Cisco ¶à¸ö°²È«·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-06-21·ì϶±àºÅºÍ¼¶±ð
CVE-2018-0301 ÑϳÁ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0304 ÑϳÁ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0308 ÑϳÁ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0312 ÑϳÁ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0314 ÑϳÁ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
·ì϶ӰÏìCisco FXOSÈí¼þºÍNX-OSÈí¼þ£¬Éæ¼°µÄ²úÆ·MDS¡¢Nexus¡¢Firepower¡¢UCS£¬¾ßÌå°æ±¾¼û·ì϶¸ÅÊö¡£
·ì϶¸ÅÊö
6ÔÂ20ÈÕ£¬Cisco¹Ù·½°ä²¼°²È«¹«¸æ½¨¸´Á˶à¸ö·ÖÆçˮƽµÄ°²È«·ì϶£¬ÆäÖÐÔ̺¬5¸öÑϳÁ·ì϶¡£ÓйØÁ´½Ó£º
https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-67770¡£
CVE-2018-0301 (Critical)
Cisco NX-OSÈí¼þµÄNX-APIÖ°ÄÜÖдæÔڵķì϶¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÏòÊÜÓ°ÏìϵͳµÄÖÎÀí½Ó¿Ú·¢ËͶñÒâÊý¾Ý°ü£¬´Ó¶øµ¼Ö»º³åÇøÒç³ö¡£
¸Ã·ì϶ÊÇÓÉÓÚNX-API×ÓϵͳµÄÉí·ÝÑé֤ģ¿éÖÐÊäÈëÑéÖ¤²»ÕýÈ·µ¼Öµġ£¹¥»÷ÕßÄܹ»Í¨¹ý½«¾«ÐÄ»ú¹ØµÄHTTP»òHTTPSÊý¾Ý°ü·¢Ë͵½ÆôÓÃÁËNX-APIÖ°ÄܵÄÊÜÓ°ÏìϵͳµÄÖÎÀí½çÃæÀ´ÀûÓô˷ì϶¡£¸Ã·ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßÒÔrootÉí·ÝÖ´ÐÐËÁÒâ´úÂë¡£°ÑÎÈ£ºNX-APIĬÈÏÊǽûÓõġ£
ÊÜÓ°Ïì²úÆ·¼°°æ±¾£º
ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´Ë·ì϶ӰÏ죺
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco NX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo#fs
CVE-2018-0304 (Critical)
Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄ·ì϶¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶ÁÈ¡Ãô¸ÐÄÚ´æÄÚÈÝ£¬´´Ôì»Ø¾ø·þÎñǰÌá»òÒÔrootÉí·ÝÖ´ÐÐËÁÒâ´úÂë¡£
´æÔÚ´Ë·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°ü±êÍ·¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËÍÌØÔìµÄCisco Fabric ServicesÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£Ò»´Î³É¹¦µÄ¹¥»÷¿ÉÄÜ»áÔÊÐí¹¥»÷ÕßÔÚCisco Fabric Services×é¼þÖе¼Ö»º³åÇøÒç³ö»ò»º³åÇø¹ý¶Á£¬Õâ¿ÉÄÜÔÊÐí¹¥»÷Õß¶ÁÈ¡Ãô¸ÐÄÚ´æÐÅÏ¢£¬´´Ôì»Ø¾ø·þÎñǰÌá»òÒÔrootÉí·ÝÖ´ÐÐËÁÒâ´úÂë¡£
ÊÜÓ°Ïì²úÆ·¼°°æ±¾£º
ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´Ë·ì϶ӰÏ죺
Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects
ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-ace#fs
CVE-2018-0308 (Critical)
Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄ·ì϶¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë»òµ¼Ö»ؾø·þÎñ¹¥»÷¡£
´æÔÚ´Ë·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°üÖеıêÍ·Öµ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËÍÌØÔìµÄCisco Fabric ServicesÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£Ò»´Î³É¹¦µÄ¹¥»÷¿ÉÄÜ»áÔì³É»º³åÇøÒç³ö£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»Ö´ÐÐËÁÒâ´úÂë»òµ¼ÖÂDoS¡£
ÊÜÓ°Ïì²úÆ·¼°°æ±¾£º
ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´Ë·ì϶ӰÏ죺
Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects
ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace#fs
CVE-2018-0312 (Critical)
Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄ·ì϶¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë»òÔÚÊÜÓ°ÏìµÄÉ豸Éϵ¼Ö»ؾø·þÎñ¹¥»÷¡£
´æÔÚ´Ë·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þÔÚ´¦ÖÃÊý¾Ý°üʱδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°ü±êÍ·¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâ»ú¹ØµÄCisco Fabric ServicesÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£Ò»´Î³É¹¦µÄ¹¥»÷¿ÉÄÜ»áÔÊÐí¹¥»÷ÕßÔÚÉ豸ÉÏÔì³É»º³åÇøÒç³ö£¬´Ó¶øÔÊÐí¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë»òÔÚÉ豸Éϵ¼Ö»ؾø·þÎñ¡£
ÊÜÓ°ÏìµÄ°æ±¾£º
ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´Ë·ì϶ӰÏ죺
Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects
ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-cli-execution#fs
CVE-2018-0314 (Critical)
Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄ·ì϶¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£
´æÔÚ´Ë·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þÔÚ´¦ÖÃÊý¾Ý°üʱδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°ü±êÍ·¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâ»ú¹ØµÄCisco Fabric ServicesÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£Ò»´Î³É¹¦µÄ¹¥»÷¿ÉÄÜ»áÔÊÐí¹¥»÷ÕßÔÚÉ豸ÉÏÔì³É»º³åÇøÒç³ö£¬´Ó¶øÔÊÐí¹¥»÷ÕßÔÚÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£
ÊÜÓ°ÏìµÄ°æ±¾£º
ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´Ë·ì϶ӰÏ죺
Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects
ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution#fs
½¨¸´½¨Ò飺
Éý¼¶ÖÁ²Î¿¼Á´½ÓÖÐÌáÐѵݲȫ°æ±¾¡£
²Î¿¼Á´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo#fs
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-ace#fs
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace#fs
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-cli-execution#fs
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution#fs


¾©¹«Íø°²±¸11010802024551ºÅ