Cisco | ¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-10-22

 

0x00 ·ì϶¸ÅÊö

2020Äê10ÔÂ21ÈÕ£¬Cisco°ä²¼°²È«²¼¸æ£¬Æä¶à¸ö²úÆ·ÖдæÔÚÑϳÁ°²È«·ì϶¡£Õâ´Î°ä²¼µÄ°²È«·ì϶¹²¼Æ36¸ö£¬ÆäÖÐ20¸ö·ì϶Ϊ¸ßΣ£¬16¸öΪÖÐΣ¡£


0x01 ·ì϶ÏêÇé

 

image.png

CiscoÕâ´Î°ä²¼µÄ°²È«·ì϶ÖУ¬É漰˼¿ÆFirepowerÍþв·ÀÓù£¨FTD£©¡¢Cisco Firepower»úÏäÖÎÀíÆ÷£¨FCM£©ºÍ×ÔÊÊÓ¦°²È«É豸£¨ASA£©µÄ¸ßΣ·ì϶Ϊ17¸ö£¬ÈçÏ£º

   

˼¿Æ°²È«Õ÷ѯ/·ìϼûû³Æ

CVE   ID

°²È«Ó°ÏìµÈ¼¶

¸ù±¾·ÖÊý

cisco-sa-asaftd-dos-QFcNEPfx

˼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍFirepowerÍþв·ÀÓùÈí¼þ»Ø¾ø·þÎñ·ì϶

CVE-2020-3554

¸ß

8.6

cisco-sa-asaftd-frag-memleak-mCtqdP9n
 
˼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍFirepowerÍþв·ÀÓùÈí¼þIPƬ¶ÎÄÚ´æÐ¹Â©·ì϶

CVE-2020-3373

¸ß

8.6

cisco-sa-asaftd-ospflls-37Xy2q6r
 
˼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍFirepowerÍþв·ÀÓùÈí¼þOSPFv2Á´Â·±¾µØÐÅÁî»Ø¾ø·þÎñ·ì϶

CVE-2020-3528

¸ß

8.6

cisco-sa-asaftd-sslvpndma-dos-HRrqB9Yx
 
˼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍFirepowerÍþв·ÀÓùÈí¼þSSL VPNÖ±½ÓÄÚ´æ½Ó¼û»Ø¾ø·þÎñ·ì϶

CVE-2020-3529

¸ß

8.6

cisco-sa-asa-ftd-tcp-dos-N3DMnU4T
 
˼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍFirepowerÍþв·ÀÓùÈí¼þSSL/TLS»á»°»Ø¾ø·þÎñ·ì϶

CVE-2020-3572

¸ß

8.6

cisco-sa-asaftd-webdos-fBzM5Ynw
 
˼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍFirepowerÍþв·ÀÓùÈí¼þWeb·þÎñ»Ø¾ø·þÎñ·ì϶

CVE-2020-3304

¸ß

8.6

cisco-sa-asaftd-fileup-dos-zvC7wtys
 
˼¿Æ×ÔÊÊÓ¦°²È«É豸Èí¼þºÍFirepowerÍþв·ÀÓùÈí¼þWeb·þÎñÎļþÉÏ´«»Ø¾ø·þÎñ·ì϶

CVE-2020-3436

¸ß

8.6

cisco-sa-ftd-ssl-dcrpt-dos-RYEkX4yy
  Cisco Firepower 2100
ϵÁÐSSL / TLS²é³­»Ø¾ø·þÎñ·ì϶

CVE-2020-3562

¸ß

8.6

cisco-sa-ftd-icmp-dos-hxxcycM
  Cisco Firepower 4110 ICMP Flood
»Ø¾ø·þÎñ·ì϶

CVE-2020-3571

¸ß

8.6

cisco-sa-ftdfmc-dirtrav-NW8XcuSB
 
˼¿ÆFirepowerÖÎÀíÖÐÐÄÈí¼þºÍFirepowerÍþв·ÀÓùÈí¼þĿ¼±éÀú·ì϶

CVE-2020-3550

¸ß

8.1

cisco-sa-ftdfmc-sft-mitm-tc8AzFs2
 
˼¿ÆFirepowerÖÎÀíÖÐÐÄÈí¼þºÍFirepowerÍþв·ÀÓùÈí¼þsftunnelͨ¹ýÉ¢Áзì϶

CVE-2020-3549

¸ß

8.1

cisco-sa-fmc-cacauthbyp-NCLGZm3Q
 
˼¿ÆFirepowerÖÎÀíÖÐÐÄÈí¼þͨÓýӼû¿¨Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶

CVE-2020-3410

¸ß

8.1

cisco-sa-ftdfmc-dos-NjYvDcLA
 
˼¿ÆFirepowerÖÎÀíÖÐÐÄÈí¼þ»Ø¾ø·þÎñ·ì϶

CVE-2020-3499

¸ß

8.6

cisco-sa-ftd-inline-dos-nXqUyEqM
 
˼¿ÆFirepowerÍþв·ÀÓùÈí¼þÄÚÁª¶Ô/±»¶¯Ä£Ê½»Ø¾ø·þÎñ·ì϶

CVE-2020-3577

¸ß

7.4

cisco-sa-ftd-container-esc-FmYqFBQV
 
˼¿ÆFirepowerÍþв·ÀÓùÈí¼þ¶àÊ·ýÈÝÆ÷תÒå·ì϶

CVE-2020-3514

¸ß

8.2

cisco-sa-ftd-snmp-dos-R8ENPbOs
 
˼¿ÆFirepowerÍþв·ÀÓùÈí¼þSNMP»Ø¾ø·þÎñ·ì϶

CVE-2020-3533

¸ß

8.6

cisco-sa-ftd-tcp-dos-GDcZDqAf
 
˼¿ÆFirepowerÍþв·ÀÓùÈí¼þTCP Flood»Ø¾ø·þÎñ·ì϶

CVE-2020-3563

¸ß

8.6

 

²¿ÃÅÑϳÁ·ì϶£º

Cisco FXOS FCM¿çÕ¾ÒªÇóαÔì·ì϶£¨CVE-2020-3456£©

´Ë·ì϶ÊÇCisco Firepower¿ÉÀ©´ó²Ù×÷ϵͳ£¨FXOS£©ÖÐCisco Firepower»úÏäÖÎÀíÆ÷£¨FCM£©ÖеÄÒ»¸ö·ì϶¡£ËüÊÇÓÉÓÚFCM½Ó¿ÚµÄCSRF±£»¤²»¼°¡£¹¥»÷Õß¹«¸æÓÕµ¼Ö¸±êÓû§µ¥»÷¶ñÒâÁ´½Ó£¬´Ó¶ø½øÐпçÕ¾µãÒªÇóαÔ죨CSRF£©¹¥»÷¡£

³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ·¢ËÍËÁÒâÒªÇó£¬ÕâЩҪÇóÖпÉÄÜÔ̺¬Î´¾­Ö¸±êÓû§ÊÚȨµÄ²Ù×÷¡£

Ó°ÏìÁìÓò£º

ÔÚnon-appliance modeϵÄASAÉ豸ÖеÄFirepower 2100ϵÁÐÉ豸

Firepower 4100ϵÁÐÉ豸

Firepower 9300ϵÁÐÉ豸

 

Cisco FMC»Ø¾ø·þÎñ·ì϶£¨CVE-2020-3499£©

´Ë·ì϶ÊÇ˼¿ÆFirepowerÖÎÀíÖÐÐÄ£¨FMC£©Ðí¿É·þÎñÖеķì϶£¬ËüÊÇÊÜÓ°ÏìµÄϵͳ¶Ô×ÊÔ´ÖµµÄ²»ÕýÈ·´¦Öõ¼ÖµÄ¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓô˷ì϶Ôì³É»Ø¾ø·þÎñ£¨DoS£©¡£

¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êϵͳ·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶¿ÉÄÜʹµÃÊÜÓ°ÏìµÄϵͳ²»ÔÙÏìÓ¦¡£

Ó°ÏìÁìÓò£º

ʹÓÃÏνÓÐí¿ÉµÄÈκÎCiscoÉ豸ÉÏÔËÐеÄCisco FMC¡£

 

Cisco FTD TCP Flood»Ø¾ø·þÎñ·ì϶£¨CVE-2020-3563£©

´Ë·ì϶ÊÇCisco FirepowerÍþв·ÀÓù£¨FTD£©µÄÊý¾Ý°ü´¦ÖÃÖ°ÄÜÖеķì϶£¬ËüÊÇÄÚ´æÖÎÀíЧÄܵÍÏÂÔì³ÉµÄ¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓô˷ì϶Ôì³É»Ø¾ø·þÎñ£¨DoS£©¡£

¹¥»÷Õßͨ¹ýÏòÊÜÓ°ÏìµÄÉ豸ÉϵÄÌØ¶¨¶Ë¿Ú·¢ËÍ´óÁ¿TCPÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£¹¥»÷Õ߳ɹ¦ÀûÓô˷ì϶¿ÉÄÜʹµÃϵͳÄÚ´æºÄ¾¡£¬µ¼ÖÂÉ豸³ÁмÓÔØ¡£

Ó°ÏìÁìÓò£º

FTD6.2.3¼°Ö®Ç°°æ±¾

FTD6.3.0 - FTD6.6.0

 

0x02 ´ëÖý¨Òé

²Î¿¼¹Ù·½°ä²¼µÄ½¨¸´½¨ÒéʵʱÉý¼¶ÖÁ°²È«°æ±¾¡£

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities

https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-74302&vs_f=Cisco%20Event%20

https://threatpost.com/cisco-dos-flaws-network-security-software/160414/

https://software.cisco.com/download/find


0x04 ¹¦·òÏß

2020-10-21  Cisco°ä²¼°²È«¹«¸æ

2020-10-22  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

 


 image.png