˼¿Æ¶à¿î²úÆ·ÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-07-20
·ì϶±àºÅ
CVE-2018-0376
CVE-2018-0377
CVE-2018-0374
CVE-2018-0375

µÈ25¸ö·ì϶£¬¼ûÏÂÎÄÁбí¡£


·ì϶¼¶±ð
ÑϳÁ

³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

Policy Suite¡¢SD-WAN¡¢WebEx ºÍ Nexus ²úÆ·


·ì϶¸ÅÊö

7ÔÂ18ÈÕ£¬Ë¼¿Æ·î¸æ¿Í»§£¬ËüÒÑÔÚÆäPolicy Suite, SD-WAN, WebEx ºÍNexus²úÆ·Öз¢ÏÖ²¢½¨²¹ÁË25¸ö·ì϶£¨4¸öcritical£¬9¸öhigh£¬12¸ömedium£©¡£ÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´Ó Policy Suite Öз¢ÏÖËĸöÑϳÁȱµã£¬ÆäÖÐÁ½¸ö°²È«·ì϶ÊÇδÈÏÖ¤½Ó¼ûȨÏÞÎÊÌ⣬¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õß½Ó¼û Policy Builder ½çÃæºÍÊ¢¿ª·þÎñÍø¹Ø½¨Òé (OSGi) ½Ó¿Ú¡£

CVE-2018-0376
Ò»µ©»ñµÃÓÉÓÚ²»×ãÉí·ÝÑéÖ¤¶øÂ¶³öµÄPolicy Builder interfaceµÄ½Ó¼ûȨÏÞ£¬¹¥»÷Õß¾ÍÄܹ»¶ÔÏÖÓд洢¿â½øÐиü¸Ä²¢´´½¨ÐµĴ洢¿â¡£ 
CVE-2018-0377
OSGi½Ó¿ÚÔÊÐí¹¥»÷Õß½Ó¼û»ò¸ü¸ÄOSGi¹ý³Ì¿É½Ó¼ûµÄÈκÎÎļþ¡£
CVE-2018-0374
²»×ãÈÏÖ¤»úÔ컹¿Éµ¼Ö Policy Builder Êý¾Ý¿âÔâ¶³ö£¬´Ó¶øµ¼Ö¹¥»÷Õß½Ó¼û²¢¸ü¸Ä´æ´¢ÔÚÆäÖеÄÈκÎÊý¾Ý¡£
CVE-2018-0375
Policy SuiteÖеÄCluster Manager´æÔÚÒ»¸öÓµÓÐĬÈÏ¡¢¾²Ì¬Í´´¦µÄrootÕÊ»§¡£Ô¶³Ì¹¥»÷ÕßÄܹ»µÇ¼´ËÕÊ»§²¢Ê¹ÓÃrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£
˼¿Æ»¹½¨¸´ÁË SD-WAN ½â¾ö¹æ»®ÖдæÔÚµÄÆß¸ö·ì϶¡£ÆäÖÐΨÖðÒ»¸öÔÚÎÞÐèÈÏÖ¤µÄÇé¿öÏÂÄÜÔâÔ¶³ÌÀûÓõķì϶ӰÏì Touch Provision ·þÎñ£¬Ëü¿Éµ¼Ö¹¥»÷ÕßÒý·¢ DoS ǰÌá¡£
ÆäËüµÄ SD-WAN °²È«·ì϶ҪÇó½øÐÐÈÏÖ¤£¬ÈçÔâÀûÓ㬿ɸ²Ð´µ×²ã²Ù×÷ϵͳÉϵÄËÁÒâÎļþ²¢ÒÔ vmanage »ò¸ùȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£ÆäÖеÄÒ»¸ö SD-WAN ·ì϶ÀûÓÃÒªÇóÈÏÖ¤ºÍ±¾µØ½Ó¼ûȨÏÞ¡£
˼¿Æ»¹Í¨ÖªÏû·ÑÕß³ÆÆä Nexus 9000 ϵÁÐµÄ Fabric »¥»»»ú£¬¾ßÌåÊÇ DHCPv6 Ö°ÄÜ£¬ËüÊÜÒ»¸ö¸ßΣȱµãÓ°Ï죬¿ÉÔâÔ¶³Ìδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÓÃÓÚÒý·¢ DoS ǰÌá¡£

˼¿Æ»¹½«¶à¸öÓ°Ïì˼¿Æ Webex Network Recording Player for AdvancedRecording Format (ARF) ºÍ WebexRecording Format (WRF) ÎļþµÄ·ì϶ÆÀΪ¸ßΣ·ì϶¡£¹¥»÷Õßͨ¹ýÈÃÖ¸±êÓû§Ê¹ÓÃÊÜÓ°Ïì²¥·ÅÆ÷´ò¿ª³ö¸ñ»ú¹ØµÄ ARF »ò WRF Îļþ¾ÍÄÜÖ´ÐÐËÁÒâ´úÂë¡£


½¨¸´½¨Ò飺

˼¿Æ¹Ù·½ÒѾ­°ä²¼Ð°汾½¨¸´ÁËÉÏÊö·ì϶£¬Óû§Ó¦ÊµÊ±Éý¼¶½øÐзÀ»¤¡£


²Î¿¼Á´½Ó£º
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities
https://www.securityweek.com/cisco-finds-serious-flaws-policy-suite-sd-wan-products