Cisco²úÆ·¶à¸öÑϳÁ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-09-06·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-0423£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
CVE-2018-0423´Ë·ì϶»áÓ°ÏìÒÔÏÂCisco²úÆ·µÄËùÓа汾£º
RV110W Wireless-N VPN·À»ðǽ
RV130W Wireless-N¶àÖ°ÄÜVPN·ÓÉÆ÷
RV215W Wireless-N VPN·ÓÉÆ÷
·ì϶¸ÅÊö
Cisco Umbrella APIÖдæÔڵķì϶¿ÉÄÜÔÊÐí¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õ߲鿴ºÍÅú¸ÄÆä×éÖ¯ºÍÆäËû×éÖ¯ÖеÄÊý¾Ý¡£¸Ã·ì϶µÄ²úÉúÊÇÓÉÓÚCisco Umbrella API½Ó¿ÚµÄÉí·ÝÑéÖ¤ÅäÖò»¼°¡£³É¹¦ÀûÓø÷ì϶¿ÉÄÜÔÊÐí¹¥»÷Õß¿ç¶à¸ö×éÖ¯¶ÁÈ¡»òÅú¸ÄÊý¾Ý¡£
CVE-2018-0423 £º
Cisco RV110W Wireless-N VPN·À»ðǽ¡¢Cisco RV130W Wireless-N¶àÖ°ÄÜVPN·ÓÉÆ÷ºÍCisco RV215W Wireless-N VPN·ÓÉÆ÷µÄWebÖÎÀí½çÃæÖдæÔڵķì϶¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼Ö»ؾø·þÎñ¹¥»÷»òÖ´ÐÐËÁÒâ´úÂë¡£¸Ã·ì϶ÊÇÓÉÓÚWebÖÎÀí½çÃæµÄGuestÓû§Ö°ÄÜÖжÔÓû§ÌṩµÄÊäÈëÌìǵÏ޶Ȳ»µ±Ôì³ÉµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êÉ豸·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶£¬´Ó¶ø´¥·¢»º³åÇøÒç³ö¡£³É¹¦ÀûÓø÷ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßʹÉ豸ÖÕ³¡ÏìÓ¦£¬µ¼Ö»ؾø·þÎñ¹¥»÷£¬»òÕßÔÊÐí¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£
½¨¸´½¨Òé
˼¿ÆÒѾÔÚCisco Umbrella production APIÖн¨¸´Á˸÷ì϶¡£ÎÞÐèÓû§²Ù×÷À´ÀûÓò¹¶¡¡£
CVE-2018-0423 £º
¶ÔÓÚCisco RV130W Wireless-N¶àÖ°ÄÜVPN·ÓÉÆ÷£¬Ë¼¿Æ°ä²¼ÁËÃâ·ÑµÄ¹Ì¼þ¸üУ¬¿Í»§Äܹ»Í¨¹ýCisco.comÉϵÄÈí¼þÖÐÐÄÏÂÔØ¹Ì¼þ¸üÐÂhttps://software.cisco.com/download/home
¶ÔÓÚCisco RV110W Wireless-N VPN·À»ðǽºÍCisco RV215W Wireless-N VPN·ÓÉÆ÷£¬Ë¼¿ÆÉÐδ°ä²¼²¢ÇÒ²»»á°ä²¼½â¾ö¸Ã·ì϶µÄ¹Ì¼þ¸üС£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-rv-routers-overflow
https://www.zdnet.com/article/cisco-warns-customers-of-critical-security-flaws-advisory-includes-apache-struts/


¾©¹«Íø°²±¸11010802024551ºÅ