˼¿ÆÐÞ¸´ÑÏÖØµÄIOxÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-27Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12648£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
˼¿Æ1000ϵÁÐConnected Grid Routers (CGR 1000)ºÍ˼¿Æ800ϵÁÐIndustrial Integrated Services Routers£¬£¬£¬×°ÖÃÁ˿ͻ§»ú²Ù×÷ϵͳµÄIOS SoftwareÒ×Êܹ¥»÷°æ±¾
Îó²î¸ÅÊö
˼¿ÆÐû²¼Çå¾²¸üУ¬£¬£¬½â¾öÁË˼¿ÆIOS Software IOxÓ¦ÓóÌÐòÇéÐÎÖеÄÒ»¸öÑÏÖØÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿Éµ¼ÖÂÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔ¸ùÓû§Éí·Ý»á¼û¿Í»§»ú²Ù×÷ϵͳ (Guest OS)¡£¡£¡£¡£¡£¡£¡£¡£
µ±µÍȨÏÞÓû§ÇëÇó»á¼û±¾Ó¦±»ÏÞÖÆÎªÖÎÀíÔ±ÕË»§²Å»ª»á¼ûµÄ¿Í»§»ú²Ù×÷ϵͳʱ£¬£¬£¬»áÒý·¢¹ýʧµÄ»ùÓÚ½ÇÉ«µÄ»á¼û¿ØÖÆ£¨RBAC£©ÆÀ¹À¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹ÓõÍȨÏÞÓû§Æ¾Ö¤ÑéÖ¤¿Í»§»ú²Ù×÷ϵͳ£¬£¬£¬´Ó¶øÊ¹ÓøÃÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
¿Í»§»ú²Ù×÷ϵͳÊǰüÀ¨Hypervisor¡¢IOSºÍGuest OSÓ³ÏñµÄÀ¦°óIOSÓ³ÏñµÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£¡£¡£Í¨¹ý˼¿ÆIOS SoftwareÓ³Ïñ°üÖ´ÐгõʼװÖûòÈí¼þÉý¼¶µÄ¿Í»§½«ÔÚÈí¼þÓ³Ïñ°ü×°ÖÃÀú³ÌÖÐ×Ô¶¯×°Öÿͻ§»ú²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£¡£
ÖÎÀíÔ±¿ÉÔÚ×°±¸CLIÖÐʹÓÃÏÂÁîshow iox host list detailÉó²é×°±¸ÉÏÊÇ·ñÆôÓÃÁ˿ͻ§»ú²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£¡£Ë¼¿ÆÔÚÇ徲ͨ¸æÖÐÌṩÁËÈçÏÂʾÀý£¬£¬£¬ËµÃ÷ÎúÆôÓÃÁ˿ͻ§»ú²Ù×÷ϵͳµÄÏÂÁîÊä³öЧ¹û£º
±ðµÄ£¬£¬£¬Ë¼¿ÆÐû²¼Á˰ëÄê¶ÈCisco IOSºÍIOS XEÈí¼þÇ徲ͨ¸æ£¨²¹¶¡ÈÕ£©£ºhttps://tools.cisco.com/security/center/viewErp.x?alertId=ERP-72547£¬£¬£¬ÆäÖаüÀ¨ËµÃ÷Îú13¸öÇ徲ȱÏݵÄ12¸ö˼¿ÆÇ徲ͨ¸æ£¬£¬£¬ËùÓеÄÕâ13¸öÎó²î¾ùδ¸ßΣÎó²î£¬£¬£¬CVSSÆÀ·ÖΪ7.5µ½9.9¡£¡£¡£¡£¡£¡£¡£¡£±¾ÎÄÌáµ½µÄÎó²îÒ²ÊÇÆäÖеÄ×é³É²¿·Ö¡£¡£¡£¡£¡£¡£¡£¡£Ë¼¿ÆÒÑÐû²¼½â¾öËùÓÐÕâЩÎó²îµÄÇå¾²¸üУ¬£¬£¬ÒÔ×èÖ¹¹¥»÷ÕßʹÓÃδÐÞ¸´×°±¸¡°»ñȡԽȨ»á¼ûȨÏÞ¡¢¾ÙÐÐÏÂÁî×¢Èë¹¥»÷»òÒý·¢¾Ü¾øÐ§ÀÍÌõ¼þ¡±¡£¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth ¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth


¾©¹«Íø°²±¸11010802024551ºÅ