Cisco | Security Manager¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-11-17

0x00 ·ì϶¸ÅÊö

2020Äê11ÔÂ16ÈÕ£¬Cisco°ä²¼°²È«¹«¸æ£¬Security ManagerÖдæÔÚ¶à¸ö°²È«·ì϶¡£·ì϶׷×ÙΪCVE-2020-27125¡¢CVE-2020-27130ºÍCVE-2020-27131¡£

 

0x01 ·ì϶ÏêÇé

 

image.png

Cisco Security ManagerΪCisco°²È«ÖÎÀíÆ÷£¬Ëü¿É½«Õ½ÊõÅäÖù¤×÷ºÍÕë¶ÔCisco°²È«ÊýÊðµÄ½ÚÔì´ëÊ©½øÐм¯Öд¦Ö㬴Ӷø¸ßЧµØÖÎÀíÆóÒµ°²È«¡£

±¾´Î°ä²¼µÄ·ì϶ÏêÇéÈçÏ£º

 

²úÆ·

CVE   ID

·ìϼûû³Æ

ÆÀ·Ö

ÑϳÁˮƽ

Cisco   Security Manager

CVE-2020-27125

Cisco Security   Manager¾²Ì¬Ö¤Êé·ì϶

7.4

¸ßΣ

CVE-2020-27130

Cisco Security   Managerõè¾¶±éÀú·ì϶

9.1

ÑϳÁ

CVE-2020-27131

Cisco Security   Manager Java·´ÐòÁл¯·ì϶

8.1

¸ßΣ

 

Ó°ÏìÁìÓò£º

Cisco Security Manager 4.21¼°Ö®Ç°°æ±¾¡£

 

Cisco Security Manager¾²Ì¬Ö¤Êé·ì϶£¨CVE-2020-27125£©

¸Ã·ì϶ÊǾ²Ì¬Í´´¦Ã»ÓÐÌṩ×ã¹»µÄ± £»¤Ôì³ÉµÄ£¬¹¥»÷ÕßÄܹ»Í¨¹ý²é¿´Ô´´úÂëÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»²é¿´¾²Ì¬Í´´¦µÈÃô¸ÐÐÅÏ¢£¬²¢ÀûÓÃÍ´´¦½øÐй¥»÷¡£

·ì϶ÏêÇéÈçÏ£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csm-rce-8gjUz9fW

 

Cisco Security Managerõè¾¶±éÀú·ì϶£¨CVE-2020-27130£©

¸Ã·ì϶ÊÇÉ豸¶ÔÒªÇóÖеÄĿ¼±éÀú×Ö·ûÐòÁеÄÑéÖ¤²»ÕýÈ·Ôì³ÉµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶¿ÉÄÜʹ¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸¸ßµÍÔØËÁÒâÎļþ¡£

·ì϶ÏêÇéÈçÏ£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csm-path-trav-NgeRnqgR

 

Cisco Security Manager Java·´ÐòÁл¯·ì϶£¨CVE-2020-27131£©

Cisco Security ManagerʹÓõÄJava·´ÐòÁл¯Ö°ÄÜÖдæÔÚ¶à¸ö°²È«·ì϶¡£ÕâЩ·ì϶ʹµÃÓû§ÌṩµÄÄÚÈݱ»²»°²È«µØ·´ÐòÁл¯¡£¹¥»÷ÕßÄܹ»Í¨¹ý½«¶ñÒâµÄÐòÁл¯Java¶ÔÏó·¢Ë͸øÊÜÓ°ÏìµÄϵͳÉϵÄÌØ¶¨ÕìÌýÆ÷À´ÀûÓÃÕâЩ·ì϶¡£³É¹¦ÀûÓô˷ì϶¿ÉÄÜʹ¹¥»÷ÕßÔÚÖ¸±êWindowsÖ÷»úÉÏʹÓÃNT AUTHORITY\SYSTEM£¨ÄÚÖÃϵͳÖÎÀíÕË»§£©È¨ÏÞÔÚÉ豸ÉÏÖ´ÐÐËÁÒâºÅÁî¡£

·ì϶ÏêÇéÈçÏ£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csm-java-rce-mWJEedcD?

 

0x02 ´ëÖý¨Òé

ĿǰCiscoÒÑÔÚCisco Security Manager 4.22Öн¨¸´ÁËCVE-2020-27125ºÍCVE-2020-27130£¬½¨Òéʵʱ¸üС£

Cisco´òËãÔÚCisco Security Manager 4.23Öн¨¸´CVE-2020-27131¼°ÆäËüJava·´ÐòÁл¯Ö°ÄÜÖеķì϶¡£

ÏÂÔØµØÖ·£º

https://software.cisco.com/download/find

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/publicationListing.x

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27131

 

0x04 ¹¦·òÏß

2020-11-16  Cisco°ä²¼°²È«²¼¸æ

2020-11-17  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/


 

image.png