Cisco SMC¼°UEÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-11-09

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-15394£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-15381£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Cisco Stealthwatch Enterprise releases  <= 6.10.2

Cisco Unity Express release < 9.0.6


·ì϶¸ÅÊö


±¾µØ¹¦·ò11ÔÂ7ÈÕ£¬Cisco¹Ù·½°ä²¼°²È«¹«¸æ³Æ½¨¸´ÁËStealthwatch Management ConsoleÒÔ¼°Unity ExpressµÄ2¸öÑϳÁ·ì϶ ¡£
CVE-2018-15394£¬¸Ã·ì϶ԴÓÚϵͳÅäÖôæÔÚÒþ»¼£¬Ò»¸öδÊÚȨµÄ¹¥»÷ÕßÄܹ»Ô¶³ÌÈÆ¹ýÑéÖ¤Á÷³Ì£¬´Ó¶øÊÜÓ°ÏìµÄϵͳÉÏÒÔÖÎÀíÔ±Éí·ÝÖ´ÐдúÂë ¡£

CVE-2018-15381£¬¸Ã·ì϶ԴÓÚ¶ÔÓû§ÌṩµÄÄÚÈݽøÐз´ÐòÁл¯²Ù×÷ÊÇûÓнøÐÐ×ã¹»µÄ¹ýÂË ¡£¹¥»÷ÕßÄܹ»ÏòÊÜÓ°ÏìµÄϵͳRMI·þÎñ·¢ËÍÒ»¸ö¶ñÒâµÄjavaÐòÁл¯¶ÔÏóÀ´´¥·¢¸Ã·ì϶£¬´Ó¶øÒÔrootȨÏÞÖ´ÐÐËÁÒâshellºÅÁî ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP


½¨¸´½¨Òé


Cisco¹Ù·½ÒѾ­°ä²¼ÁËа汾½¨¸´ÁËÉÏÊö·ì϶£¬ÊÜÓ°ÏìµÄÓû§Äܹ»ÔڵǼºó½Ó¼ûhttps://stealthwatch.flexnetoperations.com/½øÐиüР¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-smc-auth-bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-cue