¡¾·ì϶¹«¸æ¡¿Cisco 1Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-01-210x00 ·ì϶¸ÅÊö
2021Äê01ÔÂ20ÈÕ£¬Cisco°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËCisco SD-WAN¡¢DNA CenterºÍSmart Software Manager SatelliteµÈ¶à¸ö²úÆ·ÖеĶà¸ö°²È«·ì϶¡£
0x01 ·ì϶ÏêÇé

Cisco SD-WANºÅÁî×¢Èë·ì϶£¨CVE-2021-1260¡¢CVE-2021-1261¡¢CVE-2021-1262¡¢CVE-2021-1263¡¢CVE-2021-1298ºÍCVE-2021-1299£©
Cisco SD-WAN²úÆ·ÖдæÔÚ¶à¸öºÅÁî×¢Èë·ì϶£¬ÆäÖУ¬CVE-2021-1260¡¢CVE-2021-1261¡¢CVE-2021-1262¡¢CVE-2021-1263ºÍCVE-2021-1298µÄCVSSÆÀ·ÖÔÚ5.3-7.8Ö®¼ä£¬³É¹¦ÀûÓÃÕâЩ·ì϶µÄ¹¥»÷ÕßÄܹ»¶ÔÊÜÓ°ÏìµÄÉ豸ִÐкÅÁî×¢Èë¹¥»÷£¬×îÖÕ¹¥»÷ÕßÄܹ»ÔÚÉ豸ÉÏÒÔrootȨÏÞÖ´ÐÐijЩ²Ù×÷¡£
ÖµÍ×ÌùÐĵÄÊÇCisco SD-WAN vManageºÅÁî×¢Èë·ì϶£¨CVE-2021-1299£©£¬Æä´æÔÚÓÚ»ùÓÚWebµÄÖÎÀí½çÃæÖУ¬ÊÇÓû§¶ÔÉ豸ģ°åÅäÖÃÌṩµÄÐÅÏ¢µÄÊäÈëÑéÖ¤²»ÕýÈ·Ôì³ÉµÄ£¬CVSSÆÀ·Ö9.9¡£
¹¥»÷ÕßÄܹ»Í¨¹ýÏòÉ豸ģ°åÅäÖÃÌá·´Ä¿ÒâÐÅÏ¢À´ÀûÓô˷ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÊÜÓ°ÏìϵͳµÄrootȨÏÞ¡£
Ó°ÏìÁìÓò
ÈôÊÇÔÚÔËÐÐÒ×ÊÜÓ°ÏìµÄCisco SD-WAN°æ±¾£¬ÔòÕâЩ·ì϶»áÓ°ÏìÒÔÏÂCisco²úÆ·£º
SD-WAN vBond OrchestratorÈí¼þ
SD-WAN vEdgeÔÆÂ·ÓÉÆ÷
SD-WAN vEdge·ÓÉÆ÷
SD-WAN vManageÈí¼þ
SD-WAN vSmart½ÚÔìÆ÷Èí¼þ
½¨¸´°æ±¾
Cisco SD-WAN°æ±¾ | ÕâЩ·ì϶µÄµÚÒ»¸ö¹Ì¶¨°æ±¾ | ´«µÝ¼¯ÖÐÃèÊöµÄËùÓзì϶µÄµÚÒ»¸ö¹Ì¶¨°æ±¾ |
ÔçÓÚ18.3 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
18.3 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
18.4 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
19.2 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
19.3 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
20.1 | 20.1.2 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
20.3 | 20.3.2 | 20.3.2 |
20.4 | 20.4.1 | 20.4.1 |
Cisco SD-WAN»º³åÇøÒç¶Âí½Å£¨CVE-2021-1300£©
¸Ã·ì϶ÊǶÔIPÁ÷Á¿µÄ²»ÕýÈ·´¦ÖÃÔì³ÉµÄ£¬ÆäCVSSÆÀ·Ö9.8¡£¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâIPÁ÷Á¿À´ÀûÓô˷ì϶£¬×îÖÕµ¼Ö»º³åÇøÒç³ö¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÒÔrootȨÏÞÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£
´Ë±í£¬Cisco SD-WANµÄNETCONF×ÓϵͳÖл¹´æÔÚÁíÒ»¸ö»º³åÇøÒç¶Âí½Å£¨CVE-2021-1301£©£¬¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓô˷ì϶ÔÚÊÜÓ°ÏìµÄÉ豸»òϵͳÉϵ¼Ö»ؾø·þÎñ£¬ÆäCVSSÆÀ·Ö6.5¡£
Ó°ÏìÁìÓò
ÈôÊÇÔÚÔËÐÐÒ×ÊÜÓ°ÏìµÄCisco SD-WAN°æ±¾£¬ÔòÕâЩ·ì϶»áÓ°ÏìÒÔÏÂCisco²úÆ·£º
IOS XE SD-WANÈí¼þ
SD-WAN vBond OrchestratorÈí¼þ
SD-WAN vEdgeÔÆÂ·ÓÉÆ÷
SD-WAN vEdge·ÓÉÆ÷
SD-WAN vManageÈí¼þ
SD-WAN vSmart½ÚÔìÆ÷Èí¼þ
½¨¸´°æ±¾
SD-WAN
Cisco SD-WAN°æ±¾ | ·ì϶µÄµÚÒ»¸ö¹Ì¶¨°æ±¾ | ËùÓзì϶µÄµÚÒ»¸ö¹Ì¶¨°æ±¾ |
ÔçÓÚ18.3 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
18.3 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
18.4 | 18.4.5 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
19.2 | 19.2.2 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
19.3 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
20.1 | 20.1.1 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
20.3 | 20.3.1 | 20.3.2 |
20.4 | 20.4.1 | 20.4.1 |
IOS XE SD-WAN
Cisco IOS XE SD-WAN°æ±¾ | ·ì϶µÄµÚÒ»¸ö¹Ì¶¨°æ±¾ | ËùÓзì϶µÄµÚÒ»¸ö¹Ì¶¨°æ±¾ |
16.9 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
16.10 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
16.11 | Ǩáãµ½¹Ì¶¨°æ±¾¡£ | Ǩáãµ½¹Ì¶¨°æ±¾¡£ |
16.12 | 16.12.4 | 16.12.4 |
IOS XE
Cisco IOS XEͨÓð汾 | ·ì϶µÄµÚÒ»¸ö¹Ì¶¨°æ±¾ | ËùÓзì϶µÄµÚÒ»¸ö¹Ì¶¨°æ±¾ |
17.2 | 17.2.1 | 17.2.2 |
17.3 | 17.3.1 | 17.3.1 |
17.4 | 17.4.1 | 17.4.1 |
Cisco DNA Center Command Runner ºÅÁî×¢Èë·ì϶£¨CVE-2021-1264£©
¸Ã·ì϶´æÔÚÓÚCisco DNA CenterµÄCommand Runner¹¤¾ßÖУ¬ÆäCVSSÆÀ·Ö9.6¡£
¸Ã·ì϶ÊÇCommand Runner¹¤¾ßÊäÈëÑéÖ¤²»¼°µ¼Öµġ£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚºÅÁîÖ´ÐÐÆÚ¼äʹÓöñÒâÊäÈë»òŲÓúÅÁîÔËÐз¨Ê½APIÀ´ÀûÓô˷ì϶£¬×îÖÕ¿ÉÄÜÔÚCisco DNA CenterÖÎÀíµÄÉ豸ÉÏÖ´ÐÐËÁÒâCLIºÅÁî¡£
Ó°ÏìÁìÓò
Cisco DNA Center Software < 1.3.1.0
½¨¸´°æ±¾
Cisco DNA Center Software >= 1.3.1.0
Cisco Smart Software Manager Satellite Web UIºÅÁî×¢Èë·ì϶£¨CVE-2021-1138¡¢CVE-2021-1140ºÍCVE-2021-1142£©
Õâ3¸ö·ì϶¶¼ÊÇCiscoÖÇÄÜÈí¼þÖÎÀíÆ÷SatelliteµÄWeb UIÖеĺÅÁî×¢Èë·ì϶£¬ËüÃǶ¼ÊÇÊäÈëÑéÖ¤²»¼°µ¼Öµģ¬ÆäCVSSÆÀ·Ö9.8¡£¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâHTTPÒªÇóÀ´ÀûÓÃÕâЩ·ì϶£¬³É¹¦ÀûÓÃÕâЩ·ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚϵͳÉÏÔËÐÐËÁÒâºÅÁî¡£
´Ë±í£¬CiscoÖÇÄÜÈí¼þÖÎÀíÆ÷SatelliteµÄWeb UIÖл¹´æÔÚÆäËü2¸öÊäÈëÑéÖ¤²»¼°µ¼ÖµĺÅÁî×¢Èë·ì϶£¨CVE-2021-1139ºÍCVE-2021-1141£©£¬ÆäCVSSÆÀ·Ö¾ùΪ8.8¡£¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâHTTPÒªÇóÀ´ÀûÓÃËüÃÇ£¬×îÖÕÄܹ»ÒÔrootÓû§µÄÉí·ÝÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐËÁÒâºÅÁî¡£
Ó°ÏìÁìÓò
Cisco Smart Software Manager Satellite <= 5.1.0
½¨¸´°æ±¾
Cisco Smart Software Manager On-Prem >= 6.3.0
×¢£ºÔÚ6.3.0°æ±¾ÖУ¬Cisco Smart Software Manager Satellite±»³Á¶¨ÃûΪCisco Smart Software Manager On-Prem¡£
0x02 ´ëÖý¨Òé
½¨Òé²Î¿¼Cisco¹Ù·½°ä²¼µÄ°²È«²¼¸æÉý¼¶ÖÁ×îа汾¡£
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-cmdinjm-9QMSmgcn
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-pre-auth-bugs-in-sd-wan-cloud-license-manager/
0x04 ¹¦·òÏß
2021-01-20 Cisco°ä²¼°²È«²¼¸æ
2021-01-21 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ