CVE-2020-3566 | Cisco IOS-XR·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-09-02

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2020-3566

ʱ    ¼ä

2020-09-02

Àà    ÐÍ

DOS

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

ÆôÓÃDVMRPÖ°ÄܵÄIOS-XRϵÁÐËùÓа汾


Cisco¹«Ë¾ÓÚ2020Äê8ÔÂ29ÈÕ¹Ù·½°ä²¼·ì϶Ԥ¾¯£¬£¬£¬£¬£¬£¬£¬Cisco IOS-XRϵÁÐÖеľàÀëʸÁ¿¶à²¥Â·ÓɺÍ̸£¨DVMRP£©´æÔÚÒ»¸öBug£¬£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓôËbug£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÉ豸ÄÚ´æºÄ¾¡²¢Ê¹ÆäËü¹ý³Ì±ÀÀ££¬£¬£¬£¬£¬£¬£¬Æä·ì϶±àºÅΪCVE-2020-3566¡£ ¡£¡£¡£ ¡£¡£¡£IOS-XRϵÁÐÖØÒªÓÃÓÚÔËÓªÉ̺ÍÊý¾ÝÖÐÐÄ¡£ ¡£¡£¡£ ¡£¡£¡£

¸Ã·ì϶ÊÇÓÉÓÚInternet×éÖÎÀíºÍ̸£¨IGMP£©Êý¾Ý°üµÄ¶ÓÁÐÖÎÀí²»¼°ËùÖ¡£ ¡£¡£¡£ ¡£¡£¡£Ë¼¿Æ»¹Î´°ä²¼´ËÈí¼þµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬Cisco²úÆ·°²È«ÊÂÎñÏìÓ¦Ó××飨PSIRT£©ÓÚ2020Äê8ÔÂ28ÈÕ·¢´Ë¿ÌÒ°±íÊÔIJÀûÓô˷ì϶µÄ¹¥»÷»î¶¯¡£ ¡£¡£¡£ ¡£¡£¡£

0x01 ·ì϶ÏêÇé

ͼƬ1.png


ÈôÊÇ·ì϶µ¼ÖÂÄÚ´æºÄ¾¡£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜ»áÓ°ÏìÉ豸ÉÏµÄÆäËü¹ý³Ì¡£ ¡£¡£¡£ ¡£¡£¡£¿£¿£¿£¿£Äܹ»Í¨¹ýʹÓÃprocess restart igmpºÅÁî³ÁÐÂÆô¶¯IGMP¹ý³Ì£¬£¬£¬£¬£¬£¬£¬Äܹ»¸´Ô­IGMP¹ý³Ì¿÷ËðµÄÄڴ棬£¬£¬£¬£¬£¬£¬ÈçÏÂËùʾ£º

          RP/0/0/CPU0:router# process restart igmp

ÈôÊÇIGMP¹ý³Ì˲¼ä±ÀÀ££¬£¬£¬£¬£¬£¬£¬ÔòÎÞÐèÊÖ¶¯³ÁÐÂÆô¶¯IGMP¹ý³Ì£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚϵͳÒѾ­Ö´ÐÐÁ˸òÙ×÷¡£ ¡£¡£¡£ ¡£¡£¡£ÕâÖÖ×Ô¶¯³ÁÆô½«¸´Ô­¿÷ËðµÄÄÚ´æ¡£ ¡£¡£¡£ ¡£¡£¡£

ÔÚ˼¿¼»º½â´ëʩʱ£¬£¬£¬£¬£¬£¬£¬¶ÔÓÚÄÚ´æºÄ×ÝÇé¿ö£¬£¬£¬£¬£¬£¬£¬ËÙ¶ÈÏ޶ȺͽӼû½ÚÔì²½ÖèÊÇÓÐЧµÄ¡£ ¡£¡£¡£ ¡£¡£¡£¶ÔÓÚ˲¼ä²úÉúIGMP¹ý³Ì±ÀÀ£µÄÇé¿ö£¬£¬£¬£¬£¬£¬£¬Ö»ÓнӼû½ÚÔì²½ÖèÓÐЧ¡£ ¡£¡£¡£ ¡£¡£¡£

µ±É豸ÄÚ´æºÄ¾¡Ê±£¬£¬£¬£¬£¬£¬£¬ÔÚϵͳÈÕÖ¾ÖпÉÄܻῴµ½ÒÔÏÂÐÂÎÅ£º

         RP/0/RSP1/CPU0:Aug 28 03:46:10.375 UTC: raw_ip[399]: %PKT_INFRA-PQMON-6-QUEUE_DROP : Taildrop on XIPC queue 1 owned by igmp (jid=1175)

            RP/0/RSP0/CPU0:Aug 28 03:46:10.380 UTC: raw_ip[399]: %PKT_INFRA-PQMON-6-QUEUE_DROP : Taildrop on XIPC queue 1 owned by igmp (jid=1175)

            RP/0/RSP0/CPU0:Aug 28 03:49:22.850 UTC: dumper[61]: %OS-DUMPER-7-DUMP_REQUEST : Dump request for process pkg/bin/igmp

            RP/0/RSP0/CPU0:Aug 28 03:49:22.851 UTC: dumper[61]: %OS-DUMPER-7-DUMP_ATTRIBUTE : Dump request with attribute 7 for process pkg/bin/igmp

            RP/0/RSP0/CPU0:Aug 28 03:49:22.851 UTC: dumper[61]: %OS-DUMPER-4-SIGSEGV : Thread 9 received SIGSEGV - Segmentation Fault

µ±É豸µÄIGMP¹ý³Ì±ÀÀ£Ê±£¬£¬£¬£¬£¬£¬£¬ÔÚϵͳÈÕÖ¾ÖпÉÄܻῴµ½ÒÔÏÂÐÂÎÅ£º

         RP/0/RSP0/CPU0:Aug 30 17:21:47.653 UTC: igmp[1169]: %HA-HA_WD_LIB-4-RLIMIT : wd_handle_sigxfsz: Reached 90% of RLIMIT_DATA

           RP/0/RSP0/CPU0:Aug 30 17:21:47.653 UTC: igmp[1169]: %ROUTING-IPV4_IGMP-4-OOM_STATE_THROTTLE : Received Critical memory depletion warning, stop creating new igmp state

           RP/0/RSP1/CPU0:Aug 30 17:23:50.442 UTC: sysmgr[94]: igmp(1) (jid 1169) (pid 121667828) (fail_count 2) abnormally terminated, restart scheduled

 

0x02 ´ëÖý¨Òé

Ŀǰ¹Ù·½Î´°ä²¼°²È«¸üС£ ¡£¡£¡£ ¡£¡£¡£

һʱ´ëÊ©£º

1.ÔËÐÐshow igmp interfaceºÅÁîÅжÏÉ豸ÉÏÊÇ·ñÆôÓÃÁ˶ಥ·ÓÉ¡£ ¡£¡£¡£ ¡£¡£¡£

ÈçͼËùʾ£º

 

ͼƬ2.png

 

ÈôÊÇÊä³öΪ¿Õ£¬£¬£¬£¬£¬£¬£¬Ôò¸ÃÉ豸²»ÊÜÓ°Ïì¡£ ¡£¡£¡£ ¡£¡£¡£


2.ΪÁË»º½âÄÚ´æºÄ¾¡µÄÇé¿ö£¬£¬£¬£¬£¬£¬£¬½¨ÒéÖ´ÐÐËÙ¶ÈÏÞ¶È¡£ ¡£¡£¡£ ¡£¡£¡£Õâ±ØÒªÖªÂ·µ±Ç°µÄIGMPÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäËÙ¶ÈÉèÖÃΪµÍÓÚµ±Ç°µÄ¾ùÔÈËÙ¶È¡£ ¡£¡£¡£ ¡£¡£¡£ÅäÖÃģʽÏÂÊäÈëlpts pifib hardware police flow igmp rateºÅÁî¡£ ¡£¡£¡£ ¡£¡£¡£

ÈçÏÂËùʾ£º

           RP/0/0/CPU0:router(config)# lpts pifib hardware police flow igmp rate

¸ÃºÅÁî²»»áɾ³ý·ì϶ÀûÓõÄʸÁ¿¡£ ¡£¡£¡£ ¡£¡£¡£µ«ÊǸúÅÁ½µµÍͨѶÖÊÁ¿²¢Ôö³¤³É¹¦ÀûÓÃËùÐèµÄ¹¦·ò¡£ ¡£¡£¡£ ¡£¡£¡£¿£¿£¿£¿£Äܹ»ÀûÓÃÕâ¶Î¹¦·òÀ´Ö´Ðи´Ô­²Ù×÷¡£ ¡£¡£¡£ ¡£¡£¡£


3.¸üнӼû½ÚÔìÁÐ±í£¨ACL£©£¬£¬£¬£¬£¬£¬£¬ÒÔ»º½âÄÚ´æºÄ×ÝÇé¿öºÍ˲¼äIGMP¹ý³Ì±ÀÀ£Çé¿ö¡£ ¡£¡£¡£ ¡£¡£¡£ÈçÏ£º

               RP/0/0/CPU0:router(config)# ipv4 access-list deny igmp any any dvmrp

0x03 ÓйØÐÂÎÅ

https://www.securezoo.com/2020/08/cisco-warns-of-ios-xr-zero-day-vulnerability-exploit-in-the-wild-cve-2020-3566/

https://www.zdnet.com/article/cisco-warns-of-actively-exploited-ios-xr-zero-day/

 

0x04 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz

0x05 ¹¦·òÏß

2020-08-29 Cisco¹Ù·½°ä²¼Ô¤¾¯

2020-09-02 VSRC°ä²¼·ì϶¹«¸æ

 

 

ͼƬ3.png