Cisco | 11Ô¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-11-190x00 ·ì϶¸ÅÊö
2020Äê11ÔÂ18ÈÕ£¬Cisco°ä²¼°²È«¹«¸æ£¬Æä¶à¸ö²úÆ·ºÍ×é¼þÖдæÔÚ°²È«·ì϶¡£±¾´Î°ä²¼µÄ°²È«·ì϶¹²¼Æ19¸ö£¬ÆäÖÐÓÐ3¸ö·ì϶ÆÀ¼¶ÎªÑϳÁ£¬3¸ö·ì϶ÆÀ¼¶Îª¸ßΣ£¬13¸ö·ì϶ÆÀ¼¶ÎªÖÐΣ¡£
0x01 ·ì϶ÏêÇé
±¾´Î°ä²¼µÄ°²È«·ì϶ÈçÏ£º
·ìϼûû³Æ | ÆÀ¼¶ | CVE ID | °ä²¼¹¦·ò | °æ±¾ |
Cisco IMCÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ | CVE-2020-3470 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco DNA Spaces ConnectorºÅÁî×¢Èë·ì϶ | ÑϳÁ | CVE-2020-3586 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND REST APIÑéÖ¤ÈÆ¹ý·ì϶ | ÑϳÁ | CVE-2020-3531 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco °²È«WebÉ豸ȨÏÞÉý¼¶·ì϶ | ¸ßΣ | CVE-2020-3367 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND SOAP APIÊÚÈ¨ÈÆ¹ý·ì϶ | ¸ßΣ | CVE-2020-26072 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND¶ÌȱAPIÉí·ÝÑéÖ¤·ì϶ | ¸ßΣ | CVE-2020-3392 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco Webex Meetings API¿çÕ¾¾ç±¾·ì϶ | ÖÐΣ | CVE-2020-27126 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco Webex MeetingsºÍCisco Webex Meetings ServerÐÅϢй¶·ì϶ | ÖÐΣ | CVE-2020-3441 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco Webex MeetingsºÍCisco Webex Meetings Serverδ¾ÊÚȨµÄÒôƵÐÅϢй¶·ì϶ | ÖÐΣ | CVE-2020-3471 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco Webex MeetingsºÍCisco Webex Meetings Server GhostÏνӷì϶ | ÖÐΣ | CVE-2020-3419 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco ÍøÕæCEÈí¼þºÍRoomOSÈí¼þδ¾ÊÚȨµÄÁîÅÆÌìÉú·ì϶ | ÖÐΣ | CVE-2020-26068 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND¿çÕ¾µã¾ç±¾·ì϶ | ÖÐΣ | CVE-2020-26081 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FNDÓò½Ó¼û½ÚÔì²»µ±·ì϶ | ÖÐΣ | CVE-2020-26080 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FNDÐÅϢй¶·ì϶ | ÖÐΣ | CVE-2020-26076 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND REST APIÊäÈëÑéÖ¤·ì϶²»¼° | ÖÐΣ | CVE-2020-26075 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FNDδÊܱ£»¤µÄÍ´´¦´æ´¢·ì϶ | ÖÐΣ | CVE-2020-26079 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FNDÎļþ¸²¸Ç·ì϶ | ÖÐΣ | CVE-2020-26078 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco IoT FND½Ó¼û½ÚÔì²»µ±·ì϶ | ÖÐΣ | CVE-2020-26077 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
Cisco ExpresswayÐÅϢй¶·ì϶ | ÖÐΣ | CVE-2020-3482 | 2020Äê11ÔÂ18ÈÕ | 1.0 |
ÑϳÁ·ì϶ÈçÏ£º
Cisco IMCÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-3470£©
¸Ã·ì϶ÊǶÔÓû§µÄÊäÈëÑéÖ¤ÃýÎóµ¼Öµģ¬ÆäCVSSÆÀ·Ö9.8¡£¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËÍ¿ÉÄܵ¼Ö»º³åÇøÒç³öµÄ¶ñÒâHTTPÒªÇóµ½ÊÜÓ°ÏìϵͳÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÖÎÀíԱȨÏÞÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£
Ó°ÏìÁìÓò£º
5000 Series Enterprise Network Compute System (ENCS)ƽ̨
Standalone mode쵀UCS C-Series Rack Servers
UCS E-Series Servers
Standalone mode쵀UCS S-Series Servers
»º½â´ëÊ©£º
½ûÓÃCisco IMC WebÖÎÀí½çÃæ¡£ÒÔÏÂÊÇUCS C-Series ServerÉϵÄÅäÖÃʾÀý£º
xxxxxx-bmc# scope http
xxxxxx-bmc /http # set enabled no
SSH is in enabled state. Disabling HTTP service
xxxxxx-bmc /http *# commit
xxxxxx-bmc /http # show detail
HTTP Settings:
HTTP Port: 80
HTTPS Port: 443
Timeout: 1800
Max Sessions: 4
Active Sessions: 0
Enabled: no
HTTP Redirected: yes
xxxxxx-bmc /http # exit
°ÑÎÈ£º½«¡°enabled¡±ÉèÖÃΪ¡°no¡±½«¶Ï¿ªËùÓÐÔËÐÐÖеÄHTTPÏνӣ¬²¢ÎÞ·¨Í¨¹ýWebUIµÇ¼¡£
ÏêÇéÁ´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-api-rce-UXwpeDHd
Cisco DNA Spaces ConnectorºÅÁî×¢Èë·ì϶£¨CVE-2020-3586£©
¸Ã·ì϶ÊÇ»ùÓÚWebµÄÖÎÀí½çÃæ¶ÔÓû§ÊäÈëÑéÖ¤²»¼°Ôì³ÉµÄ£¬ÆäCVSSÆÀ·Ö9.4¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏò»ùÓÚWebµÄÖÎÀí½çÃæ·¢ËͶñÒâHTTPÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÔڵײã²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£
Ó°ÏìÁìÓò£º
Cisco DNA Spaces Connector 2.2¼°Ö®Ç°°æ±¾¡£
½¨¸´½¨Ò飺
¸üÐÂÖÁCisco DNA Spaces Connector 2.3¼°¸ü¸ß°æ±¾¡£
ÏêÇéÁ´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dna-cmd-injection-rrAYzOwc
Cisco IoT FND REST APIÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-3531£©
¸Ã·ì϶ÊÇÎÞ·¨ÕýÈ·ÑéÖ¤REST APIŲÓõ¼Öµģ¬ÆäCVSSÆÀ·Ö9.8¡£¹¥»÷ÕßÄܹ»Í¨¹ý»ñÈ¡¿çÕ¾µãÒªÇóαÔ죨CSRF£©ÁîÅÆ²¢½áºÏREST APIÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄܽӼûÊÜÓ°ÏìÉ豸µÄÊý¾Ý¿â²¢¶ÁÈ¡¡¢¸ü¸Ä»òɾ³ýÐÅÏ¢¡£
Ó°ÏìÁìÓò£º
Cisco IoT FND 4.6.1֮ǰµÄ°æ±¾¡£
½¨¸´½¨Ò飺
¸üÐÂÖÁCisco IoT FND 4.6.1¼°¸ü¸ß°æ±¾¡£
ÏêÇéÁ´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-FND-BCK-GHkPNZ5F
0x02 ´ëÖý¨Òé
ĿǰCiscoÒѾ°ä²¼ÁËÓйظüУ¬½¨Òé²Î¿¼¹Ù·½²¼¸æÊµÊ±½¨¸´¡£
ÏÂÔØµØÖ·£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3531
0x04 ¹¦·òÏß
2020-11-18 Cisco°ä²¼°²È«²¼¸æ
2020-11-19 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ