Cisco²úÆ·¶à¸öÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-09-06

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-0435 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.1 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-0423 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CVE-2018-0435´Ë·ì϶ӰÏìCisco Umbrella·þÎñ¡£


CVE-2018-0423´Ë·ì϶»áÓ°ÏìÒÔÏÂCisco²úÆ·µÄËùÓа汾£º
RV110W Wireless-N VPN·À»ðǽ
RV130W Wireless-N¶àÖ°ÄÜVPN·ÓÉÆ÷

RV215W Wireless-N VPN·ÓÉÆ÷


·ì϶¸ÅÊö


CVE-2018-0435 £º
Cisco Umbrella APIÖдæÔڵķì϶¿ÉÄÜÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õ߲鿴ºÍÅú¸ÄÆä×éÖ¯ºÍÆäËû×éÖ¯ÖеÄÊý¾Ý¡£¸Ã·ì϶µÄ²úÉúÊÇÓÉÓÚCisco Umbrella API½Ó¿ÚµÄÉí·ÝÑéÖ¤ÅäÖò»¼°¡£³É¹¦ÀûÓø÷ì϶¿ÉÄÜÔÊÐí¹¥»÷Õß¿ç¶à¸ö×éÖ¯¶ÁÈ¡»òÅú¸ÄÊý¾Ý¡£


CVE-2018-0423 £º
Cisco RV110W Wireless-N VPN·À»ðǽ¡¢Cisco RV130W Wireless-N¶àÖ°ÄÜVPN·ÓÉÆ÷ºÍCisco RV215W Wireless-N VPN·ÓÉÆ÷µÄWebÖÎÀí½çÃæÖдæÔڵķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼Ö»ؾø·þÎñ¹¥»÷»òÖ´ÐÐËÁÒâ´úÂë¡£¸Ã·ì϶ÊÇÓÉÓÚWebÖÎÀí½çÃæµÄGuestÓû§Ö°ÄÜÖжÔÓû§ÌṩµÄÊäÈëÌìǵÏ޶Ȳ»µ±Ôì³ÉµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êÉ豸·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶ £¬´Ó¶ø´¥·¢»º³åÇøÒç³ö¡£³É¹¦ÀûÓø÷ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßʹÉ豸ÖÕ³¡ÏìÓ¦ £¬µ¼Ö»ؾø·þÎñ¹¥»÷ £¬»òÕßÔÊÐí¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£


½¨¸´½¨Òé


CVE-2018-0435 £º
˼¿ÆÒѾ­ÔÚCisco Umbrella production APIÖн¨¸´Á˸÷ì϶¡£ÎÞÐèÓû§²Ù×÷À´ÀûÓò¹¶¡¡£
CVE-2018-0423 £º
¶ÔÓÚCisco RV130W Wireless-N¶àÖ°ÄÜVPN·ÓÉÆ÷ £¬Ë¼¿Æ°ä²¼ÁËÃâ·ÑµÄ¹Ì¼þ¸üР£¬¿Í»§Äܹ»Í¨¹ýCisco.comÉϵÄÈí¼þÖÐÐÄÏÂÔØ¹Ì¼þ¸üÐÂhttps://software.cisco.com/download/home
¶ÔÓÚCisco RV110W Wireless-N VPN·À»ðǽºÍCisco RV215W Wireless-N VPN·ÓÉÆ÷ £¬Ë¼¿ÆÉÐδ°ä²¼²¢ÇÒ²»»á°ä²¼½â¾ö¸Ã·ì϶µÄ¹Ì¼þ¸üС£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-umbrella-api
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-rv-routers-overflow
https://www.zdnet.com/article/cisco-warns-customers-of-critical-security-flaws-advisory-includes-apache-struts/