Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Cisco IOS ºÍIOS XE SNMP Ô¶³Ì´úÂëÖ´ÐÐÎó²î |
CVE ID | CVE-2025-20352 |
Îó²îÀàÐÍ | »º³åÇøÒç³ö | ·¢Ã÷ʱ¼ä | 2025-09-26 |
Îó²îÆÀ·Ö | 7.7 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Cisco IOS£¨Internetwork Operating System£©ÊÇ˼¿Æ¹«Ë¾ÎªÆä·ÓÉÆ÷ºÍ½»Á÷»ú×°±¸¿ª·¢µÄ²Ù×÷ϵͳ£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÆóÒµºÍЧÀÍÌṩÉ̵ÄÍøÂç×°±¸ÖС£¡£¡£¡£¡£¡£¡£IOS XEÊÇIOSµÄÉý¼¶°æ±¾£¬£¬£¬£¬£¬»ùÓÚLinuxÄںˣ¬£¬£¬£¬£¬¾ß±¸¸ü¸ßµÄ¿ÉÀ©Õ¹ÐÔ¡¢ÎÞаÐԺ͸üÇ¿µÄÍøÂçÐéÄ⻯ÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£IOS XEÖ§³Ö¸üÖØ´óµÄÓ¦ÓúÍЧÀÍ£¬£¬£¬£¬£¬Ìṩ¸üÇ¿µÄÇå¾²ÐԺͿÉÖÎÀíÐÔ£¬£¬£¬£¬£¬ÊÊÓÃÓÚ¸ßÐÔÄܵÄÍøÂç×°±¸£¬£¬£¬£¬£¬ÈçCisco Catalyst 9000ϵÁн»Á÷»ú¡£¡£¡£¡£¡£¡£¡£Á½Õß¶¼Ö§³Ö¸»ºñµÄÍøÂçÐÒé¡¢ÖÎÀí¹¤¾ßºÍÇå¾²¹¦Ð§£¬£¬£¬£¬£¬ÊÇÏÖ´úÍøÂç×°±¸µÄ½¹µã²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£
2025Äê9ÔÂ26ÈÕ£¬£¬£¬£¬£¬°ÙÀÖ²©¼¯ÍÅVSRC¼à²âµ½Ò»¸öÓ°ÏìCisco IOSºÍIOS XEÈí¼þµÄSNMP£¨¼òÆÓÍøÂçÖÎÀíÐÒ飩»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÈ«ÐĽṹµÄSNMPÊý¾Ý°ü£¬£¬£¬£¬£¬Ê¹ÓøÃÎó²îÔÚÊÜÓ°Ïì×°±¸ÉÏÌᳫԶ³Ì¹¥»÷£¬£¬£¬£¬£¬µ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©»òÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¡£¡£¡£¡£¹ØÓÚµÍȨÏÞµÄÈÏÖ¤Ô¶³Ì¹¥»÷Õߣ¬£¬£¬£¬£¬ÈôÓµÓÐÓÐÓõÄSNMPv2cÖ»¶ÁÉçÇø×Ö·û´®»òSNMPv3Óû§Æ¾Ö¤£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂ×°±¸ÖØÆô£¬£¬£¬£¬£¬´Ó¶ø´¥·¢DoS£»£»£»£»£»¹ØÓÚ¸ßȨÏ޵Ĺ¥»÷Õߣ¬£¬£¬£¬£¬ÈôÓµÓÐSNMPv1/v2cÖ»¶ÁÉçÇø×Ö·û´®»òSNMPv3ƾ֤£¬£¬£¬£¬£¬²¢ÇҾ߱¸ÖÎÀíÔ±»òÌØÈ¨15ƾ֤£¬£¬£¬£¬£¬Ôò¿ÉÄÜÒÔrootÉí·ÝÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬ÍêÈ«¿ØÖÆÊÜÓ°Ïì×°±¸¡£¡£¡£¡£¡£¡£¡£Îó²îÆÀ·Ö7.7£¬£¬£¬£¬£¬Îó²î¼¶±ð¸ßΣ¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
¸ÃÎó²îÓ°ÏìËùÓÐÆôÓÃÁËSNMP²¢Î´ÏÔʽɨ³ýÊÜÓ°ÏìOIDµÄ×°±¸£¬£¬£¬£¬£¬°üÀ¨µ«²»ÏÞÓÚÔËÐÐCisco IOSºÍIOS XEÈí¼þµÄ·ÓÉÆ÷ºÍ½»Á÷»ú£¬£¬£¬£¬£¬ÏêϸÊÜÓ°ÏìµÄ×°±¸»¹°üÀ¨ÔËÐÐMeraki CS 17¼°¸üÔç°æ±¾µÄMeraki MS390ϵÁн»Á÷»úºÍCisco Catalyst 9300ϵÁн»Á÷»ú¡£¡£¡£¡£¡£¡£¡£ÐèÒª×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬Cisco IOS XRºÍNX-OSÈí¼þ²»ÊܸÃÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
CiscoÒÑÐû²¼ÐÞ¸´²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁÐÞ¸´°æ±¾£¬£¬£¬£¬£¬ÒÔ³¹µ×½â¾ö¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte/
3.2 ÔÝʱ²½·¥
ÖÎÀíÔ±Ó¦Ö»ÔÊÐíÊÜÐÅÈεÄÓû§»á¼ûSNMP£¬£¬£¬£¬£¬ïÔÌDZÔÚ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte/https://nvd.nist.gov/vuln/detail/CVE-2025-20352