˼¿Æ¶à¿î²úÆ·ÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-20
Îó²î±àºÅ
CVE-2018-0376
CVE-2018-0377
CVE-2018-0374
CVE-2018-0375

µÈ25¸öÎó²î £¬£¬£¬¼ûÏÂÎÄÁбí¡£¡£¡£¡£


Îó²î¼¶±ð
ÑÏÖØ

³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

Policy Suite¡¢SD-WAN¡¢WebEx ºÍ Nexus ²úÆ·


Îó²î¸ÅÊö

7ÔÂ18ÈÕ £¬£¬£¬Ë¼¿Æ¼û¸æ¿Í»§ £¬£¬£¬ËüÒÑÔÚÆäPolicy Suite, SD-WAN, WebEx ºÍNexus²úÆ·Öз¢Ã÷²¢ÐÞ²¹ÁË25¸öÎó²î£¨4¸öcritical £¬£¬£¬9¸öhigh £¬£¬£¬12¸ömedium£©¡£¡£¡£¡£ÈçÏ£º


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


´Ó Policy Suite Öз¢Ã÷ËĸöÑÏÖØÈ±ÏÝ £¬£¬£¬ÆäÖÐÁ½¸öÇå¾²Îó²îÊÇδÈÏÖ¤»á¼ûȨÏÞÎÊÌâ £¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õß»á¼û Policy Builder ½çÃæºÍ¿ª·ÅЧÀÍÍø¹Ø½¨Òé (OSGi) ½Ó¿Ú¡£¡£¡£¡£

CVE-2018-0376
Ò»µ©»ñµÃÓÉÓÚȱ·¦Éí·ÝÑéÖ¤¶øÌ»Â¶µÄPolicy Builder interfaceµÄ»á¼ûȨÏÞ £¬£¬£¬¹¥»÷Õ߾ͿÉÒÔ¶ÔÏÖÓд洢¿â¾ÙÐиü¸Ä²¢½¨ÉèеĴ洢¿â¡£¡£¡£¡£ 
CVE-2018-0377
OSGi½Ó¿ÚÔÊÐí¹¥»÷Õß»á¼û»ò¸ü¸ÄOSGiÀú³Ì¿É»á¼ûµÄÈκÎÎļþ¡£¡£¡£¡£
CVE-2018-0374
ȱ·¦ÈÏÖ¤»úÖÆ»¹¿Éµ¼Ö Policy Builder Êý¾Ý¿âÔâ̻¶ £¬£¬£¬´Ó¶øµ¼Ö¹¥»÷Õß»á¼û²¢¸ü¸Ä´æ´¢ÔÚÆäÖеÄÈκÎÊý¾Ý¡£¡£¡£¡£
CVE-2018-0375
Policy SuiteÖеÄCluster Manager±£´æÒ»¸ö¾ßÓÐĬÈÏ¡¢¾²Ì¬Æ¾Ö¤µÄrootÕÊ»§¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒԵǼ´ËÕÊ»§²¢Ê¹ÓÃrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£
˼¿Æ»¹ÐÞ¸´ÁË SD-WAN ½â¾ö¼Æ»®Öб£´æµÄÆß¸öÎó²î¡£¡£¡£¡£ÆäÖÐΨÖðÒ»¸öÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏÂÄÜÔâÔ¶³ÌʹÓõÄÎó²îÓ°Ïì Touch Provision ЧÀÍ £¬£¬£¬Ëü¿Éµ¼Ö¹¥»÷ÕßÒý·¢ DoS Ìõ¼þ¡£¡£¡£¡£
ÆäËüµÄ SD-WAN Çå¾²Îó²îÒªÇó¾ÙÐÐÈÏÖ¤ £¬£¬£¬ÈçÔâʹÓà £¬£¬£¬¿É¸²Ð´µ×²ã²Ù×÷ϵͳÉϵÄí§ÒâÎļþ²¢ÒÔ vmanage »ò¸ùȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£ÆäÖеÄÒ»¸ö SD-WAN Îó²îʹÓÃÒªÇóÈÏÖ¤ºÍÍâµØ»á¼ûȨÏÞ¡£¡£¡£¡£
˼¿Æ»¹Í¨ÖªÏûºÄÕß³ÆÆä Nexus 9000 ϵÁÐµÄ Fabric ½»Á÷»ú £¬£¬£¬ÏêϸÊÇ DHCPv6 ¹¦Ð§ £¬£¬£¬ËüÊÜÒ»¸ö¸ßΣȱÏÝÓ°Ïì £¬£¬£¬¿ÉÔâÔ¶³Ìδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÓÃÓÚÒý·¢ DoS Ìõ¼þ¡£¡£¡£¡£

˼¿Æ»¹½«¶à¸öÓ°Ïì˼¿Æ Webex Network Recording Player for AdvancedRecording Format (ARF) ºÍ WebexRecording Format (WRF) ÎļþµÄÎó²îÆÀΪ¸ßΣÎó²î¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÈÃÄ¿µÄÓû§Ê¹ÓÃÊÜÓ°Ïì²¥·ÅÆ÷·­¿ªÌØÊâ½á¹¹µÄ ARF »ò WRF Îļþ¾ÍÄÜÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


ÐÞ¸´½¨Ò飺

˼¿Æ¹Ù·½ÒѾ­Ðû²¼Ð°汾ÐÞ¸´ÁËÉÏÊöÎó²î £¬£¬£¬Óû§Ó¦ÊµÊ±Éý¼¶¾ÙÐзÀ»¤¡£¡£¡£¡£


²Î¿¼Á´½Ó£º
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities
https://www.securityweek.com/cisco-finds-serious-flaws-policy-suite-sd-wan-products