?Cisco | IOS ºÍ IOS XE¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-09-250x00 Îó²î¸ÅÊö
CiscoÔÚ2020Äê09ÔÂ24ÈÕÖÜËÄÐû²¼ÁË42¸öÇå¾²¸üÐÂÀ´ÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄÇå¾²Îó²î¡£ÕâЩÎó²î¿ÉÄܻᵼÖ¾ܾø·þÎñ¡¢ÎļþÁýÕÖ¡¢ÊäÈëÑéÖ¤¹¥»÷ºÍí§Òâ´úÂëÖ´Ðеȡ£ÆäÖÐÓÐ29¸öÎó²îµÄÆ·¼¶Îª¸ßΣ£¬ÁíÍâ13¸öÊÇÖÐΣ¡£
0x01 Îó²îÏêÇé

Cisco´Ë´ÎÐû²¼µÄÇå¾²Îó²îÈçÏ£º
Îó²î±àºÅ | Îó²îÃû³Æ | ÑÏÖØË®Æ½ | Ðû²¼ÈÕÆÚ |
CVE-2020-3421 | »ùÓÚCisco IOS XEÈí¼þÇøÓòµÄ·À»ðǽ¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3417 | Cisco IOS XEÈí¼þí§Òâ´úÂëÖ´ÐÐÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3429 | Catalyst 9000ϵÁÐWPA¾Ü¾ø·þÎñÎó²îµÄCisco IOS XEÎÞÏß¿ØÖÆÆ÷Èí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3400 | Cisco IOS XEÈí¼þWeb UIÊÚÈ¨ÈÆ¹ýÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3408 | Cisco IOSºÍIOS XEÈí¼þ²ð·ÖDNS¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3524 | Cisco IOS XE ROM¼àÊÓÆ÷Èí¼þÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3409 | Cisco IOSºÍIOS XEÈí¼þPROFINET¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3359 | Catalyst 9800ϵÁÐÎÞÏß¿ØÖÆÆ÷µÄCisco IOS XEÈí¼þ¶à²¥DNS¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3465 | Cisco IOS XEÈí¼þÒÔÌ«Íø¿ò¼Ü¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3422 | Cisco IOS XEÈí¼þIP·þÎñ¼¶±ðÐÒé¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3492 | Catalyst 9800ϵÁеÄCisco IOS XEÈí¼þºÍCisco WLC Flexible NetFlow°æ±¾9µÄCisco AireOSÈí¼þ¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3510 | Catalyst 9200ϵÁн»Á÷»úµÄCisco IOS XEÈí¼þÉ¡ÅþÁ¬Æ÷¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3416 | ÓÃÓÚCisco ASR 900ϵÁзÓɽ»Á÷»ú´¦Öóͷ£Æ÷µÄCisco IOS XEÈí¼þ3í§Òâ´úÂëÖ´ÐÐÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3511 | Cisco IOSºÍIOS XEÈí¼þISDN Q.931¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3390 | Catalyst 9000ϵÁÐSNMPÏÝÚå¾Ü¾ø·þÎñÎó²îµÄCisco IOS XEÎÞÏß¿ØÖÆÆ÷Èí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3509 | ÓÃÓÚCisco cBR-8ÈںϿíÁì·ÓÉÆ÷µÄCisco IOS XEÈí¼þDHCP¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3141 | Cisco IOS XEÈí¼þÌØÈ¨Éý¼¶Îó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3512 | Cisco IOSºÍIOS XEÈí¼þPROFINETÁ´Â·²ã·¢Ã÷ÐÒé¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3426 | ÓÃÓÚCisco¹¤ÒµÂ·ÓÉÆ÷µÄCisco IOSÈí¼þVirtual-LPWAδ¾ÊÚȨµÄ»á¼ûÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3508 | ÓÃÓÚCisco ASR 1000ϵÁÐ20 GbpsǶÈëʽ·þÎñ´¦Öóͷ£Æ÷IP ARP¾Ü¾ø·þÎñÎó²îµÄCisco IOS XEÈí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3428 | Catalyst 9000ϵÁÐWLANÍâµØÆÊÎö¾Ü¾ø·þÎñÎó²îµÄCisco IOS XEÎÞÏß¿ØÖÆÆ÷Èí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3407 | Cisco IOS XEÈí¼þRESTCONFºÍNETCONF-YANG»á¼û¿ØÖÆÁбí¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3486 | Catalyst 9000ϵÁÐCAPWAP¾Ü¾ø·þÎñÎó²îµÄCisco IOS XEÎÞÏß¿ØÖÆÆ÷Èí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3399 | Catalyst 9000ϵÁÐCAPWAP¾Ü¾ø·þÎñÎó²îµÄCisco IOS XEÎÞÏß¿ØÖÆÆ÷Èí¼þ | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3552 | Cisco Aironet½ÓÈëµãÒÔÌ«ÍøÓÐÏ߿ͻ§¶Ë¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3560 | Cisco Aironet½ÓÈëµãUDP·ººé¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3527 | Cisco Catalyst 9200ϵÁн»Á÷»ú³¬´óÖ¡¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3414 | ÓÃÓÚCisco 4461¼¯³É·þÎñ·ÓÉÆ÷µÄCisco IOS XEÈí¼þ¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3526 | Cisco IOS XEÈí¼þͨÓÿª·ÅÕ½ÂÔ·þÎñÒýÇæ¾Ü¾ø·þÎñÎó²î | ¸ß | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3503 | Cisco IOS XEÈí¼þÀ´±öShellδ¾ÊÚȨµÄÎļþϵͳ»á¼ûÎó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3396 | Cisco IOS XEÈí¼þIOx·Ã¿ÍÍâ¿ÇUSB SSDÃüÃû¿Õ¼ä±£»¤ÌØÈ¨Éý¼¶Îó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3393 | Cisco IOS XEÈí¼þIOxÓ¦ÓóÌÐòÍйÜÌØÈ¨Éý¼¶Îó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3404 | Cisco IOS XEÈí¼þÔÞ³ÉÁîÅÆÈÆ¹ýÎó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3403 | Cisco IOS XEÈí¼þÏÂÁî×¢ÈëÎó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3474 | Cisco IOS XEÈí¼þWebÖÎÀí¿ò¼ÜÎó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3423 | Cisco IOS XEÈí¼þí§Òâ´úÂëÖ´ÐÐÎó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3479 | Cisco IOSºÍIOS XEÈí¼þMP-BGP EVPN¾Ü¾ø·þÎñÎó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3477 | Cisco IOSºÍIOS XEÈí¼þÐÅϢй¶Îó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3476 | Cisco IOS XEÈí¼þí§ÒâÎļþÁýÕÖÎó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3418 | Catalyst 9000ϵÁеÄCisco IOS XEÎÞÏß¿ØÖÆÆ÷Èí¼þ²»µ±µÄ»á¼û¿ØÖÆÎó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3559 | Cisco Aironet½ÓÈëµãÉí·ÝÑéÖ¤ºéË®¾Ü¾ø·þÎñÎó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
CVE-2020-3516 | Cisco IOS XEÈí¼þWeb UIÊäÈëÑéÖ¤²»µ±Îó²î | ÖÐ | 2020Äê9ÔÂ24ÈÕ |
²¿·ÖÎó²îÏêÇéÈçÏ£º
Cisco IOS XE»ùÓÚÈí¼þÇøÓòµÄ·À»ðǽ¾Ü¾ø·þÎñÎó²î£¨CVE-2020-3421£©
¸ÃÎó²îÊÇÓÉÓÚͨ¹ý×°±¸Î´ÍêÕû´¦Öóͷ£µÚ4²ãÊý¾Ý°üËùÖ£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×°±¸·¢ËÍÒ»¶¨Ë³ÐòµÄÁ÷Á¿Ä£Ê½À´Ê¹ÓôËÎó²î¡£
ÀÖ³ÉʹÓøÃÎó²î¿ÉÄÜʹ¹¥»÷ÕßÖØÐ¼ÓÔØ×°±¸£¬´Ó¶øµ¼Ö¾ܾø·þÎñ¡£¸ÃÎó²îCVSSÆÀ·Ö8.6·Ö£¬Îó²îÓ°ÏìÆ·¼¶¸ß¡£ÏÖÔÚ˼¿ÆÒѾÐû²¼Ïàʶ¾ö´ËÎó²îµÄÈí¼þ¸üС£
Îó²îϸ½Ú£º
Cisco IOS XE»ùÓÚÈí¼þÇøÓòµÄ·À»ðǽ¾Ü¾ø·þÎñÎó²îÈôÊÇÔÚ¼ì²é²ÎÊýÓ³ÉäÏÂÉèÖÃÁËlog dropped-packets¹¦Ð§£¬Ôò×°±¸»áÊܵ½Ó°Ïì¡£¿ÉÒÔͨ¹ýµÇ¼װ±¸²¢Ê¹ÓÃshow run | section parameter-map²ÎÊýÓ³ÉäÏÂÁîÀ´ÑéÖ¤ÊÇ·ñÉèÖÃÁËlog dropped-packets¹¦Ð§¡£ÈôÊÇÊä³ö°üÀ¨ÈκδøÓÐlog dropped-packetsµÄÐУ¬ÔòÌåÏÖ×°±¸Ò×Êܹ¥»÷¡£
ÒÔÏÂʾÀýÏÔʾÁËÒ×Êܹ¥»÷µÄ×°±¸ÉèÖã¬ÆäÖÐÔÚÈ«¾Ö¼ì²éÕ½ÂÔ»ò×Ô½ç˵ÃüÃûµÄ¼ì²éÕ½ÂÔÉÏÆôÓÃÁËlog dropped-packets¹¦Ð§£¨ÈôÊÇÉèÖÃÖзºÆðÁËÆäÖÐÈκÎÒ»¸ö£¬Ôò×°±¸Ò×Êܹ¥»÷£©£º

Cisco IOS XE»ùÓÚÈí¼þÇøÓòµÄ·À»ðǽ¾Ü¾ø·þÎñÎó²î£¨CVE-2020-3480£©
¸ÃÎó²îÊÇÓÉÓÚͨ¹ý×°±¸Î´ÍêÕû´¦Öóͷ£µÚ4²ãÊý¾Ý°üËùÖ¡£¹¥»÷Õß¿ÉÒÔͨ¹ý×°±¸·¢ËÍÒ»¶¨Ë³ÐòµÄÁ÷Á¿Ä£Ê½À´Ê¹ÓôËÎó²î¡£
ÀÖ³ÉʹÓøÃÎó²î¿ÉÄÜʹ¹¥»÷Õßµ¼ÖÂ×°±¸×èֹͨ¹ý·À»ðǽת·¢Á÷Á¿£¬´Ó¶øµ¼Ö¾ܾø·þÎñ¡£¸ÃÎó²îCVSSÆÀ·Ö8.6·Ö£¬Îó²îÓ°ÏìÆ·¼¶¸ß¡£ÏÖÔÚ˼¿ÆÒѾÐû²¼Ïàʶ¾ö´ËÎó²îµÄÈí¼þ¸üС£
Îó²îϸ½Ú£º
ÈôÊÇÔÚ¼ì²é²ÎÊýͼÏÂÉèÖÃone-minute high¹¦Ð§£¬Ôò×°±¸»áÊܵ½Ó°Ïì¡£ÖÎÀíÔ±¿ÉÒÔͨ¹ýµÇ¼װ±¸²¢Ê¹ÓÃshow run | section parameter-map ÏÂÁîÀ´ÑéÖ¤´ËÎó²î¡£ÈôÊÇÊä³ö°üÀ¨one-minute highµÄÈκÎÐУ¬Ôò×°±¸Ò×Êܹ¥»÷¡£ÈçÏÂËùʾ£º

Cisco IOS XEí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3417£©
´ËÎó²îÊÇÓÉÓÚÆô¶¯¾ç±¾ÔÚÉèÖÃÌØ¶¨ROM monitor (ROMMON)±äÁ¿Ê±²»×¼È·µÄÑéÖ¤¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÔڵײãϵͳ(OS)µÄÌØ¶¨Ä¿Â¼ÖÐ×°ÖôúÂë²¢ÉèÖÃÌØ¶¨µÄROMMON±äÁ¿À´Ê¹ÓôËÎó²î¡£ÒªÊ¹ÓÃÕâ¸öÎó²î£¬¹¥»÷ÕßÐèÒªÔ¶³Ì»á¼û×°±¸£¬»òÕß¶Ô×°±¸¾ßÓÐÎïÆÊÎö¼ûȨÏÞ¡£
ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔڵײãϵͳÉÏÖ´ÐдúÂë¡£¸ÃÎó²îCVSSÆÀ·Ö6.8·Ö£¬Îó²îÓ°ÏìÆ·¼¶¸ß¡£ÏÖÔÚ˼¿ÆÒѾÐû²¼Ïàʶ¾ö´ËÎó²îµÄÈí¼þ¸üС£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚCisco¹Ù·½ÒÑÐû²¼Ïà¹ØÎó²îµÄÇå¾²¸üУ¬Îª×ÊÖúÈ·¶¨Cisco IOSºÍIOS XEÈí¼þÖеÄÎó²îΣº¦£¬CiscoÌṩÁËCisco Software Checker¹¤¾ßÀ´Ê¶±ðÓ°ÏìÌØ¶¨Èí¼þ°æ±¾µÄËùÓÐCiscoÇå¾²Îó²î£¬ÒÔ¼°Ã¿¸öͨ¸æÖÐËùÊöÎó²îµÄ¿ÉÐÞ¸´µÄ×îÔç°æ±¾¡£ÈôÊÇÊÊÓ㬸ù¤¾ß»¹»á·µ»Ø×îÔçµÄ¿¯Ðа棬¸Ã¿¯ÐаæÐÞ¸´ÁËËùÓÐÒÑÈ·¶¨µÄת´ïÖÐÐÎòµÄËùÓÐÎó²î¡£
¿ÉÒÔʹÓÃCisco Software Checker¹¤¾ß£º
1. Ñ¡ÔñÒ»¸öϵͳµÄÒ»¸ö»òÕß¶à¸ö°æ±¾¾ÙÐÐÎó²îÅÌÎÊ¡££¨¿Éƾ֤Îó²îµÄÑÏÖØÆ·¼¶¾ÙÐÐÅÌÎÊ£©
2. ÉÏ´«°æ±¾ÎļþÁÐ±í£¨.txtÎļþ£©¾ÙÐÐÎó²îÅÌÎÊ¡£
3. ÊäÈëshow versionÏÂÁîÊä³ö¡£
Èçͼ£º

Cisco Software Checker¹¤¾ßÁ´½Ó£º
https://tools.Cisco.com/security/center/softwarechecker.x
Çå¾²°æ±¾ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find/
0x03 ²Î¿¼Á´½Ó
https://tools.Cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=50#~Vulnerabilities
https://tools.Cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-sa-zbfw-94ckG4G#fs
https://tools.Cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-sa-xbace-OnCEbyS
https://threatpost.com/Cisco-patches-bugs/159537/
0x04 ʱ¼äÏß
2020-09-24 CiscoÐû²¼Ç徲ͨ¸æ
2020-09-25 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ