¡¾Îó²îͨ¸æ¡¿Cisco 1Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-01-210x00 Îó²î¸ÅÊö
2021Äê01ÔÂ20ÈÕ£¬CiscoÐû²¼Ç徲ͨ¸æ£¬¹ûÕæÁËCisco SD-WAN¡¢DNA CenterºÍSmart Software Manager SatelliteµÈ¶à¸ö²úÆ·ÖеĶà¸öÇå¾²Îó²î¡£
0x01 Îó²îÏêÇé

Cisco SD-WANÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1260¡¢CVE-2021-1261¡¢CVE-2021-1262¡¢CVE-2021-1263¡¢CVE-2021-1298ºÍCVE-2021-1299£©
Cisco SD-WAN²úÆ·Öб£´æ¶à¸öÏÂÁî×¢ÈëÎó²î£¬ÆäÖУ¬CVE-2021-1260¡¢CVE-2021-1261¡¢CVE-2021-1262¡¢CVE-2021-1263ºÍCVE-2021-1298µÄCVSSÆÀ·ÖÔÚ5.3-7.8Ö®¼ä£¬ÀÖ³ÉʹÓÃÕâЩÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¶ÔÊÜÓ°ÏìµÄ×°±¸Ö´ÐÐÏÂÁî×¢Èë¹¥»÷£¬×îÖÕ¹¥»÷Õß¿ÉÒÔÔÚ×°±¸ÉÏÒÔrootȨÏÞÖ´ÐÐijЩ²Ù×÷¡£
ÖµµÃ×¢ÖØµÄÊÇCisco SD-WAN vManageÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1299£©£¬Æä±£´æÓÚ»ùÓÚWebµÄÖÎÀí½çÃæÖУ¬ÊÇÓû§¶Ô×°±¸Ä£°åÉèÖÃÌṩµÄÐÅÏ¢µÄÊäÈëÑéÖ¤²»×¼È·Ôì³ÉµÄ£¬CVSSÆÀ·Ö9.9¡£
¹¥»÷Õß¿ÉÒÔͨ¹ýÏò×°±¸Ä£°åÉèÖÃÌá½»¶ñÒâÐÅÏ¢À´Ê¹ÓôËÎó²î£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÊÜÓ°ÏìϵͳµÄrootȨÏÞ¡£
Ó°Ïì¹æÄ£
ÈôÊÇÕýÔÚÔËÐÐÒ×ÊÜÓ°ÏìµÄCisco SD-WAN°æ±¾£¬ÔòÕâЩÎó²î»áÓ°ÏìÒÔÏÂCisco²úÆ·£º
SD-WAN vBond OrchestratorÈí¼þ
SD-WAN vEdgeÔÆÂ·ÓÉÆ÷
SD-WAN vEdge·ÓÉÆ÷
SD-WAN vManageÈí¼þ
SD-WAN vSmart¿ØÖÆÆ÷Èí¼þ
ÐÞ¸´°æ±¾
Cisco SD-WAN°æ±¾ | ÕâЩÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ת´ï¼¯ÖÐÐÎòµÄËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
ÔçÓÚ18.3 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
18.3 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
18.4 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
19.2 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
19.3 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
20.1 | 20.1.2 | Ǩáãµ½Àο¿°æ±¾¡£ |
20.3 | 20.3.2 | 20.3.2 |
20.4 | 20.4.1 | 20.4.1 |
Cisco SD-WAN»º³åÇøÒç³öÎó²î£¨CVE-2021-1300£©
¸ÃÎó²îÊǶÔIPÁ÷Á¿µÄ²»×¼È·´¦Öóͷ£Ôì³ÉµÄ£¬ÆäCVSSÆÀ·Ö9.8¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâIPÁ÷Á¿À´Ê¹ÓôËÎó²î£¬×îÖÕµ¼Ö»º³åÇøÒç³ö¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔrootȨÏÞÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
±ðµÄ£¬Cisco SD-WANµÄNETCONF×ÓϵͳÖл¹±£´æÁíÒ»¸ö»º³åÇøÒç³öÎó²î£¨CVE-2021-1301£©£¬¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔÚÊÜÓ°ÏìµÄ×°±¸»òϵͳÉϵ¼Ö¾ܾø·þÎñ£¬ÆäCVSSÆÀ·Ö6.5¡£
Ó°Ïì¹æÄ£
ÈôÊÇÕýÔÚÔËÐÐÒ×ÊÜÓ°ÏìµÄCisco SD-WAN°æ±¾£¬ÔòÕâЩÎó²î»áÓ°ÏìÒÔÏÂCisco²úÆ·£º
IOS XE SD-WANÈí¼þ
SD-WAN vBond OrchestratorÈí¼þ
SD-WAN vEdgeÔÆÂ·ÓÉÆ÷
SD-WAN vEdge·ÓÉÆ÷
SD-WAN vManageÈí¼þ
SD-WAN vSmart¿ØÖÆÆ÷Èí¼þ
ÐÞ¸´°æ±¾
SD-WAN
Cisco SD-WAN°æ±¾ | Îó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
ÔçÓÚ18.3 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
18.3 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
18.4 | 18.4.5 | Ǩáãµ½Àο¿°æ±¾¡£ |
19.2 | 19.2.2 | Ǩáãµ½Àο¿°æ±¾¡£ |
19.3 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
20.1 | 20.1.1 | Ǩáãµ½Àο¿°æ±¾¡£ |
20.3 | 20.3.1 | 20.3.2 |
20.4 | 20.4.1 | 20.4.1 |
IOS XE SD-WAN
Cisco IOS XE SD-WAN°æ±¾ | Îó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
16.9 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
16.10 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
16.11 | Ǩáãµ½Àο¿°æ±¾¡£ | Ǩáãµ½Àο¿°æ±¾¡£ |
16.12 | 16.12.4 | 16.12.4 |
IOS XE
Cisco IOS XEͨÓð汾 | Îó²îµÄµÚÒ»¸öÀο¿°æ±¾ | ËùÓÐÎó²îµÄµÚÒ»¸öÀο¿°æ±¾ |
17.2 | 17.2.1 | 17.2.2 |
17.3 | 17.3.1 | 17.3.1 |
17.4 | 17.4.1 | 17.4.1 |
Cisco DNA Center Command Runner ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1264£©
¸ÃÎó²î±£´æÓÚCisco DNA CenterµÄCommand Runner¹¤¾ßÖУ¬ÆäCVSSÆÀ·Ö9.6¡£
¸ÃÎó²îÊÇCommand Runner¹¤¾ßÊäÈëÑé֤ȱ·¦µ¼Öµġ£¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÏÂÁîÖ´ÐÐʱ´úʹÓöñÒâÊäÈë»òŲÓÃÏÂÁîÔËÐгÌÐòAPIÀ´Ê¹ÓôËÎó²î£¬×îÖÕÄܹ»ÔÚCisco DNA CenterÖÎÀíµÄ×°±¸ÉÏÖ´ÐÐí§ÒâCLIÏÂÁî¡£
Ó°Ïì¹æÄ£
Cisco DNA Center Software < 1.3.1.0
ÐÞ¸´°æ±¾
Cisco DNA Center Software >= 1.3.1.0
Cisco Smart Software Manager Satellite Web UIÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1138¡¢CVE-2021-1140ºÍCVE-2021-1142£©
Õâ3¸öÎó²î¶¼ÊÇCiscoÖÇÄÜÈí¼þÖÎÀíÆ÷SatelliteµÄWeb UIÖеÄÏÂÁî×¢ÈëÎó²î£¬ËüÃǶ¼ÊÇÊäÈëÑé֤ȱ·¦µ¼Öµģ¬ÆäCVSSÆÀ·Ö9.8¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâHTTPÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬ÀÖ³ÉʹÓÃÕâЩÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÉÏÔËÐÐí§ÒâÏÂÁî¡£
±ðµÄ£¬CiscoÖÇÄÜÈí¼þÖÎÀíÆ÷SatelliteµÄWeb UIÖл¹±£´æÆäËü2¸öÊäÈëÑé֤ȱ·¦µ¼ÖµÄÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1139ºÍCVE-2021-1141£©£¬ÆäCVSSÆÀ·Ö¾ùΪ8.8¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâHTTPÇëÇóÀ´Ê¹ÓÃËüÃÇ£¬×îÖÕ¿ÉÒÔÒÔrootÓû§µÄÉí·ÝÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£
Ó°Ïì¹æÄ£
Cisco Smart Software Manager Satellite <= 5.1.0
ÐÞ¸´°æ±¾
Cisco Smart Software Manager On-Prem >= 6.3.0
×¢£ºÔÚ6.3.0°æ±¾ÖУ¬Cisco Smart Software Manager Satellite±»ÖØÃüÃûΪCisco Smart Software Manager On-Prem¡£
0x02 ´¦Öóͷ£½¨Òé
½¨Òé²Î¿¼Cisco¹Ù·½Ðû²¼µÄÇ徲ͨ¸æÉý¼¶ÖÁ×îа汾¡£
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-cmdinjm-9QMSmgcn
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-pre-auth-bugs-in-sd-wan-cloud-license-manager/
0x04 ʱ¼äÏß
2021-01-20 CiscoÐû²¼Ç徲ͨ¸æ
2021-01-21 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ