Cisco Small Business Switches ¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-01-22

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-15439£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½:8.1


Ó°ÏìÁìÓò


ÊÜÓ°Ïì²úÆ·£º

Cisco Small Business 200 Series Smart Switches

Cisco Small Business 300 Series Managed Switches

Cisco Small Business 500 Series Stackable Managed Switches

Cisco 250 Series Smart Switches

Cisco 350 Series Managed Switches

Cisco 350X Series Stackable Managed Switches

Cisco 550X Series Stackable Managed Switches 


²»ÊÜÓ°Ïì²úÆ·£º

Cisco 200E Series Smart Switches

Cisco 220 Series Smart Switches

ÒÔ¼°ÔËÐÐ˼¿ÆIOSÈí¼þ¡¢Ë¼¿ÆIOS XEÈí¼þ»ò˼¿ÆNX-OSÈí¼þµÄÉ豸


·ì϶¸ÅÊö


Cisco Small Business 200 Series Smart SwitchesµÈ¶¼ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÓ×ÐÍÖÇÄÜ»¥»»»úÉ豸¡£Small Business Switches SoftwareÊÇÒ»Ì×ÔËÐÐÔÚÆäÖеĻ¥»»»úÈí¼þ¡£ ¶à¿îCisco²úÆ·µÄSmall Business SwitchesÈí¼þ´æÔÚ°²È«·ì϶¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÈÆ¹ýÊÜÓ°ÏìµÄÉ豸µÄÓû§Éí·ÝÑéÖ¤»úÔì¡£


¸Ã·ì϶ÓëÉ豸ÉϵÄÌØÈ¨Óû§ÕË»§µÈĬÈÏÅäÖÃÓйØ¡£ÌØÈ¨Óû§ÕÊ»§ÊÇΪ³õʼµÇ¼¶ø´´½¨µÄ£¬Òò¶øÎÞ·¨´Ó˼¿ÆÓ×ÐÍóÒ×»¥»»»úÉ豸ÖÐɾ³ý¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


˼¿Æ°ä²¼µÄ¹«¸æÖÐÓÐÒ»¸ö½â¾ö¹æ»®£¬¼´ÔÚÉ豸ÅäÖÃÖÐÔö³¤Ò»¸öÓµÓÐ15¼¶½Ó¼ûȨÏÞ¼¶´ËÍâÓû§ÕÊ»§À´½ûÓÃÌØÈ¨ÕÊ»§¡£Óû§Äܹ»½«admin×÷ΪÓû§IDÀ´ÅäÖÃÐÂÕÊ»§£¬½«½Ó¼ûȨÏÞÉèÖÃΪ15¼¶£¬²¢ÓÃÒ»¸ö¸´ÔÓÃÜÂë´úÌæÇ¿ÃÜÂë¡£


Ŀǰ»¹Ã»Óзì϶²¹¶¡£¬µ«Ë¼¿ÆÕýÈ«Á¦½¨¸´·ì϶¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-sbsw-privacc

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15439