¡¾Íþвͨ¸æ¡¿Cisco£¨Ë¼¿Æ£©·¢Ã÷ÐÒéÎó²î£¨CDP£©
2020-02-06
×ÛÊö
±±¾©Ê±¼ä2ÔÂ6ÈÕ£¬Ë¼¿Æ£¨Cisco£©¹Ù·½ÐÞ¸´Á˱£´æÓÚCDPÐÒéÖеÄ5¸ö¸ßΣÎó²î£¬¸ÃÐÒé¿ÉÔÊÐí˼¿Æ×°±¸ÔÚÄÚÍøÇéÐÎͨ¹ý¶à²¥ÐÂÎÅÏ໥·ÖÏíÐÂÎÅ£¬Ö÷ÒªÓ°ÏìIPµç»°ºÍÉãÏñÍ·×°±¸¡£
´Ë´Î¹ûÕæµÄ5¸öÎó²î¾ùÊôÓÚÄÚ´æÒç³öÎó²î£¬ÏÖʵʹÓÃÄѶȴó£¬ÔÚÌØ¶¨Ìõ¼þÏ¿ÉÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£Ë¼¿ÆÔÚÎó²îͨ¸æÖÐÖ¸³ö£º Cisco·¢Ã÷ÐÒéÊǵÚ2²ãÐÒ顣ҪʹÓôËÎó²î£¬¹¥»÷Õß±ØÐèÓëÊÜÓ°ÏìµÄ×°±¸Î»ÓÚͳһ¹ã²¥ÓòÖУ¨µÚ2²ãÏàÁÚ£©¡£
Îó²îCVE£º
CVE-2020-3110
CVE-2020-3111
CVE-2020-3118
CVE-2020-3119
CVE-2020-3120
ÊÜÓ°ÏìµÄ×°±¸
Cisco FXOS Software,
Cisco IP Camera Firmware,
Cisco IP Phone Firmware,
Cisco NX-OS Software,
Cisco IOS-XR
Cisco UCS Fabric Interconnects
²»ÊÜÓ°ÏìµÄ×°±¸
Cisco IOS and Cisco IOS-XE Software, and firewalls such as the Cisco ASA, Cisco Firepower 1000 Series, and Cisco Firepower 2100 Series. (Though CVE-2020-3120 affects the Firepower 4100 Series and Firepower 9300 Security Appliances)
»º½â²½·¥
˼¿Æ¹Ù·½ÒѾÐû²¼Ð°汾ÐÞ¸´ÁËÕâЩÎó²î£¬ÇëÓû§¾¡¿ìÉý¼¶¾ÙÐзÀ»¤¡£
ÏêÇé²Î¿¼Ë¼¿Æ¹Ù·½Í¨¸æÖ¸ÄÏ£º
https://community.cisco.com/t5/security-blogs/insights-about-multiple-vulnerabilities-in-cisco-discovery/ba-p/4023505
²Î¿¼Á´½Ó
https://www.helpnetsecurity.com/2020/02/05/cdpwn-vulnerabilities/
https://www.armis.com/cdpwn/#devices
https://community.cisco.com/t5/security-blogs/insights-about-multiple-vulnerabilities-in-cisco-discovery/ba-p/4023505
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£ »ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

¾ÅÓÎÀϸçÔÆ







