˼¿ÆÎå¸ö¸ßΣÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-06Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-3120£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3119£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3118£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3111£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3110£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
·ÓÉÆ÷£º
ASR 9000ϵÁоۺÏЧÀÍ·ÓÉÆ÷
ÔËÓªÉÌ·ÓÉϵͳ£¨CRS£©
Firepower 1000ϵÁÐ
Firepower 2100ϵÁÐ
Firepower 4100ϵÁÐ
Firepower 9300Çå¾²×°±¸
IOS XRv 9000·ÓÉÆ÷
ÔËÐÐ˼¿ÆIOS XRµÄ°×ºÐ·ÓÉÆ÷
½»Á÷»ú£º
Nexus 1000ÐéÄâ±ßÑØ
Nexus 1000V½»Á÷»ú
Nexus 3000ϵÁн»Á÷»ú
Nexus 5500ϵÁн»Á÷»ú
Nexus 5600ϵÁн»Á÷»ú
Nexus 6000ϵÁн»Á÷»ú
Nexus 7000ϵÁн»Á÷»ú
Nexus 9000ϵÁйâÏ˽»Á÷»ú
MDS 9000ϵÁжà²ã½»Á÷»ú
ÍøÂçÈÚºÏϵͳ£¨NCS£©1000ϵÁÐ
ÍøÂçÈÚºÏϵͳ£¨NCS£©5000ϵÁÐ
ÍøÂçÈÚºÏϵͳ£¨NCS£©540·ÓÉÆ÷
ÍøÂçÈÚºÏϵͳ£¨NCS£©5500ϵÁÐ
ÍøÂçÈÚºÏϵͳ£¨NCS£©560·ÓÉÆ÷
ÍøÂçÈÚºÏϵͳ£¨NCS£©6000ϵÁÐ
UCS 6200ϵÁн»Á÷¾ØÕó»¥Áª
UCS 6300ϵÁн»Á÷¾ØÕó»¥Áª
UCS 6400ϵÁн»Á÷¾ØÕó»¥Áª
IPµç»°»ú£º
IP¾Û»áµç»°»ú7832
IP¾Û»áµç»°»ú8832
IPµç»°»ú6800ϵÁÐ
IPµç»°»ú7800ϵÁÐ
IPµç»°»ú8800ϵÁÐ
IPµç»°»ú8851ϵÁÐ
ͳһIP¾Û»áµç»°»ú8831
ÎÞÏßIPµç»°»ú8821
ÎÞÏßIPµç»°»ú8821-EX
IPÉãÏñÍ·£º
ÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñÍ·
Îó²î¸ÅÊö
Çå¾²Ñо¿Ô±Åû¶ÁËÆÕ±é°²ÅÅÓÚ˼¿Æ·¢Ã÷ÐÒé (CDP) ÖеÄÎå¸ö¸ßΣÎó²î¡£¡£¡£ÕâЩÎó²îÊÇÓÉÎïÁªÍøÍøÂçÇå¾²¹«Ë¾ Armis ·¢Ã÷µÄ£¬£¬£¬£¬£¬£¬±»ÃüÃûΪ¡°CDPwn¡±£¬£¬£¬£¬£¬£¬Ó°ÏìµÄÊÇ˼¿Æ×¨ÓÐÐÒé CDP¡£¡£¡£¸ÃÐÒé¿ÉÔÊÐí˼¿Æ×°±¸Í¨¹ý¶à²¥ÐÂÎÅÏ໥·ÖÏíÐÂÎÅ£¬£¬£¬£¬£¬£¬ËüʵÏÖÓÚ´ó×ÚÖ÷Á÷˼¿Æ²úÆ·ÖУ¬£¬£¬£¬£¬£¬×Ô20ÊÀ¼Í90ÄêÔÂÆð±»Ê¹Óᣡ£¡£¸ÃÐÒ鲢δ¹ãΪÈËÖª£¬£¬£¬£¬£¬£¬ÓÉÓÚËü²¢Î´Ì»Â¶ÔÚ»¥ÁªÍøÉϲ¢ÇÒ½öÔÚÍâµØÍøÂçÖÐÔËÐС£¡£¡£
ҪʹÓÃÕâЩÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏÈÐèÒªÔÚÍâµØÍøÂçÖÐפ×ã¡£¡£¡£Èë¿Úµã¿ÉÒÔÊÇÈκÎÊÂÎïÈçÎïÁªÍø×°±¸¡£¡£¡£ºÚ¿ÍÄܹ»Ê¹ÓÃÕâ¸öÈë¿Ú×°±¸²¥±¨¶ñÒâ CDP ÐÅÏ¢²¢½ÓÊÜ˼¿Æ×°±¸¡£¡£¡£ÕâÀïµÄÖ÷ҪĿµÄÊÇ˼¿ÆÂ·ÓÉÆ÷¡¢½»Á÷»úºÍ·À»ðǽ£¬£¬£¬£¬£¬£¬ËüÃdzÖÓÐ˼¿ÆÕû¸öÍøÂçµÄÃÜÔ¿£¬£¬£¬£¬£¬£¬Ä¬ÈÏÆôÓà CDP¡£¡£¡£
ÕâЩ CDPwn Îó²îËäÈ»ÎÞ·¨ÓÃÓÚ´Ó»¥ÁªÍøÔ¶³ÌÆÆ½â×éÖ¯»ú¹¹µÄÇå¾²ÍøÂ磬£¬£¬£¬£¬£¬Ëü¿É±»ÓÃÓÚÌáÉý³õʼ»á¼ûȨÏÞ¡¢½ÓÊÜÒªº¦µãÈç·ÓÉÆ÷ºÍ½»Á÷»úÀ´É¾³ýÍøÂç·Ö¶Î²¢ÔÚ¹«Ë¾ÍøÂçºáÏòÒÆ¶¯ÒÔ¹¥»÷ÆäËü×°±¸¡£¡£¡£CDP »¹ÔÚÆäËü˼¿Æ²úÆ·Öн»¸¶²¢Ä¬ÈÏÆôÓÃÈç VoIP µç»°ºÍ IP ÉãÏñÍ·¡£¡£¡£CDPwn ¹¥»÷Ò²¿É±»ÓÃÓÚ¹¥»÷ÕâЩװ±¸¡£¡£¡£¹¥»÷Õß»¹Äܹ»Ê¹Óà CDPwn ½ÓÊÜÒ×Êܹ¥»÷µÄ×°±¸Èçµç»°ºÍÇå¾²ÉãÏñÍ·¡¢×°ÖöñÒâÈí¼þ¡¢ÌáÈ¡Êý¾Ý»òÉõÖÁÇÔÌýͨ»°ºÍÊÓÆµÄÚÈÝ¡£¡£¡£
CDPwnÓÉÎå¸öÎó²î×é³É£¬£¬£¬£¬£¬£¬°üÀ¨ËĸöÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î£¬£¬£¬£¬£¬£¬µÚÎå¸öÎó²îÊǾܾøÐ§ÀÍ£¨DoS£©Îó²î£¬£¬£¬£¬£¬£¬¸ÅÊöÈçÏ£º
˼¿ÆNX-OSÈí¼þ¡ªË¼¿Æ·¢Ã÷ÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3119£©
¸ÃÎó²îÊÇÒ»¸ö¿ÍÕ»Òç³öÎó²î£¬£¬£¬£¬£¬£¬±£´æÓÚIOS XRʵÑéµÄCDPÖÐÆÊÎöº¬ÓжÔÒÔÌ«Íø¹©µç£¨PoE£©ÇëÇó×ֶξÙÐÐÐÉ̵ÄÐÅÏ¢µÄCDPÊý¾Ý°üÕâ¸ö»·½Ú¡£¡£¡£º¬ÓÐÌ«¶àPoEÇëÇó×ֶεÄCDPÊý¾Ý°ü½«ÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏ´¥·¢¸ÃÎó²î¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕýµ±µÄCDPÊý¾Ý°üÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬Ö»ÒªÕýµ±Êý¾Ý°üµÄ¹¦Âʼ¶±ð¸ßÓÚ½»Á÷»ú±¾¸ÃÊÕµ½µÄ×ܹ¦Âʼ¶±ð£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¿ÍÕ»Òç³ö¡£¡£¡£Í¨¹ýʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÖÜÈ«¿ØÖƽ»Á÷»ú¼°ÆäÈÏÕæµÄÄDz¿·ÖÍøÂç»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬´Ó¶øÆÆËð·Ö¶Î£¬£¬£¬£¬£¬£¬²¢ÔÊÐíÔÚVLANÖ®¼ä¾ÙÐÐÌøÔ¾¡£¡£¡£
˼¿ÆIOS-XR¡ªCDPÃûÌÃ×Ö·û´®Îó²î£¨CVE-2020-3118£©
¸ÃÎó²îÊÇÒ»ÖÖÃûÌÃ×Ö·û´®Îó²î£¬£¬£¬£¬£¬£¬±£´æÓÚIOS XRʵÑéµÄCDPÖÐÆÊÎöÈëÕ¾CDPÊý¾Ý°üµÄijЩ×Ö·û´®×ֶΣ¨×°±¸IDºÍ¶Ë¿ÚIDµÈ£©Õâ¸ö»·½Ú¡£¡£¡£Õâ¸öÎó²îʹ¹¥»÷Õß¿ÉÒÔ¿ØÖÆ×ª´ï¸øsprintfº¯ÊýµÄÃûÌÃ×Ö·û´®²ÎÊý¡£¡£¡£Ê¹ÓÃijЩµÄÃûÌÃ×Ö·û´®×Ö·û£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«ÊÜ¿Ø×Ö½ÚдÈëÔ½½ç¿ÍÕ»£¨out-of-bounds stack£©±äÁ¿£¬£¬£¬£¬£¬£¬ÕâÏÖʵÉϵ¼Ö¿ÍÕ»Òç³ö¡£¡£¡£È»ºó£¬£¬£¬£¬£¬£¬ÕâÖÖÀàÐ͵ÄÒç³öµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÖÜÈ«¿ØÖÆÄ¿µÄ·ÓÉÆ÷£¬£¬£¬£¬£¬£¬ÔÚÍø¶ÎÖ®¼ä´«ÊäÁ÷Á¿£¬£¬£¬£¬£¬£¬²¢Ê¹Ó÷ÓÉÆ÷ʵÑéºóÐø¹¥»÷¡£¡£¡£
˼¿ÆIPÓïÒôµç»°»ú¡ªCDPÔ¶³ÌÖ´Ðк;ܾøÐ§ÀÍÎó²î£¨CVE-2020-3111£©
˼¿ÆIPµç»°»úʹÓÃCDP¾ÙÐÐÖÎÀí£¬£¬£¬£¬£¬£¬°üÀ¨ÉèÖõ绰»úÓ¦ÅþÁ¬µ½ÄĸöVLAN¡£¡£¡£µç»°»ú»¹¿ÉÒÔÇëÇóÌØ¶¨µÄPoE²ÎÊý£¬£¬£¬£¬£¬£¬ÓëËüÏàÅþÁ¬µÄ½»Á÷»ú¿ÉÒÔʹÓÃCDPÆôÓûò½ûÓÃÄÇЩ²ÎÊý¡£¡£¡£ÔÚ¸ÃÎó²îÖУ¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓö˿ÚIDÆÊÎöº¯ÊýÖеĿÍÕ»Òç³ö£¬£¬£¬£¬£¬£¬Ôڵ绰»úÉÏÖ´ÐдúÂë¡£¡£¡£ËäÈ»CDPÊý¾Ý°üÓÉÍøÂçÖÐÿ¸öÖ§³ÖCDPµÄ½»Á÷»úÖÕÖ¹£¬£¬£¬£¬£¬£¬µ«IPµç»°»úʵÑéµÄCDP±£´æÁíÒ»¸öbug£ºµ¥²¥ºÍ¹ã²¥CDPÊý¾Ý°üÒ²±»ÊÓΪÕýµ±µÄCDPÊý¾Ý°ü¡£¡£¡£
Ö»Óб»·¢Ë͵½Ò»¸öÖ¸¶¨µÄ¶à²¥MACµØµã£¬£¬£¬£¬£¬£¬ÆäËûËùÓÐ˼¿ÆÍøÂç×°±¸²Å»á½«ÒÔÌ«ÍøÊý¾Ý°ü½â¶ÁΪÕýµ±µÄCDPÊý¾Ý°ü¡£¡£¡£ÕâÒâζ×Å£¬£¬£¬£¬£¬£¬ÎªÁËÔÚIPµç»°»úÉÏ´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ´¦ÓÚÍâµØÍøÂçÖеÄÈκÎλÖ㬣¬£¬£¬£¬£¬¶ø²»µ«ÏÞÓÚÖ±½Ó´ÓÄ¿µÄ×°±¸ÏàÅþÁ¬µÄ½ÓÈë½»Á÷»úÄÚ²¿·¢ËͶñÒâÖÆ×÷µÄCDPÊý¾Ý°ü¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬ÓÉÓÚIPµç»°»ú»¹½«¹ã²¥CDPÊý¾Ý°ü½â¶ÁΪÕýµ±µÄCDPÊý¾Ý°ü£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔ·¢ËÍÒÔÌ«Íø¹ã²¥Êý¾Ý°ü£¬£¬£¬£¬£¬£¬Õâ»á´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬Í¬Ê±¶Ôͳһ¸öLANÉϵÄËùÓиßΣװ±¸·¢¶¯DoS¹¥»÷¡£¡£¡£
˼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñÍ·¡ªË¼¿Æ·¢Ã÷ÐÒéÔ¶³Ì´úÂëÖ´Ðк;ܾøÐ§ÀÍÎó²î£¨CVE-2020-3110£©
¸ÃÎó²îÊÇÒ»¸ö¶ÑÒç³öÎó²î£¬£¬£¬£¬£¬£¬±£´æÓÚ˼¿Æ8000ϵÁÐIPÉãÏñͷʵÑéµÄCDPÖÐÆÊÎöCDPÊý¾Ý°üÕâ¸ö»·½Ú¡£¡£¡£ÈëÕ¾CDPÊý¾Ý°üÖÐÌṩ¹ý´óµÄ¶Ë¿ÚID×Ö¶Îʱ£¬£¬£¬£¬£¬£¬»áÒý·¢Õâ¸ö¶ÑÒç³ö¡£¡£¡£¶ÑÒç³öº¬Óй¥»÷Õß¿ØÖƵÄ×Ö½Ú£¬£¬£¬£¬£¬£¬¿ÉÓɹ¥»÷Õß¶à´Î´¥·¢¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬IPÉãÏñÍ·ÖÐʹÓõÄCDPÊØ»¤³ÌÐòÊÇÓëλÖÃÎ޹صĶþ½øÖÆÎļþ£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅËü²¢²»Ê¹ÓÃASLR£¨µØµã¿Õ¼ä½á¹¹Ëæ»ú»¯£©»º½â²½·¥¡£¡£¡£ÓÉÓÚÉÏÊöÇéÐΣ¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÒç³ö¡¢ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£
˼¿ÆFXOS¡¢IOS XRºÍNX-OSÈí¼þ¡ªË¼¿Æ·¢Ã÷ÐÒé¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2020-3120£©
ֻҪʹ·ÓÉÆ÷»ò½»Á÷»úµÄCDPÊØ»¤³ÌÐò·ÖÅɵ¼ÖÂÀú³ÌÍß½âµÄ´ó¶ÎÄڴ棬£¬£¬£¬£¬£¬¿É´¥·¢¸ÃÎó²î¡£¡£¡£½èÖú¸ÃÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɵ¼ÖÂCDPÀú³ÌÖØ¸´Í߽⣬£¬£¬£¬£¬£¬½ø¶øµ¼Ö·ÓÉÖØÊÓÆô¡£¡£¡£ÕâÒâζ׏¥»÷Õß¿ÉÒÔʹÓøÃÎó²î¶ÔÄ¿µÄ·ÓÉÆ÷ʵÑéÖÜÈ«µÄDoS¹¥»÷£¬£¬£¬£¬£¬£¬½ø¶øÍêÈ«ÆÆËðÄ¿µÄÍøÂç¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://tools.cisco.com/security/center/publicationListing.x¡£¡£¡£
²Î¿¼Á´½Ó
https://www.armis.com/cdpwn/


¾©¹«Íø°²±¸11010802024551ºÅ