Cisco IOS XEÈí¼þWeb UI¿çÕ¾µãÇëÇóαÔìÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-14

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1904£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚCisco IOS XEÈí¼þ°æ±¾ÇÒÆôÓÃÁËHTTP Server¹¦Ð§µÄCisco×°±¸¡£¡£¡£¡£¡£


Îó²î¸ÅÊö


Cisco IOS XEÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ΪÆäÍøÂç×°±¸¿ª·¢µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£Cisco IOS XE SoftwareÖеÄWeb UI±£´æCSRFÎó²î£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶ÔÊÜÓ°ÏìµÄϵͳ¾ÙÐпçÕ¾µãÇëÇóαÔ죨CSRF£©¹¥»÷¡£¡£¡£¡£¡£


¸ÃÎó²îÊÇÓÉÓÚÊÜÓ°ÏìÉè±¹ØÁ¬ÄWeb UIµÄCSRF±£»£»£»¤È±·¦¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý˵·þ½Ó¿ÚµÄÓû§×ñÕÕ¶ñÒâÁ´½ÓÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÓÃÊÜÓ°ÏìÓû§µÄȨÏÞ¼¶±ðÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£¡£¡£ÈôÊÇÓû§¾ßÓÐÖÎÀíȨÏÞ£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔ¸ü¸ÄÉèÖ㬣¬£¬Ö´ÐÐÏÂÁî»òÖØÐ¼ÓÔØÊÜÓ°ÏìµÄ×°±¸¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


½ûÓÃHTTP Server¹¦Ð§¿ÉÏû³ý´ËÎó²îµÄ¹¥»÷ǰÑÔ£¬£¬£¬²¢ÇÒ¿ÉÄÜÊÇÊʵ±µÄ»º½â²½·¥£¬£¬£¬Ö±µ½¿ÉÒÔÉý¼¶ÊÜÓ°ÏìµÄ×°±¸¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190612-iosxe-csrf