˼¿Æ220ϵÁÐÖÇÄÜ»¥»»»ú¶à¸ö°²È«·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-08-08? ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1912£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.1£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1913£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
? Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ºÏÓÃÓÚCisco Small Business 220 Series Smart Switches ¹Ì¼þ°æ±¾ < 1.1.4.4¡£
? ·ì϶¸ÅÊö
Cisco Small Business 220 Series Smart SwitchesÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»¿îÓ×ÐÍÖÇÄÜ»¥»»»úÉ豸¡£
˼¿Æ£¨Cisco Small Business£©220ϵÁÐÖÇÄÜ»¥»»»úµÄWebÖÎÀí½çÃæÖдæÔÚºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»Óгä·ÖÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµÄHTTP»òHTTPSÒªÇóÀûÓø÷ì϶ÒÔrootÓû§È¨ÏÞÖ´ÐÐËÁÒâµÄshellºÅÁî¡£
˼¿Æ£¨Cisco Small Business£©220ϵÁÐÖÇÄÜ»¥»»»úµÄWebÖÎÀí½çÃæÖдæÔÚÈÏÖ¤ÈÆ¹ý·ì϶£¬¸Ã·ì϶ԴÓÚ²»ÆëÈ«µÄȨÏ޲鳡£¹¥»÷ÕßÀûÓø÷ì϶Äܹ»ÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öÏÂÉÏ´«ËÁÒâÎļþ¡£
˼¿Æ£¨Cisco Small Business£©220ϵÁÐÖÇÄÜ»¥»»»úµÄWebÖÎÀí½çÃæÖдæÔÚ»º³åÇøÃýÎó·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»Óгä·ÖµØÑéÖ¤Óû§Ìá½»µÄÊý¾Ý²¢ÇÒûÓнøÐÐÕýÈ·µÄÌìǵ²é³¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµÄÒªÇóÀûÓø÷ì϶Ôڵײã²Ù×÷ϵͳÉÏÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£
? ·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
? ½¨¸´½¨Òé
˼¿ÆÒѾ°ä²¼ÁË×îеĹ̼þ°æ±¾£¬ÊÜÓ°ÏìµÄÓû§Ó¦ÊµÊ±Éý¼¶½øÐзÀ»¤£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-inject
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-auth_bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-rce
? ²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ