Cisco IOS XE¼°Ó×ÐÍÆóҵ·ÓÉÆ÷¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-29

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2017-3823£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½£º8.8
CVE±àºÅ£ºCVE-2019-1653£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2019-1652£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.2£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2019-1742£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1745£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1747£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1749£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1748£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1738£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1739£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1740£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1751£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1752£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1737£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1754£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1753£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1756£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1755£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1750£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1741£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1746£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1743£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1760£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1759£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.3£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1761£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º4.3£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1762£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º4.4£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1757£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.9£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1758£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º4.7£¬¹Ù·½Î´ÆÀ¶¨



Ó°Ïì²úÆ·



Cisco IOS XE¼°Ó×ÐÍÆóҵ·ÓÉÆ÷µÈ



·ì϶¸ÅÊö



˼¿ÆÏµÍ³ÖÜÈý°ä²¼Á˶à¸ö²¹¶¡£¬ÓëÆäIOS XE²Ù×÷ϵͳÖеķì϶ÓйØ¡£²¢ÖÒ¸æ¿Í»§Á½¸öÓ×ÐÍÆóҵ·ÓÉÆ÷£¨RV320ºÍRV325£©ÈÝÒ×Êܵ½¹¥»÷£¬²¢ÇÒÁ½Õß¶¼Ã»ÓпÉÓõIJ¹¶¡¡£Á½¸ö·ÓÉÆ÷ȱµãCVE-2019-1652ºÍCVE-2019-1653¶¼ÊÇÔÚ1Ô·ݳõ´Î´ò²¹¶¡£¬µ«Ë¼¿ÆÖÜÈý°µÊ¾Á½¸ö²¹¶¡¶¼¡°²»ÆëÈ«¡±£¬Á½¸ö·ÓÉÆ÷ÒÀÈ»ÈÝÒ×Êܵ½¹¥»÷¡£¸ÅÊöÈçÏ£º


CVE-2017-3823


Cisco WebExä¯ÀÀÆ÷À©´óÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃÊÜÓ°ÏìϵͳÉÏÊÜÓ°ÏìµÄä¯ÀÀÆ÷µÄȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£ ÔÚMicrosoft WindowsÉÏÔËÐÐʱ£¬´Ë·ì϶»áÓ°ÏìCisco WebEx Meetings ServerºÍCisco WebEx Centers£¨»áÒéÖÐÐÄ£¬»î¶¯ÖÐÐÄ£¬ÅàѵÖÐÐĺÍÖ§³ÖÖÐÐÄ£©µÄä¯ÀÀÆ÷À©´ó¡£
 ¸Ã·ì϶ÊÇÓɲå¼þÖеÄÀûÓ÷¨Ê½±à³Ì½Ó¿Ú£¨API£©ÏìÓ¦½âÎöÆ÷ÖеÄÉè¼ÆÈ±µãÒýÆðµÄ¡£ Äܹ»Ëµ·þÊÜÓ°ÏìµÄÓû§½Ó¼ûÊܹ¥»÷Õß½ÚÔìµÄÍøÒ³»ò¸ú×Ù¹¥»÷ÕßÌṩµÄÊÜÓ°Ïìä¯ÀÀÆ÷Á´½ÓµÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶¡£ ÈôÊdzɹ¦£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÊÜÓ°ÏìµÄä¯ÀÀÆ÷µÄȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£


CVE-2019-1653


Cisco Small Business RV320ºÍRV325˫ǧÕ×WAN VPN·ÓÉÆ÷µÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¼ìË÷Ãô¸ÐÐÅÏ¢¡£
¸Ã·ì϶ÊÇÓÉÓÚ¶ÔURLµÄ½Ó¼û½ÚÔì²»µ±Ôì³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýHTTP»òHTTPSÏνӵ½ÊÜÓ°ÏìµÄÉ豸²¢ÒªÇóÌØ¶¨µÄURLÀ´ÀûÓô˷ì϶¡£ ³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷ÕßÏÂÔØÂ·ÓÉÆ÷ÅäÖûò¾ßÌåµÄÕï¶ÏÐÅÏ¢¡£
¸üУ¬2019Äê3ÔÂ27ÈÕ£º·¢ÏÖ´Ë·ì϶µÄ³õʼ½¨¸´·¨Ê½²»ÆëÈ«¡£ ˼¿ÆÄ¿Ç°ÔÚ½øÐÐÈ«Ãæ½¨¸´¡£ Ò»µ©¹Ì¶¨´úÂë¿ÉÓ㬸ÃÎĵµ½«¸üС£


CVE-2019-1652


Cisco Small Business RV320ºÍRV325˫ǧÕ×WAN VPN·ÓÉÆ÷µÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеķì϶¿ÉÄÜÔÊÐíÓµÓÐÊÜÓ°ÏìÉ豸ÖÎÀíȨÏ޵ľ­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâºÅÁî¡£
¸Ã·ì϶ÊÇÓÉÓÚÓû§ÌṩµÄÊäÈëÑéÖ¤²»ÕýÈ·¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìÉ豸µÄ»ùÓÚWebµÄÖÎÀí½çÃæ·¢ËͶñÒâHTTP POSTÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷ÕßÒÔrootÉí·ÝÔڵײãLinux shellÉÏÖ´ÐÐËÁÒâºÅÁî¡£
¸üУ¬2019Äê3ÔÂ27ÈÕ£º·¢ÏÖ´Ë·ì϶µÄ³õʼ½¨¸´·¨Ê½²»ÆëÈ«¡£Ë¼¿ÆÄ¿Ç°ÔÚ½øÐÐÈ«Ãæ½¨¸´¡£Ò»µ©¹Ì¶¨´úÂë¿ÉÓ㬸ÃÎĵµ½«¸üС£


CVE-2019-1742


Cisco IOS XEÈí¼þµÄWeb UIÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß½Ó¼ûÃô¸ÐÅäÏàÐÅÏ¢¡£
¸Ã·ì϶ÊÇÓÉÓÚ¶ÔWeb UIÖеÄÎļþµÄ²»ÕýÈ·½Ó¼û½ÚÔì×÷³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶¡£ ³É¹¦ÀûÓÃÄܹ»Ê¹¹¥»÷Õß»ñµÃ¶ÔÃô¸ÐÅäÏàÐÅÏ¢µÄ½Ó¼ûȨÏÞ¡£


CVE-2019-1745


Cisco IOS XEÈí¼þÖеķì϶¿ÉÄÜÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄ±¾µØ¹¥»÷Õß×¢ÈëÒÔÌáÉýµÄȨÏÞÖ´ÐеÄËÁÒâºÅÁî¡£
¸Ã·ì϶ÊÇÓÉÓÚÓû§ÌṩµÄºÅÁîµÄÊäÈëÑéÖ¤²»¼°¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÉ豸½øÐÐÉí·ÝÑéÖ¤²¢ÏòÊÜÓ°ÏìµÄºÅÁîÌá½»¾«ÐÄÉè¼ÆµÄÊäÈëÀ´ÀûÓô˷ì϶¡£ ÀûÓ÷ì϶¿ÉÄÜÔÊÐí¹¥»÷Õß»ñµÃÊÜÓ°ÏìÉ豸µÄrootȨÏÞ¡£


CVE-2019-1747


Ö´ÐÐCisco IOSÈí¼þºÍCisco IOS XEÈí¼þµÄ¶ÌÐÂÎÅ·þÎñ£¨SMS£©´¦ÖÃÖ°Äܵķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸ÉÏ´¥·¢»Ø¾ø·þÎñ£¨DoS£©Ç°Ìá¡£


¸Ã·ì϶ÊÇÓÉÓÚʹÓÃÌØÊâ×Ö·û¼¯±àÂëµÄSMSºÍ̸Êý¾Ýµ¥Ôª£¨PDU£©µÄ²»ÕýÈ·´¦ÖÃÔì³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâSMSÐÂÎÅÀ´ÀûÓô˷ì϶¡£ ³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÊÜÓ°ÏìÉ豸ÉϵÄÎÞÏßWAN£¨WWAN£©·äÎѽӿÚÄ£¿é±ÀÀ££¬´Ó¶øµ¼Ö±ØÒªÊÖ¶¯¹ýÎÊÒÔ¸´Ô­Õý³£²Ù×÷ǰÌáµÄDoSǰÌá¡£


CVE-2019-1749


ÓÃÓÚCisco¾ÛºÏ·þÎñ·ÓÉÆ÷£¨ASR£©900·ÓÉ»¥»»»ú´¦ÖÃÆ÷3£¨RSP3£©µÄCisco IOS XEÈí¼þµÄÈë¿ÚÁ÷Á¿ÑéÖ¤Öеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÏàÁÚ¹¥»÷Õß´¥·¢ÊÜÓ°ÏìÉ豸µÄ³ÁмÓÔØ£¬´Ó¶øµ¼Ö»ؾø·þÎñ £¨DoS£©Ç°Ìá¡£


¸Ã·ì϶µÄ´æÔÚÊÇÓÉÓÚ¸ÃÈí¼þ²»Äܳä·ÖÑéÖ¤RSP3ƽ̨ÉÏʹÓõÄASICÉϵÄÈë¿ÚÁ÷Á¿¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËÍÌåʽÃýÎóµÄOSPF°æ±¾2£¨OSPFv2£©ÐÂÎÅÀ´ÀûÓô˷ì϶¡£ ³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷Õß³ÁмÓÔØiosd¹ý³Ì£¬´¥·¢ÊÜÓ°ÏìÉ豸µÄ³ÁмÓÔØ²¢µ¼ÖÂDoSǰÌá¡£


CVE-2019-1748


Cisco IOSÈí¼þºÍCisco IOS XEÈí¼þµÄ˼¿ÆÍøÂç¼´²å¼´Óã¨PnP£©´úÀíÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßδ¾­ÊÚȨ½Ó¼ûÃô¸ÐÊý¾Ý¡£


¸Ã·ì϶µÄ´æÔÚÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þ²»¼°ÒÔÑéÖ¤Ö¤Êé¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸ÌṩÔì×÷µÄÖ¤ÊéÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷Õß½øÐÐÖÐÑëÈ˹¥»÷£¬ÒÔ½âÃܺÍÅú¸ÄÓû§ÓëÊÜÓ°ÏìÈí¼þµÄÏνӵĻúÃÜÐÅÏ¢¡£


CVE-2019-1738 CVE-2019-1739 CVE-2019-1740


Cisco IOSÈí¼þºÍCisco IOS XEÈí¼þµÄ»ùÓÚÍøÂçµÄÀûÓ÷¨Ê½¼ø±ð£¨NBAR£©Ö°ÄÜÖеĶà¸ö·ì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼ÖÂÊÜÓ°ÏìµÄÉ豸³ÁмÓÔØ¡£ ÕâЩ·ì϶ÊÇÓÉDNS½âÎöÆ÷ÉϵĽâÎöÎÊÌâÒýÆðµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÔËÐÐÊÜÓ°Ïì°æ±¾ÇÒÆôÓÃÁËNBARµÄ·ÓÉÆ÷·¢Ë;«ÐÄÉè¼ÆµÄDNSÊý¾Ý°üÀ´ÀûÓÃÕâЩ·ì϶¡£ ³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷Õß³ÁмÓÔØÊÜÓ°ÏìµÄÉ豸£¬´Ó¶øµ¼Ö»ؾø·þÎñ£¨DoS£©Ç°Ìá¡£


CVE-2019-1751


Cisco IOSÈí¼þµÄÍøÂçµØÖ·×ª»»64£¨NAT64£©Ö°ÄÜÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼Ö½ӿڶÓÁÐШÈë»òÉ豸³ÁмÓÔØ¡£


¸Ã·ì϶ÊÇÓÉÓÚ¶Ôͨ¹ýÉ豸·¢Ë͵ÄijЩIPv4Êý¾Ý°üÁ÷µÄÃýÎó´¦ÖÃÔì³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÉ豸·¢ËÍÌØ¶¨µÄIPv4Êý¾Ý°üÁ÷À´ÀûÓô˷ì϶¡£ ¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷Õßµ¼Ö½ӿڶÓÁÐШÈë»òÉ豸³ÁмÓÔØ£¬´Ó¶øµ¼Ö»ؾø·þÎñ£¨DoS£©Ç°Ìá¡£


CVE-2019-1752


Cisco IOSÈí¼þºÍCisco IOS XEÈí¼þµÄISDNÖ°ÄÜÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼ÖÂÉ豸³ÁмÓÔØ¡£
¸Ã·ì϶ÊÇÓÉÓÚQ.931ÐÅÏ¢ÔªËØÖÐÌØ¶¨ÖµµÄÃýÎó´¦ÖÃÔì³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýʹÓÃÌØ¶¨µÄQ.931ÐÅÏ¢ÔªËØÅ²ÓÃÊÜÓ°ÏìµÄÉ豸À´ÀûÓô˷ì϶¡£ ¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷Õß³ÁмÓÔØÉ豸£¬´Ó¶øµ¼ÖÂÊÜÓ°ÏìÉ豸ÉϵĻؾø·þÎñ£¨DoS£©Ç°Ìá¡£


CVE-2019-1737


Cisco IOSÈí¼þºÍCisco IOS XEÈí¼þ´¦ÖÃIP·þÎñˮƽºÍ̸£¨SLA£©Êý¾Ý°üʱµÄ·ì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÒýÆð½Ó¿ÚШÈëºÍ×îÖջؾø·þÎñ£¨DoS£©Çé¿ö¡£


¸Ã·ì϶ÊÇÓÉÓÚIP SLAÏìÓ¦·¨Ê½ÀûÓ÷¨Ê½´úÂëÖеÄÌ×½Ó×Ö×ÊÔ´´¦Öò»µ±Ôì³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢Ë;«ÐÄÉè¼ÆµÄIP SLAÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£ ¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷Õßʹ½Ó¿Ú±äΪШÈ룬´Ó¶øµ¼ÖÂÊÜÓ°ÏìÉ豸ÉϵÄ×îÖջؾø·þÎñ£¨DoS£©Ç°Ìá¡£


CVE-2019-1754


Cisco IOS XEÈí¼þµÄÊÚȨ×ÓϵͳÖеķì϶¿ÉÄÜÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µ«ÎÞÌØÈ¨£¨1¼¶£©µÄÔ¶³Ì¹¥»÷Õßͨ¹ýʹÓÃWeb UIÔËÐÐÌØÈ¨Cisco IOSºÅÁî¡£


¸Ã·ì϶ÊÇÓÉÓÚ¶ÔWeb UIÓû§µÄÓû§È¨Ï޵IJ»ÕýÈ·ÑéÖ¤Ôì³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòWeb UIÖеÄÌØ¶¨¶ËµãÌá·´Ä¿Òâ¸ºÔØÀ´ÀûÓô˷ì϶¡£ ³É¹¦ÀûÓÃÄܹ»ÔÊÐí½ÏµÍȨÏ޵Ĺ¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐÓµÓиü¸ßȨÏÞµÄËÁÒâºÅÁî¡£


CVE-2019-1753


Cisco IOS XEÈí¼þµÄWeb UIÖеķì϶¿ÉÄÜÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µ«ÎÞÌØÈ¨£¨1¼¶£©µÄÔ¶³Ì¹¥»÷ÕßʹÓÃWeb UIÔËÐÐÌØÈ¨Cisco IOSºÅÁî¡£


¸Ã·ì϶ÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ºÍËãÕÊWeb·þÎñÖÎÀí´úÀí£¨WSMA£©Ö°ÄÜÖеÄÊäÈë¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìÉ豸µÄWeb UIÌá·´Ä¿Òâ¸ºÔØÀ´ÀûÓô˷ì϶¡£ ³É¹¦ÀûÓÃÄܹ»ÔÊÐí½ÏµÍȨÏ޵Ĺ¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐÓµÓиü¸ßȨÏÞµÄËÁÒâºÅÁî¡£


CVE-2019-1756


Cisco IOS XEÈí¼þÖеķì϶¿ÉÄÜÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃrootȨÏÞÔÚÊÜÓ°ÏìÉ豸µÄµ×²ãLinux shellÉÏÖ´ÐкÅÁî¡£
³öÏÖ´Ë·ì϶µÄÔ­ÒòÊÇÊÜÓ°ÏìµÄÈí¼þ²»ÕýÈ·µØËãÕÊÁËÓû§ÌṩµÄÊäÈë¡£ ÓµÓжÔÊÜÓ°ÏìÉ豸µÄÓÐЧÖÎÀíÔ±½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÄܹ»Í¨¹ýÔÚWeb UIÖÐÌṩӵÓжñÒâ¸ºÔØµÄÓû§Ãû²¢ËæºóÏòWeb UIÖеÄÌØ¶¨¶Ëµã·¢³öÒªÇóÀ´ÀûÓô˷ì϶¡£ ³É¹¦µÄ¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷ÕßÒÔrootÓû§Éí·ÝÔËÐÐËÁÒâºÅÁ´Ó¶øÆëÈ«·ÛËéϵͳ¡£


CVE-2019-1755


Cisco IOS XEÈí¼þµÄWeb·þÎñÖÎÀí´úÀí£¨WSMA£©Ö°ÄÜÖеķì϶¿ÉÄÜÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔÌØÈ¨¼¶±ð15Óû§Éí·ÝÖ´ÐÐËÁÒâCisco IOSºÅÁî¡£


³öÏÖ´Ë·ì϶µÄÔ­ÒòÊÇÊÜÓ°ÏìµÄÈí¼þ²»ÕýÈ·µØËãÕÊÁËÓû§ÌṩµÄÊäÈë¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êÀûÓ÷¨Ê½Ìá½»¾«ÐÄÉè¼ÆµÄHTTPÒªÇóÀ´ÀûÓô˷ì϶¡£ ³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐËÁÒâºÅÁî¡£


CVE-2019-1750


Catalyst 4500ϵÁл¥»»»úÉÏCisco IOS XEÈí¼þµÄ¼òÒ×Ðé¹¹»¥»»ÏµÍ³£¨VSS£©Öеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÏàÁÚ¹¥»÷Õßµ¼Ö»¥»»»ú³ÁмÓÔØ¡£


¸Ã·ì϶ÊÇÓÉÓÚ´¦ÖÃÓëEasy Virtual Switching Systemһ·ʹÓõÄCisco·¢ÏÖºÍ̸£¨CDP£©Êý¾Ý°üʱµÄÃýÎó´¦Öò»ÆëÈ«¡£ ¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËÍÌØÔìµÄCDPÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£ ¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷Õß³ÁмÓÔØÉ豸£¬´Ó¶øµ¼Ö»ؾø·þÎñ£¨DoS£©Ç°Ìá¡£


CVE-2019-1741


Cisco IOS XEÈí¼þµÄ˼¿Æ¼ÓÃÜÁ÷Á¿·ÖÎö£¨ETA£©Ö°ÄÜÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼Ö»ؾø·þÎñ£¨DoS£©Çé¿ö¡£


¸Ã·ì϶ÊÇÓÉÓÚ´¦ÖÃÌåʽÃýÎóµÄ´«ÈëÊý¾Ý°üʱ´æÔÚµÄÂß¼­ÃýÎóµ¼ÖÂÔÚ¿ªÊͺó½Ó¼ûÄÚ²¿Êý¾Ý½á¹¹¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢Ë;«ÐÄÉè¼ÆµÄÌåʽÃýÎóµÄIPÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£ ³É¹¦ÀûÓù¥»÷¿ÉÄÜ»áʹ¹¥»÷Õß³ÁмÓÔØÊÜÓ°ÏìµÄÉ豸£¬´Ó¶øµ¼ÖÂDoSÇé¿ö¡£


CVE-2019-1746


Cisco IOSÈí¼þºÍCisco IOS XEÈí¼þÖеÄȺ¼¯ÖÎÀíºÍ̸£¨CMP£©´¦ÖôúÂëÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÏàÁÚ¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸ÉÏ´¥·¢»Ø¾ø·þÎñ£¨DoS£©Ç°Ìá¡£


¸Ã·ì϶ÊÇÓÉÓÚ´¦ÖÃCMPÖÎÀíÊý¾Ý°üʱÊäÈëÑéÖ¤²»¼°Ôì³ÉµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâCMPÖÎÀíÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓÿÉÄܻᵼÖ»¥»»»ú±ÀÀ££¬´Ó¶øµ¼ÖÂDoSÇé¿ö¡£ »¥»»»ú½«×Ô¶¯³ÁмÓÔØ¡£


CVE-2019-1743


Cisco IOS XEÈí¼þµÄWeb UI¿ò¼ÜÖеķì϶¿ÉÄÜÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶ÔÊÜÓ°ÏìÉ豸µÄÎļþϵͳ½øÐÐδ¾­ÊÚȨµÄ¸ü¸Ä¡£


¸Ã·ì϶ÊÇÓÉÓÚÊäÈëÑéÖ¤²»µ±Ôì³ÉµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔì×÷¶ñÒâÎļþ²¢½«ÆäÉÏ´«µ½É豸À´ÀûÓô˷ì϶¡£¹¥»÷Äܹ»ÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸ÉÏ»ñµÃÌáÉýµÄȨÏÞ¡£


CVE-2019-1760


Cisco IOS XEÈí¼þµÄ»úÄÜ·Óɰ汾3£¨PfRv3£©Öеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼ÖÂÊÜÓ°ÏìµÄÉ豸³ÁмÓÔØ¡£
¸Ã·ì϶ÊÇÓÉÓÚ´¦ÖÃÌåʽÃýÎóµÄÖÇÄÜ̽²âÊý¾Ý°üËùÖ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚÊÜÓ°ÏìµÄÉ豸ÉÏ·¢ËÍÌØÔìµÄÖÇÄÜ̽²âÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷Õß³ÁмÓÔØÉ豸£¬´Ó¶øµ¼Ö¶ÔÊÜÓ°ÏìϵͳµÄ»Ø¾ø·þÎñ£¨DoS£©¹¥»÷¡£


CVE-2019-1759


Cisco IOS XEÈí¼þµÄǧÕ×ÒÔÌ«ÍøÖÎÀí½Ó¿ÚµÄ½Ó¼û½ÚÔìÁÐ±í£¨ACL£©Ö°ÄÜÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß½Ó¼ûǧÕ×ÒÔÌ«ÍøÖÎÀí½Ó¿ÚÉÏÅäÖõÄIPµØÖ·¡£


¸Ã·ì϶ÊÇÓÉCisco IOS XEÈí¼þ16.1.1°æ±¾ÖÐÒýÈëµÄÂß¼­ÃýÎóÒýÆðµÄ£¬¸ÃÃýÎó»á×èÖ¹ACLÔÚÀûÓÃÓÚÖÎÀí½Ó¿Úʱ¹¤×÷¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÖÎÀí½çÃæ³¢ÊÔ½Ó¼ûÉ豸À´ÀûÓôËÎÊÌâ¡£


CVE-2019-1761


Cisco IOSºÍIOS XEÈí¼þµÄÈȱ¸Ó÷ÓÉÆ÷ºÍ̸£¨HSRP£©×ÓϵͳÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÏàÁÚ¹¥»÷Õß´ÓÊÜÓ°ÏìµÄÉ豸½Ó¹ÜDZÔÚµÄÃô¸ÐÐÅÏ¢¡£¸Ã·ì϶ÊÇÓÉÓÚÄÚ´æ³õʼ»¯²»¼°Ôì³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ý´ÓÏàÁÚHSRP³ÉÔ±½Ó¹ÜHSRPv2Á÷Á¿À´ÀûÓô˷ì϶¡£³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷Õß´ÓÏàÁÚÉ豸½Ó¹ÜDZÔÚµÄÃô¸ÐÐÅÏ¢¡£


CVE-2019-1762


Cisco IOSºÍIOS XEÈí¼þµÄ°²È«´æ´¢Ö°ÄÜÖеķì϶¿ÉÄÜÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄ±¾µØ¹¥»÷Õß½Ó¼ûÊÜÓ°ÏìÉ豸ÉϵÄÃô¸ÐϵͳÐÅÏ¢¡£
¸Ã·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þ´¦ÖÃÅäÖøüÐÂʱÔÚ¼ÓÃÜʱִÐеIJ»ÕýÈ·µÄÄÚ´æ²Ù×÷¡£¹¥»÷ÕßÄܹ»Í¨¹ý¼ìË÷ÊÜÓ°ÏìÉ豸µÄÌØ¶¨ÄÚ´æµØÎ»µÄÄÚÈÝÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓÿÉÄܵ¼ÖÂ×÷ΪÉ豸ÅäÖõÄÒ»²¿ÃŵÄÃÜÔ¿×ÊÁϵĹ«¿ª£¬Æä¿ÉÓÃÓÚ¸´Ô­¹Ø¼üϵͳÐÅÏ¢¡£


CVE-2019-1757


Cisco IOSºÍIOS XEÈí¼þµÄ˼¿ÆÖÇÄܺô½ÐÖ÷Ò³Ö°ÄÜÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃÎÞЧ֤Êé¶ÔÃô¸ÐÊý¾Ý½øÐÐδ¾­ÊÚȨµÄ¶ÁÈ¡½Ó¼û¡£


¸Ã·ì϶ÊÇÓÉÊÜÓ°ÏìµÄÈí¼þÑéÖ¤Ö¤Êé²»¼°Ôì³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸ÌṩÔì×÷µÄÖ¤ÊéÀ´ÀûÓô˷ì϶¡£ ³É¹¦µÄ¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷Õß½øÐÐÖÐÑëÈ˹¥»÷£¬ÒÔ½âÃÜÓû§ÓëÊÜÓ°ÏìÈí¼þµÄÏνÓÉϵĻúÃÜÐÅÏ¢¡£


CVE-2019-1758


Catalyst 6500ϵÁл¥»»»úÉÏCisco IOSÈí¼þµÄ802.1xÖ°ÄÜÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÏàÁÚ¹¥»÷ÕßÔÚÉí·ÝÑé֤֮ǰ½Ó¼ûÍøÂç¡£


¸Ã·ì϶ÊÇÓÉÓÚÔÚ¹ý³Ìõè¾¶Öд¦ÖÃ802.1xÊý¾Ý°üµÄ·½Ê½¡£¹¥»÷ÕßÄܹ»Í¨¹ý³¢ÊÔÔÚ802.1xÅäÖõĶ˿ÚÉÏÏνӵ½ÍøÂçÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷Õß¼äЪÐԵػñµÃ¶ÔÍøÂçµÄ½Ó¼û¡£



½¨¸´½¨Òé



Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶¡£



²Î¿¼Á´½Ó



https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170124-webex
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-inject
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-xeid
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-xecmd
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-sms-dos
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-rsp3-ospf
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-pnp-cert
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-nbar
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-nat64
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-isdn
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-ipsla-dos
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-iosxe-privesc
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-iosxe-pe
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-iosxe-cmdinject
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-iosxe-cmdinj
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-evss
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-eta-dos
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-cmp-dos
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-afu
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-pfrv3
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-mgmtacl
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-ios-infoleak
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-info
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-call-home-cert
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-c6500