¶à¿îCisco²úÆ·ËÁÒâºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-11-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15271£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Cisco RV016 Multi-WAN VPN Router <4.2.3.10

Cisco RV042 Dual WAN VPN Router <4.2.3.10

Cisco RV042G Dual Gigabit WAN VPN Router <4.2.3.10

Cisco RV082 Dual WAN VPN Router <4.2.3.10


·ì϶¸ÅÊö


Cisco RV016 Multi-WAN VPN RouterµÈ¶¼ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»¿îVPN£¨Ð鹹רÓÃÍøÂ磩·ÓÉÆ÷¡£


¶à¿îCisco²úÆ·ÖеÄWebÖÎÀí½çÃæ´æÔÚËÁÒâºÅÁîÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Î´ÄܶÔHTTP payload½øÐÐÊäÈëÑéÖ¤£¬Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµÄHTTPÒªÇóÀûÓø÷ì϶ÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼ÁË·ì϶½¨¸´·¨Ê½£¬Çëʵʱ¹Ø×¢¸üУº


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-sbrv-cmd-x¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-sbrv-cmd-x