˼¿Æ220ϵÁÐÖÇÄܽ»Á÷»ú¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-08

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1914£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.2£¬£¬£¬ £¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1912£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.1£¬£¬£¬ £¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1913£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬ £¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚCisco Small Business 220 Series Smart Switches ¹Ì¼þ°æ±¾ < 1.1.4.4¡£¡£ ¡£


Îó²î¸ÅÊö


Cisco Small Business 220 Series Smart SwitchesÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»¿îСÐÍÖÇÄܽ»Á÷»ú×°±¸¡£¡£ ¡£


CVE-2019-1914

˼¿Æ£¨Cisco Small Business£©220ϵÁÐÖÇÄܽ»Á÷»úµÄWebÖÎÀí½çÃæÖб£´æÏÂÁî×¢ÈëÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓгä·ÖÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£ ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµÄHTTP»òHTTPSÇëÇóʹÓøÃÎó²îÒÔrootÓû§È¨ÏÞÖ´ÐÐí§ÒâµÄshellÏÂÁî¡£¡£ ¡£


CVE-2019-1912

˼¿Æ£¨Cisco Small Business£©220ϵÁÐÖÇÄܽ»Á÷»úµÄWebÖÎÀí½çÃæÖб£´æÈÏÖ¤ÈÆ¹ýÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ²»ÍêÈ«µÄȨÏÞ¼ì²é¡£¡£ ¡£¹¥»÷ÕßʹÓøÃÎó²î¿ÉÒÔÔÚδ¾­Éí·ÝÑéÖ¤µÄÇéÐÎÏÂÉÏ´«í§ÒâÎļþ¡£¡£ ¡£


CVE-2019-1913

˼¿Æ£¨Cisco Small Business£©220ϵÁÐÖÇÄܽ»Á÷»úµÄWebÖÎÀí½çÃæÖб£´æ»º³åÇø¹ýʧÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓгä·ÖµØÑéÖ¤Óû§Ìá½»µÄÊý¾Ý²¢ÇÒûÓоÙÐÐ׼ȷµÄ½çÏß¼ì²é¡£¡£ ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµÄÇëÇóʹÓøÃÎó²îÔڵײã²Ù×÷ϵͳÉÏÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£ ¡£


ÐÞ¸´½¨Òé


˼¿ÆÒѾ­Ðû²¼ÁË×îеĹ̼þ°æ±¾£¬£¬£¬ £¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§Ó¦ÊµÊ±Éý¼¶¾ÙÐзÀ»¤£º


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-inject

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-auth_bypass

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-rce


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/publicationListing.x