˼¿Æ¶à¿î²úÆ·ÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-20
Îó²î±àºÅ
CVE-2018-0376
CVE-2018-0377
CVE-2018-0374
CVE-2018-0375

µÈ25¸öÎó²î£¬£¬£¬£¬¼ûÏÂÎÄÁбí¡£¡£¡£


Îó²î¼¶±ð
ÑÏÖØ

³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

Policy Suite¡¢SD-WAN¡¢WebEx ºÍ Nexus ²úÆ·


Îó²î¸ÅÊö

7ÔÂ18ÈÕ£¬£¬£¬£¬Ë¼¿Æ¼û¸æ¿Í»§£¬£¬£¬£¬ËüÒÑÔÚÆäPolicy Suite, SD-WAN, WebEx ºÍNexus²úÆ·Öз¢Ã÷²¢ÐÞ²¹ÁË25¸öÎó²î£¨4¸öcritical£¬£¬£¬£¬9¸öhigh£¬£¬£¬£¬12¸ömedium£©¡£¡£¡£ÈçÏ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


´Ó Policy Suite Öз¢Ã÷ËĸöÑÏÖØÈ±ÏÝ£¬£¬£¬£¬ÆäÖÐÁ½¸öÇå¾²Îó²îÊÇδÈÏÖ¤»á¼ûȨÏÞÎÊÌ⣬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õß»á¼û Policy Builder ½çÃæºÍ¿ª·ÅЧÀÍÍø¹Ø½¨Òé (OSGi) ½Ó¿Ú¡£¡£¡£

CVE-2018-0376
Ò»µ©»ñµÃÓÉÓÚȱ·¦Éí·ÝÑéÖ¤¶øÌ»Â¶µÄPolicy Builder interfaceµÄ»á¼ûȨÏÞ£¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔ¶ÔÏÖÓд洢¿â¾ÙÐиü¸Ä²¢½¨ÉèеĴ洢¿â¡£¡£¡£ 
CVE-2018-0377
OSGi½Ó¿ÚÔÊÐí¹¥»÷Õß»á¼û»ò¸ü¸ÄOSGiÀú³Ì¿É»á¼ûµÄÈκÎÎļþ¡£¡£¡£
CVE-2018-0374
ȱ·¦ÈÏÖ¤»úÖÆ»¹¿Éµ¼Ö Policy Builder Êý¾Ý¿âÔâ̻¶£¬£¬£¬£¬´Ó¶øµ¼Ö¹¥»÷Õß»á¼û²¢¸ü¸Ä´æ´¢ÔÚÆäÖеÄÈκÎÊý¾Ý¡£¡£¡£
CVE-2018-0375
Policy SuiteÖеÄCluster Manager±£´æÒ»¸ö¾ßÓÐĬÈÏ¡¢¾²Ì¬Æ¾Ö¤µÄrootÕÊ»§¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒԵǼ´ËÕÊ»§²¢Ê¹ÓÃrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£
˼¿Æ»¹ÐÞ¸´ÁË SD-WAN ½â¾ö¼Æ»®Öб£´æµÄÆß¸öÎó²î¡£¡£¡£ÆäÖÐΨÖðÒ»¸öÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏÂÄÜÔâÔ¶³ÌʹÓõÄÎó²îÓ°Ïì Touch Provision ЧÀÍ£¬£¬£¬£¬Ëü¿Éµ¼Ö¹¥»÷ÕßÒý·¢ DoS Ìõ¼þ¡£¡£¡£
ÆäËüµÄ SD-WAN Çå¾²Îó²îÒªÇó¾ÙÐÐÈÏÖ¤£¬£¬£¬£¬ÈçÔâʹÓ㬣¬£¬£¬¿É¸²Ð´µ×²ã²Ù×÷ϵͳÉϵÄí§ÒâÎļþ²¢ÒÔ vmanage »ò¸ùȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£ÆäÖеÄÒ»¸ö SD-WAN Îó²îʹÓÃÒªÇóÈÏÖ¤ºÍÍâµØ»á¼ûȨÏÞ¡£¡£¡£
˼¿Æ»¹Í¨ÖªÏûºÄÕß³ÆÆä Nexus 9000 ϵÁÐµÄ Fabric ½»Á÷»ú£¬£¬£¬£¬ÏêϸÊÇ DHCPv6 ¹¦Ð§£¬£¬£¬£¬ËüÊÜÒ»¸ö¸ßΣȱÏÝÓ°Ï죬£¬£¬£¬¿ÉÔâÔ¶³Ìδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÓÃÓÚÒý·¢ DoS Ìõ¼þ¡£¡£¡£

˼¿Æ»¹½«¶à¸öÓ°Ïì˼¿Æ Webex Network Recording Player for AdvancedRecording Format (ARF) ºÍ WebexRecording Format (WRF) ÎļþµÄÎó²îÆÀΪ¸ßΣÎó²î¡£¡£¡£¹¥»÷Õßͨ¹ýÈÃÄ¿µÄÓû§Ê¹ÓÃÊÜÓ°Ïì²¥·ÅÆ÷·­¿ªÌØÊâ½á¹¹µÄ ARF »ò WRF Îļþ¾ÍÄÜÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


ÐÞ¸´½¨Ò飺

˼¿Æ¹Ù·½ÒѾ­Ðû²¼Ð°汾ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬Óû§Ó¦ÊµÊ±Éý¼¶¾ÙÐзÀ»¤¡£¡£¡£


²Î¿¼Á´½Ó£º
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities
https://www.securityweek.com/cisco-finds-serious-flaws-policy-suite-sd-wan-products