Cisco ¶à¸ö°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-21

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-0301  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0304  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0308  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0312  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0314  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


·ì϶ӰÏìCisco FXOSÈí¼þºÍNX-OSÈí¼þ£¬Éæ¼°µÄ²úÆ·MDS¡¢Nexus¡¢Firepower¡¢UCS£¬¾ßÌå°æ±¾¼û·ì϶¸ÅÊö¡£


·ì϶¸ÅÊö


6ÔÂ20ÈÕ£¬Cisco¹Ù·½°ä²¼°²È«¹«¸æ½¨¸´Á˶à¸ö·ÖÆçˮƽµÄ°²È«·ì϶£¬ÆäÖÐÔ̺¬5¸öÑϳÁ·ì϶¡£ÓйØÁ´½Ó£º

https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-67770¡£

 

CVE-2018-0301 (Critical)


Cisco NX-OSÈí¼þµÄNX-APIÖ°ÄÜÖдæÔڵķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÏòÊÜÓ°ÏìϵͳµÄÖÎÀí½Ó¿Ú·¢ËͶñÒâÊý¾Ý°ü£¬´Ó¶øµ¼Ö»º³åÇøÒç³ö¡£


¸Ã·ì϶ÊÇÓÉÓÚNX-API×ÓϵͳµÄÉí·ÝÑé֤ģ¿éÖÐÊäÈëÑéÖ¤²»ÕýÈ·µ¼ÖµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ý½«¾«ÐÄ»ú¹ØµÄHTTP»òHTTPSÊý¾Ý°ü·¢Ë͵½ÆôÓÃÁËNX-APIÖ°ÄܵÄÊÜÓ°ÏìϵͳµÄÖÎÀí½çÃæÀ´ÀûÓô˷ì϶¡£¸Ã·ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßÒÔrootÉí·ÝÖ´ÐÐËÁÒâ´úÂë¡£°ÑÎÈ£ºNX-APIĬÈÏÊǽûÓõÄ¡£


ÊÜÓ°Ïì²úÆ·¼°°æ±¾£º


ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´Ë·ì϶ӰÏ죺


MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules


ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco NX-OSÈí¼þ°æ±¾Ïê¼û £º


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo#fs


CVE-2018-0304 (Critical)


Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄ·ì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶ÁÈ¡Ãô¸ÐÄÚ´æÄÚÈÝ£¬´´Ôì»Ø¾ø·þÎñǰÌá»òÒÔrootÉí·ÝÖ´ÐÐËÁÒâ´úÂë¡£


´æÔÚ´Ë·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°ü±êÍ·¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËÍÌØÔìµÄCisco Fabric ServicesÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£Ò»´Î³É¹¦µÄ¹¥»÷¿ÉÄÜ»áÔÊÐí¹¥»÷ÕßÔÚCisco Fabric Services×é¼þÖе¼Ö»º³åÇøÒç³ö»ò»º³åÇø¹ý¶Á£¬Õâ¿ÉÄÜÔÊÐí¹¥»÷Õß¶ÁÈ¡Ãô¸ÐÄÚ´æÐÅÏ¢£¬´´Ôì»Ø¾ø·þÎñǰÌá»òÒÔrootÉí·ÝÖ´ÐÐËÁÒâ´úÂë¡£

ÊÜÓ°Ïì²úÆ·¼°°æ±¾£º


ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´Ë·ì϶ӰÏ죺

Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects

ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-ace#fs

CVE-2018-0308 (Critical)

Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄ·ì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë»òµ¼Ö»ؾø·þÎñ¹¥»÷¡£


´æÔÚ´Ë·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°üÖеıêÍ·Öµ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËÍÌØÔìµÄCisco Fabric ServicesÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£Ò»´Î³É¹¦µÄ¹¥»÷¿ÉÄÜ»áÔì³É»º³åÇøÒç³ö£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»Ö´ÐÐËÁÒâ´úÂë»òµ¼ÖÂDoS¡£


ÊÜÓ°Ïì²úÆ·¼°°æ±¾£º

ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´Ë·ì϶ӰÏ죺


Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects


ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace#fs

CVE-2018-0312 (Critical)


Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄ·ì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë»òÔÚÊÜÓ°ÏìµÄÉ豸Éϵ¼Ö»ؾø·þÎñ¹¥»÷¡£


´æÔÚ´Ë·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þÔÚ´¦ÖÃÊý¾Ý°üʱδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°ü±êÍ·¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâ»ú¹ØµÄCisco Fabric ServicesÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£Ò»´Î³É¹¦µÄ¹¥»÷¿ÉÄÜ»áÔÊÐí¹¥»÷ÕßÔÚÉ豸ÉÏÔì³É»º³åÇøÒç³ö£¬´Ó¶øÔÊÐí¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë»òÔÚÉ豸Éϵ¼Ö»ؾø·þÎñ¡£

ÊÜÓ°ÏìµÄ°æ±¾£º


ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´Ë·ì϶ӰÏ죺


Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects


ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-cli-execution#fs

CVE-2018-0314 (Critical)


Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄ·ì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£


´æÔÚ´Ë·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þÔÚ´¦ÖÃÊý¾Ý°üʱδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°ü±êÍ·¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâ»ú¹ØµÄCisco Fabric ServicesÊý¾Ý°üÀ´ÀûÓô˷ì϶¡£Ò»´Î³É¹¦µÄ¹¥»÷¿ÉÄÜ»áÔÊÐí¹¥»÷ÕßÔÚÉ豸ÉÏÔì³É»º³åÇøÒç³ö£¬´Ó¶øÔÊÐí¹¥»÷ÕßÔÚÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£


ÊÜÓ°ÏìµÄ°æ±¾£º


ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´Ë·ì϶ӰÏ죺


Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects


ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution#fs

½¨¸´½¨Ò飺

Éý¼¶ÖÁ²Î¿¼Á´½ÓÖÐÌáÐѵݲȫ°æ±¾¡£

²Î¿¼Á´½Ó£º


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo#fs


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-ace#fs


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace#fs


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-cli-execution#fs


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution#fs