Cisco IOS XEÈí¼þWeb UI¿çÕ¾µãÇëÇóαÔìÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-14

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1904£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚCisco IOS XEÈí¼þ°æ±¾ÇÒÆôÓÃÁËHTTP Server¹¦Ð§µÄCisco×°±¸¡£¡£¡£¡£


Îó²î¸ÅÊö


Cisco IOS XEÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ΪÆäÍøÂç×°±¸¿ª·¢µÄ²Ù×÷ϵͳ¡£¡£¡£¡£Cisco IOS XE SoftwareÖеÄWeb UI±£´æCSRFÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶ÔÊÜÓ°ÏìµÄϵͳ¾ÙÐпçÕ¾µãÇëÇóαÔ죨CSRF£©¹¥»÷¡£¡£¡£¡£


¸ÃÎó²îÊÇÓÉÓÚÊÜÓ°ÏìÉè±¹ØÁ¬ÄWeb UIµÄCSRF±£»£» £»£»¤È±·¦¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý˵·þ½Ó¿ÚµÄÓû§×ñÕÕ¶ñÒâÁ´½ÓÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÓÃÊÜÓ°ÏìÓû§µÄȨÏÞ¼¶±ðÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£¡£ÈôÊÇÓû§¾ßÓÐÖÎÀíȨÏÞ£¬£¬£¬£¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔ¸ü¸ÄÉèÖ㬣¬£¬£¬£¬£¬£¬Ö´ÐÐÏÂÁî»òÖØÐ¼ÓÔØÊÜÓ°ÏìµÄ×°±¸¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£


ÐÞ¸´½¨Òé


½ûÓÃHTTP Server¹¦Ð§¿ÉÏû³ý´ËÎó²îµÄ¹¥»÷ǰÑÔ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÊÇÊʵ±µÄ»º½â²½·¥£¬£¬£¬£¬£¬£¬£¬Ö±µ½¿ÉÒÔÉý¼¶ÊÜÓ°ÏìµÄ×°±¸¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190612-iosxe-csrf