[¸ßΣ·ì϶¾¯±¨] ˼¿Æ¸ßΣ·ì϶±»ÓÃÀ´¹¥»÷¹Ø¼ü»ù´¡ÉèÊ©£¬ÎÒ¹úÒÑÓлú¹¹Êܵ½¹¥»÷
°ä²¼¹¦·ò 2018-04-082018Äê3ÔÂ28ÈÕ£¬Ë¼¿Æ°ä²¼Á˸ßΣ·ì϶Ԥ¾¯³ÆË¼¿ÆIOS¡¢IOS XEºÍIOS XRÈí¼þÖдæÔÚ¶à¸ö·ì϶¡£ÆäÖÐÔ̺¬2¸öÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2018-0171¡¢CVE-2018-0151¡£¹¥»÷Õß¿ÉÀûÓ÷ì϶½øÐÐδÊÚȨ½Ó¼û¡¢ÌáȨ¡¢Ö´ÐÐËÁÒâ´úÂë»òµ¼Ö»ؾø·þÎñ¡£
·ìϼûèÊö
Cisco Smart InstallÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-0171£©·çÏյȼ¶£º³¬Î£
Cisco IOS¡¢IOS XEÈí¼þSmart Install¿Í»§¶ËÖдæÔÚ»º³åÇø²Ö¿âÒç¶Âí½Å£¨CVE-2018-0171£©£¬¸Ã·ì϶ÊÇÓÉÓÚ¶Ô·Ö×éÊý¾ÝÑéÖ¤²»µ±Ôì³ÉµÄ¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õߣ¬Äܹ»Í¨¹ý»ú¹Ø¶ñÒâSmall InstallÐÂÎŰü£¬ÏòÊÜÓ°ÏìÉ豸µÄTCP 4786¶Ë¿Ú·¢Ë͸ÃÊý¾Ý°ü£¬³ÁÔØÖ¸±êÉ豸£¬Ôì³ÉÉ豸»Ø¾ø·þÎñ£¨DoS£©»òÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£
ÓÉÓÚ4786¶Ë¿ÚĬÈÏ¿ªÆô£¬ÇҸ÷ì϶pocÒѾ±»¹«¿ª£¬·ì϶·çÏÕˮƽ¼«¸ß¡£
¸Ã·ì϶´æÔÚÓÚÔËÐÐÁËCisco IOS/IOS EXÊÜÓ°Ïì°æ±¾Èí¼þ£¬ÇÒΪSmart Install ClientģʽµÄÉ豸¡£Î´¿ªÆôCisco Smart Install£¬»ò±»ÉèÖÃΪSmart Install DirectorģʽµÄÉ豸²»ÔÚÓ°ÏìÖ®ÁС£
Cisco QoSÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-0151£© ·çÏյȼ¶£º³¬Î£
¸Ã·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìÉ豸¶Ô´ïµ½ÆäUDP 18999¶Ë¿ÚµÄÊý¾Ý°üÖÐijЩֵµÄÌìǵ²é³²»µ±Ôì³ÉµÄ¡£¹¥»÷Õß¿Éͨ¹ýÏòÊÜÓ°ÏìÉ豸·¢ËͶñÒâ»ú¹ØµÄÊý¾Ý°üÀ´ÀûÓ÷ì϶£¬ÊÜÓ°ÏìÉ豸ÔÚ´¦ÖÃÊý¾Ý°üʱ¿ÉÄܲúÉú»º³åÇøÒç³ö£¬µ¼ÖÂÉ豸³ÁÔØ¡£¸Ã·ì϶ӰÏìËùÓÐÔËÐÐÁËCisco IOS/IOS EXÊÜÓ°Ïì°æ±¾Èí¼þµÄÉ豸¡£
Ŀǰ¹ú¼ÊÉÏ»òÐíÓжþÊ®ÍòÊÜÓ°ÏìÉ豸¶³öÔÚ¹«ÍøÉÏ£º
ÉÏÖÜ£¬Ò»¸öÃûΪ¡°JHT¡±µÄºÚ¿Í×éÖ¯ÀûÓÃ˼¿ÆCVE-2018-0171 ÖÇÄÜ×°Ö÷ì϶¹¥»÷ÁËÔ̺¬¶íÂÞ˹ºÍÒÁÀÊÔÚÄڵĶà¸ö¹ú¶ÈÍøÂç»ù´¡ÉèÊ©¡£±»¹¥»÷µÄCisco·ÓÉÆ÷µÄÅäÖÃÎļþstartup.config»á±»¸²¸Ç£¬Â·ÓÉÆ÷½«³ÁÐÂÆô¶¯¡£³ýÁ˵¼Ö´óÃæ»ýÍøÂçÖжÏÒÔ±í£¬ÖÎÀíÔ±»¹»á·¢ÏÖ·ÓÉÆ÷ÅäÖÃÎļþ±»¸ü¸Ä³É£º¡°Don't mess with our elections.... -JHT usafreedom_jht@tutanota.com¡±¡£
½ñÌ죬ÎÒÃÇÂ½ÐøÊÕµ½¶à¸ö¹úÄÚ»ú¹¹Ôâ·êͬÑùµÄ¹¥»÷µÄÐÂÎÅ¡£±»¹¥»÷µÄÉ豸³ý̱»¾±í£¬ÅäÖÃÎļþ»¹»áÏÔʾһ¸öÃÀ¹ú¹úÆì¡£
½â¾ö¹æ»®
1.Cisco¹Ù·½ÒѾ°ä²¼Á˸üв¹¶¡£¬£¬½¨ÒéÓйØÓû§¾¡¿ì¸üÐÂÉý¼¶¡££¨https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2£©
2.GA»Æ½ð¼×ÒÑÓÚ4ÔÂ4ÈÕÉý¼¶ÊÂÎñ¿â£¬ÊÂÎñÃû³Æ£ºTCP_Cisco_SmartInstall_Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2018-0171)£¬Çë¿í´óÓû§ÊµÊ±Éý¼¶¡£
ÌìãÙÈëÇÖ¼ì²âϵͳ±¨¾¯½ØÍ¼£º
ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º
ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º
2018Äê3ÔÂ28ÈÕ£¬Ë¼¿Æ°ä²¼Á˸ßΣ·ì϶Ԥ¾¯³ÆË¼¿ÆIOS¡¢IOS XEºÍIOS XRÈí¼þÖдæÔÚ¶à¸ö·ì϶¡£ÆäÖÐÔ̺¬2¸öÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2018-0171¡¢CVE-2018-0151¡£¹¥»÷Õß¿ÉÀûÓ÷ì϶½øÐÐδÊÚȨ½Ó¼û¡¢ÌáȨ¡¢Ö´ÐÐËÁÒâ´úÂë»òµ¼Ö»ؾø·þÎñ¡£
·ìϼûèÊö
Cisco Smart InstallÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-0171£©·çÏյȼ¶£º³¬Î£
Cisco IOS¡¢IOS XEÈí¼þSmart Install¿Í»§¶ËÖдæÔÚ»º³åÇø²Ö¿âÒç¶Âí½Å£¨CVE-2018-0171£©£¬¸Ã·ì϶ÊÇÓÉÓÚ¶Ô·Ö×éÊý¾ÝÑéÖ¤²»µ±Ôì³ÉµÄ¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õߣ¬Äܹ»Í¨¹ý»ú¹Ø¶ñÒâSmall InstallÐÂÎŰü£¬ÏòÊÜÓ°ÏìÉ豸µÄTCP 4786¶Ë¿Ú·¢Ë͸ÃÊý¾Ý°ü£¬³ÁÔØÖ¸±êÉ豸£¬Ôì³ÉÉ豸»Ø¾ø·þÎñ£¨DoS£©»òÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£
ÓÉÓÚ4786¶Ë¿ÚĬÈÏ¿ªÆô£¬ÇҸ÷ì϶pocÒѾ±»¹«¿ª£¬·ì϶·çÏÕˮƽ¼«¸ß¡£
¸Ã·ì϶´æÔÚÓÚÔËÐÐÁËCisco IOS/IOS EXÊÜÓ°Ïì°æ±¾Èí¼þ£¬ÇÒΪSmart Install ClientģʽµÄÉ豸¡£Î´¿ªÆôCisco Smart Install£¬»ò±»ÉèÖÃΪSmart Install DirectorģʽµÄÉ豸²»ÔÚÓ°ÏìÖ®ÁС£
Cisco QoSÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-0151£© ·çÏյȼ¶£º³¬Î£
¸Ã·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìÉ豸¶Ô´ïµ½ÆäUDP 18999¶Ë¿ÚµÄÊý¾Ý°üÖÐijЩֵµÄÌìǵ²é³²»µ±Ôì³ÉµÄ¡£¹¥»÷Õß¿Éͨ¹ýÏòÊÜÓ°ÏìÉ豸·¢ËͶñÒâ»ú¹ØµÄÊý¾Ý°üÀ´ÀûÓ÷ì϶£¬ÊÜÓ°ÏìÉ豸ÔÚ´¦ÖÃÊý¾Ý°üʱ¿ÉÄܲúÉú»º³åÇøÒç³ö£¬µ¼ÖÂÉ豸³ÁÔØ¡£¸Ã·ì϶ӰÏìËùÓÐÔËÐÐÁËCisco IOS/IOS EXÊÜÓ°Ïì°æ±¾Èí¼þµÄÉ豸¡£
Ŀǰ¹ú¼ÊÉÏ»òÐíÓжþÊ®ÍòÊÜÓ°ÏìÉ豸¶³öÔÚ¹«ÍøÉÏ£º
ÉÏÖÜ£¬Ò»¸öÃûΪ¡°JHT¡±µÄºÚ¿Í×éÖ¯ÀûÓÃ˼¿ÆCVE-2018-0171 ÖÇÄÜ×°Ö÷ì϶¹¥»÷ÁËÔ̺¬¶íÂÞ˹ºÍÒÁÀÊÔÚÄڵĶà¸ö¹ú¶ÈÍøÂç»ù´¡ÉèÊ©¡£±»¹¥»÷µÄCisco·ÓÉÆ÷µÄÅäÖÃÎļþstartup.config»á±»¸²¸Ç£¬Â·ÓÉÆ÷½«³ÁÐÂÆô¶¯¡£³ýÁ˵¼Ö´óÃæ»ýÍøÂçÖжÏÒÔ±í£¬ÖÎÀíÔ±»¹»á·¢ÏÖ·ÓÉÆ÷ÅäÖÃÎļþ±»¸ü¸Ä³É£º¡°Don't mess with our elections.... -JHT usafreedom_jht@tutanota.com¡±¡£
½ñÌ죬ÎÒÃÇÂ½ÐøÊÕµ½¶à¸ö¹úÄÚ»ú¹¹Ôâ·êͬÑùµÄ¹¥»÷µÄÐÂÎÅ¡£±»¹¥»÷µÄÉ豸³ý̱»¾±í£¬ÅäÖÃÎļþ»¹»áÏÔʾһ¸öÃÀ¹ú¹úÆì¡£
½â¾ö¹æ»®
1.Cisco¹Ù·½ÒѾ°ä²¼Á˸üв¹¶¡£¬£¬½¨ÒéÓйØÓû§¾¡¿ì¸üÐÂÉý¼¶¡££¨https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2£©
2.GA»Æ½ð¼×ÒÑÓÚ4ÔÂ4ÈÕÉý¼¶ÊÂÎñ¿â£¬ÊÂÎñÃû³Æ£ºTCP_Cisco_SmartInstall_Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2018-0171)£¬Çë¿í´óÓû§ÊµÊ±Éý¼¶¡£
ÌìãÙÈëÇÖ¼ì²âϵͳ±¨¾¯½ØÍ¼£º
ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º
ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º



¾©¹«Íø°²±¸11010802024551ºÅ