Cisco SD-WAN Solution ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-01-25

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1651£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-1648£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì²úÆ·£º

CVE-2019-1651£º


´Ë·ì϶»áÓ°ÏìÔËÐÐCisco SD-WAN Solution 18.4.0֮ǰ°æ±¾µÄÒÔÏÂ˼¿Æ²úÆ·£º

vSmart Controller Software


CVE-2019-1648£º


´Ë·ì϶»áÓ°ÏìÔËÐÐCisco SD-WAN Solution 18.4.0֮ǰ°æ±¾µÄÒÔÏÂ˼¿Æ²úÆ·£º

vBond Orchestrator Software

vEdge 100 Series Routers

vEdge 1000 Series Routers

vEdge 2000 Series Routers

vEdge 5000 Series Routers

vEdge Cloud Router Platform

vManage Network Management Software

vSmart Controller Software


·ì϶¸ÅÊö


Cisco vEdge 100 Series RoutersµÈ¶¼ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄ²úÆ·¡£SD-WAN SolutionÊÇÔËÐÐÔÚÆäÖеÄÒ»Ì×ÍøÂçÀ©´ó½â¾ö¹æ»®¡£Cisco SD-WAN Solution 18.4.0֮ǰ°æ±¾ÖдæÔÚÒÔÏ·ì϶£¬ÏêÇéÈçÏ£º


CVE-2019-1651


˼¿ÆSD-WAN SolutionµÄvContainerÖеķì϶¿ÉÄÜÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼Ö»ؾø·þÎñǰÌá²¢ÒÔrootÓû§Éí·ÝÖ´ÐÐËÁÒâ´úÂë¡£


¸Ã·ì϶ÊÇÓÉvContainerµÄ²»ÕýÈ·Ììǵ²é³­ÒýÆðµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâÎļþÀ´ÀûÓô˷ì϶ÊÜÓ°ÏìµÄvContainerÊ·ý¡£³É¹¦ÀûÓÃÄܹ»ÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄvContainerÉϵ¼Ö»º³åÇøÒç³öÇé¿ö£¬Õâ¿ÉÄܵ¼Ö¹¥»÷ÕßÄܹ»Ê¹ÓÃDoSǰÌáÒÔrootÓû§Éí·ÝÖ´ÐÐËÁÒâ´úÂë¡£


CVE-2019-1648


Cisco SD-WAN SolutionµÄÓû§×éÅäÖÃÖеķì϶¿ÉÄÜÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄ±¾µØ¹¥»÷Õß»ñµÃÊÜÓ°ÏìÉ豸ÉϵÄȨÏÞÌáÉý¡£


¸Ã·ì϶ÊÇÓÉÓÚδÄÜÕýÈ·Ñé֤ijЩ·ì϶×éÅäÖÃÖÐÔ̺¬µÄ²ÎÊý¡£¹¥»÷ÕßÄܹ»Í¨¹ý½«¾«ÐÄÉè¼ÆµÄÎļþдÈëĿ¼À´ÀûÓô˷ì϶£¬Óû§×éÅäÖÃλÓڵײã²Ù×÷ϵͳ¡£³É¹¦¹¥»÷¿ÉÄÜÔÊÐí¹¥»÷Õß»ñµÃ¸ùroot È¨ÏÞ²¢ÆëÈ«½ÚÔìÉ豸¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-bo

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-sol-escal


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-bo

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-sol-escal