéÔÚ802.1xÉèÖõĶ˿ÚÉÏÅþÁ¬µ½ÍøÂçÀ´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷Õß¼äЪÐԵػñµÃ¶ÔÍøÂçµÄ»á¼û¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î¡£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170124-webex
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-inject
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-xeid
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-xecmd
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-sms-dos
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-rsp3-ospf
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-pnp-cert
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-nbar
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-nat64
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-isdn
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-ipsla-dos
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-iosxe-privesc
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-iosxe-pe
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-iosxe-cmdinject
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-iosxe-cmdinj
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-evss
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-eta-dos
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-cmp-dos
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-afu
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-pfrv3
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-mgmtacl
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-ios-infoleak
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-info
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-call-home-cert
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-c6500


¾©¹«Íø°²±¸11010802024551ºÅ