˼¿ÆÐÞ¸´ÑÏÖØµÄIOxÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-27

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12648£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬£¬£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


˼¿Æ1000ϵÁÐConnected Grid Routers (CGR 1000)ºÍ˼¿Æ800ϵÁÐIndustrial Integrated Services Routers£¬£¬£¬ £¬£¬×°ÖÃÁ˿ͻ§»ú²Ù×÷ϵͳµÄIOS SoftwareÒ×Êܹ¥»÷°æ±¾


Îó²î¸ÅÊö


˼¿ÆÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬½â¾öÁË˼¿ÆIOS Software IOxÓ¦ÓóÌÐòÇéÐÎÖеÄÒ»¸öÑÏÖØÎó²î¡£¡£¡£¸ÃÎó²î¿Éµ¼ÖÂÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔ¸ùÓû§Éí·Ý»á¼û¿Í»§»ú²Ù×÷ϵͳ (Guest OS)¡£¡£¡£


µ±µÍȨÏÞÓû§ÇëÇó»á¼û±¾Ó¦±»ÏÞÖÆÎªÖÎÀíÔ±ÕË»§²Å»ª»á¼ûµÄ¿Í»§»ú²Ù×÷ϵͳʱ£¬£¬£¬ £¬£¬»áÒý·¢¹ýʧµÄ»ùÓÚ½ÇÉ«µÄ»á¼û¿ØÖÆ£¨RBAC£©ÆÀ¹À¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹ÓõÍȨÏÞÓû§Æ¾Ö¤ÑéÖ¤¿Í»§»ú²Ù×÷ϵͳ£¬£¬£¬ £¬£¬´Ó¶øÊ¹ÓøÃÎó²î¡£¡£¡£


¿Í»§»ú²Ù×÷ϵͳÊǰüÀ¨Hypervisor¡¢IOSºÍGuest OSÓ³ÏñµÄÀ¦°óIOSÓ³ÏñµÄÒ»²¿·Ö¡£¡£¡£Í¨¹ý˼¿ÆIOS SoftwareÓ³Ïñ°üÖ´ÐгõʼװÖûòÈí¼þÉý¼¶µÄ¿Í»§½«ÔÚÈí¼þÓ³Ïñ°ü×°ÖÃÀú³ÌÖÐ×Ô¶¯×°Öÿͻ§»ú²Ù×÷ϵͳ¡£¡£¡£


ÖÎÀíÔ±¿ÉÔÚ×°±¸CLIÖÐʹÓÃÏÂÁîshow iox host list detailÉó²é×°±¸ÉÏÊÇ·ñÆôÓÃÁ˿ͻ§»ú²Ù×÷ϵͳ¡£¡£¡£Ë¼¿ÆÔÚÇ徲ͨ¸æÖÐÌṩÁËÈçÏÂʾÀý£¬£¬£¬ £¬£¬ËµÃ÷ÎúÆôÓÃÁ˿ͻ§»ú²Ù×÷ϵͳµÄÏÂÁîÊä³öЧ¹û£º


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



±ðµÄ£¬£¬£¬ £¬£¬Ë¼¿ÆÐû²¼Á˰ëÄê¶ÈCisco IOSºÍIOS XEÈí¼þÇ徲ͨ¸æ£¨²¹¶¡ÈÕ£©£ºhttps://tools.cisco.com/security/center/viewErp.x?alertId=ERP-72547£¬£¬£¬ £¬£¬ÆäÖаüÀ¨ËµÃ÷Îú13¸öÇ徲ȱÏݵÄ12¸ö˼¿ÆÇ徲ͨ¸æ£¬£¬£¬ £¬£¬ËùÓеÄÕâ13¸öÎó²î¾ùδ¸ßΣÎó²î£¬£¬£¬ £¬£¬CVSSÆÀ·ÖΪ7.5µ½9.9¡£¡£¡£±¾ÎÄÌáµ½µÄÎó²îÒ²ÊÇÆäÖеÄ×é³É²¿·Ö¡£¡£¡£Ë¼¿ÆÒÑÐû²¼½â¾öËùÓÐÕâЩÎó²îµÄÇå¾²¸üУ¬£¬£¬ £¬£¬ÒÔ×èÖ¹¹¥»÷ÕßʹÓÃδÐÞ¸´×°±¸¡°»ñȡԽȨ»á¼ûȨÏÞ¡¢¾ÙÐÐÏÂÁî×¢Èë¹¥»÷»òÒý·¢¾Ü¾øÐ§ÀÍÌõ¼þ¡±¡£¡£¡£


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬ £¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth ¡£¡£¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth