˼¿Æ¶à¿î²úÆ·ÑϳÁ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-07-20CVE-2018-0376
CVE-2018-0377
CVE-2018-0374
CVE-2018-0375
µÈ25¸ö·ì϶£¬¼ûÏÂÎÄÁÐ±í¡£
ÑϳÁ
³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Policy Suite¡¢SD-WAN¡¢WebEx ºÍ Nexus ²úÆ·
7ÔÂ18ÈÕ£¬Ë¼¿Æ·î¸æ¿Í»§£¬ËüÒÑÔÚÆäPolicy Suite, SD-WAN, WebEx ºÍNexus²úÆ·Öз¢ÏÖ²¢½¨²¹ÁË25¸ö·ì϶£¨4¸öcritical£¬9¸öhigh£¬12¸ömedium£©¡£ÈçÏ£º
´Ó Policy Suite Öз¢ÏÖËĸöÑϳÁȱµã£¬ÆäÖÐÁ½¸ö°²È«·ì϶ÊÇδÈÏÖ¤½Ó¼ûȨÏÞÎÊÌ⣬¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õß½Ó¼û Policy Builder ½çÃæºÍÊ¢¿ª·þÎñÍø¹Ø½¨Òé (OSGi) ½Ó¿Ú¡£
CVE-2018-0376Ò»µ©»ñµÃÓÉÓÚ²»×ãÉí·ÝÑéÖ¤¶øÂ¶³öµÄPolicy Builder interfaceµÄ½Ó¼ûȨÏÞ£¬¹¥»÷Õß¾ÍÄܹ»¶ÔÏÖÓд洢¿â½øÐиü¸Ä²¢´´½¨ÐµĴ洢¿â¡£
CVE-2018-0377
OSGi½Ó¿ÚÔÊÐí¹¥»÷Õß½Ó¼û»ò¸ü¸ÄOSGi¹ý³Ì¿É½Ó¼ûµÄÈκÎÎļþ¡£
CVE-2018-0374
²»×ãÈÏÖ¤»úÔ컹¿Éµ¼Ö Policy Builder Êý¾Ý¿âÔâ¶³ö£¬´Ó¶øµ¼Ö¹¥»÷Õß½Ó¼û²¢¸ü¸Ä´æ´¢ÔÚÆäÖеÄÈκÎÊý¾Ý¡£
CVE-2018-0375
Policy SuiteÖеÄCluster Manager´æÔÚÒ»¸öÓµÓÐĬÈÏ¡¢¾²Ì¬Í´´¦µÄrootÕÊ»§¡£Ô¶³Ì¹¥»÷ÕßÄܹ»µÇ¼´ËÕÊ»§²¢Ê¹ÓÃrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£
˼¿Æ»¹½¨¸´ÁË SD-WAN ½â¾ö¹æ»®ÖдæÔÚµÄÆß¸ö·ì϶¡£ÆäÖÐΨÖðÒ»¸öÔÚÎÞÐèÈÏÖ¤µÄÇé¿öÏÂÄÜÔâÔ¶³ÌÀûÓõķì϶ӰÏì Touch Provision ·þÎñ£¬Ëü¿Éµ¼Ö¹¥»÷ÕßÒý·¢ DoS ǰÌá¡£
ÆäËüµÄ SD-WAN °²È«·ì϶ҪÇó½øÐÐÈÏÖ¤£¬ÈçÔâÀûÓ㬿ɸ²Ð´µ×²ã²Ù×÷ϵͳÉϵÄËÁÒâÎļþ²¢ÒÔ vmanage »ò¸ùȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£ÆäÖеÄÒ»¸ö SD-WAN ·ì϶ÀûÓÃÒªÇóÈÏÖ¤ºÍ±¾µØ½Ó¼ûȨÏÞ¡£
˼¿Æ»¹Í¨ÖªÏû·ÑÕß³ÆÆä Nexus 9000 ϵÁÐµÄ Fabric »¥»»»ú£¬¾ßÌåÊÇ DHCPv6 Ö°ÄÜ£¬ËüÊÜÒ»¸ö¸ßΣȱµãÓ°Ï죬¿ÉÔâÔ¶³Ìδ¾ÈÏÖ¤µÄ¹¥»÷ÕßÓÃÓÚÒý·¢ DoS ǰÌá¡£
˼¿Æ»¹½«¶à¸öÓ°Ïì˼¿Æ Webex Network Recording Player for AdvancedRecording Format (ARF) ºÍ WebexRecording Format (WRF) ÎļþµÄ·ì϶ÆÀΪ¸ßΣ·ì϶¡£¹¥»÷Õßͨ¹ýÈÃÖ¸±êÓû§Ê¹ÓÃÊÜÓ°Ïì²¥·ÅÆ÷´ò¿ª³ö¸ñ»ú¹ØµÄ ARF »ò WRF Îļþ¾ÍÄÜÖ´ÐÐËÁÒâ´úÂë¡£
˼¿Æ¹Ù·½ÒѾ°ä²¼Ð°汾½¨¸´ÁËÉÏÊö·ì϶£¬Óû§Ó¦ÊµÊ±Éý¼¶½øÐзÀ»¤¡£
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities
https://www.securityweek.com/cisco-finds-serious-flaws-policy-suite-sd-wan-products


¾©¹«Íø°²±¸11010802024551ºÅ