¡¾Â©¶´Í¨¸æ¡¿Cisco 1Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2022-01-20


0x00 ©¶´¸ÅÊö

2022Äê1ÔÂ19ÈÕ £¬CiscoÐû²¼Äþ¾²Í¨¸æ £¬ÐÞ¸´ÁËÆä¶à¸ö²úÎïÖеĶà¸öÄþ¾²Â©¶´ £¬ÕâЩ©¶´Äܹ»µ¼ÖÂÐÅϢй¶¡¢¾Ü¾ø·þÎñ¡¢ÃüÁî×¢Èë»òÔ¶³Ì´úÂëÖ´ÐС£

 

0x01 ©¶´ÏêÇé

Cisco StarOS Èí¼þµÄ Cisco Redundancy Configuration Manager (RCM) ÖдæÔÚ2¸öÄþ¾²Â©¶´ £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»ñÈ¡Ãô¸ÐÐÅÏ¢»òÒÔrootÓû§Éí·ÝÖ´ÐÐÈÎÒâ´úÂë¡£ÏêÇéÈçÏ£º

CVE-2022-20649£ºCisco RCMÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÓÉÓÚ´íÎóµØÎªÌض¨·þÎñÆôÓÃÁ˵÷ÊÔģʽ £¬Cisco RCM for Cisco StarOS Software ÖдæÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVSSÆÀ·ÖΪ9.0£© £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÒÑÅäÖÃÈÝÆ÷µÄÉÏÏÂÎÄÖÐÒÔrootȨÏÞ¶ÔÓ¦Ó÷¨Ê½Ö´ÐÐÔ¶³Ì´úÂë¡£

CVE-2022-20648£ºCisco RCMÐÅϢй¶©¶´

ÓÉÓÚµ÷ÊÔ·þÎñ´íÎóµØÕìÌýºÍ½ÓÊÜ´«ÈëÁ¬½Ó £¬Cisco RCM for Cisco StarOS Software µÄµ÷ÊÔ¹¦Ð§ÖдæÔÚÐÅϢй¶©¶´£¨CVSSÆÀ·ÖΪ5.3£© £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´Ðе÷ÊÔ²Ù×÷ £¬Õâ¿ÉÄܵ¼Öµ÷ÊÔÐÅÏ¢µÈÃô¸ÐÐÅϢй¶¡£

´ËÍâ £¬Cisco»¹ÐÞ¸´ÁËÆä¶à¸ö²úÎïÖеÄSnort Modbus ¾Ü¾ø·þÎñ©¶´£¨CVE-2022-20685 £¬CVSSÆÀ·Ö7.5£©ºÍCLI ÃüÁî×¢Èë©¶´£¨CVE-2022-20655 £¬CVSSÆÀ·Ö8.8£©¡£Ç°ÕßÊÇÓÉÓÚ´¦Öà Modbus Á÷Á¿Ê±·ºÆðÕûÊýÒç³ö £¬Snort ¼ì²âÒýÇæµÄ Modbus Ô¤´¦ÖÃÆ÷ÖдæÔÚÄþ¾²ÎÊÌâ £¬¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉè±¹ØÁ¬¼Ö¾ܾø·þÎñ (DoS) ¡£¸Ã©¶´Ó°ÏìÔçÓÚ°æ±¾ 2.9.18 ºÍ°æ±¾ 3.1.0.100 µÄËùÓпªÔ´ Snort ÏîÄ¿°æ±¾ £¬²¢Ó°ÏìÁ˶à¸öCisco²úÎï £»ºóÕßÊÇÓÉÓÚÔÚÊÜÓ°ÏìµÄ²úÎïÉ϶Խø³Ì²ÎÊýµÄÑéÖ¤²»³äʵ £¬¶à¸ö Cisco ²úÎïµÄ CLI ʵʩÖдæÔÚ×¢Èë©¶´ £¬ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄµ±µØ¹¥»÷ÕßÖ´ÐÐÃüÁî×¢Èë¹¥»÷¡£

 

Ó°Ï췶Χ

CVE-2022-20649¡¢CVE-2022-20648£º

Cisco RCM for StarOS °æ±¾<= 21.25

 

0x02 ´¦Öý¨Òé

ĿǰCiscoÒѾ­ÐÞ¸´ÁËÉÏÊö©¶´ £¬½¨Ò鼰ʱ²ÎÕÕ¹Ù·½Í¨¸æÉý¼¶¸üÐÂÖÁÏàÓ¦ÐÞ¸´°æ±¾¡£

Õë¶ÔCVE-2022-20649¡¢CVE-2022-20648£º

l  Cisco RCM for StarOS °æ±¾< 21.25£ºÇ¨ÒƵ½Àι̰汾¡£

l  Cisco RCM for StarOS °æ±¾ 21.25£ºÉý¼¶µ½21.25.4¡£

ÈôÒª´ÓCisco.com ÉϵÄÈí¼þÖÐÐÄÏÂÔØÈí¼þ £¬ÇëÖ´ÐÐÒÔϲÙ×÷£º

1.µ¥»÷¡°Browse all¡±¡£

2.Ñ¡Ôñ¡°Wireless > Mobile Internet > Platforms > Ultra Packet Core > Ultra Software¡±¡£

3.´Ó×ó²à´°¸ñÖÐÑ¡ÔñÒ»¸ö°æ±¾¡£

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rcm-vuls-7cS3Nuq

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cli-cmdinj-4MttWZPB

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-dos-9D3hJLuj

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-01-20

Ê×´ÎÐû²¼

  

0x05 ¸½Â¼

¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú¹«Ë¾½¨Á¢ÓÚ1996Äê £¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊÐ £¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ° £¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹ £¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ £¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£

¶àÄêÀ´ £¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png