Cisco IOS XEÈí¼þWeb UI¿çÕ¾µãÇëÇóαÔìÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-14

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1904 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚCisco IOS XEÈí¼þ°æ±¾ÇÒÆôÓÃÁËHTTP Server¹¦Ð§µÄCisco×°±¸¡£


Îó²î¸ÅÊö


Cisco IOS XEÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ΪÆäÍøÂç×°±¸¿ª·¢µÄ²Ù×÷ϵͳ¡£Cisco IOS XE SoftwareÖеÄWeb UI±£´æCSRFÎó²î £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶ÔÊÜÓ°ÏìµÄϵͳ¾ÙÐпçÕ¾µãÇëÇóαÔ죨CSRF£©¹¥»÷¡£


¸ÃÎó²îÊÇÓÉÓÚÊÜÓ°ÏìÉè±¹ØÁ¬ÄWeb UIµÄCSRF±£»¤È±·¦¡£¹¥»÷Õß¿ÉÒÔͨ¹ý˵·þ½Ó¿ÚµÄÓû§×ñÕÕ¶ñÒâÁ´½ÓÀ´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÓÃÊÜÓ°ÏìÓû§µÄȨÏÞ¼¶±ðÖ´ÐÐí§Òâ²Ù×÷¡£ÈôÊÇÓû§¾ßÓÐÖÎÀíȨÏÞ £¬Ôò¹¥»÷Õß¿ÉÒÔ¸ü¸ÄÉèÖà £¬Ö´ÐÐÏÂÁî»òÖØÐ¼ÓÔØÊÜÓ°ÏìµÄ×°±¸¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


½ûÓÃHTTP Server¹¦Ð§¿ÉÏû³ý´ËÎó²îµÄ¹¥»÷ǰÑÔ £¬²¢ÇÒ¿ÉÄÜÊÇÊʵ±µÄ»º½â²½·¥ £¬Ö±µ½¿ÉÒÔÉý¼¶ÊÜÓ°ÏìµÄ×°±¸¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190612-iosxe-csrf