Cisco²úÆ·¶à¸öÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-09-06

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-0435£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.1£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-0423£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CVE-2018-0435´ËÎó²îÓ°ÏìCisco UmbrellaЧÀÍ¡£¡£¡£¡£¡£¡£¡£


CVE-2018-0423´ËÎó²î»áÓ°ÏìÒÔÏÂCisco²úÆ·µÄËùÓа汾£º
RV110W Wireless-N VPN·À»ðǽ
RV130W Wireless-N¶à¹¦Ð§VPN·ÓÉÆ÷

RV215W Wireless-N VPN·ÓÉÆ÷


Îó²î¸ÅÊö


CVE-2018-0435 £º
Cisco Umbrella APIÖб£´æµÄÎó²î¿ÉÄÜÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÉó²éºÍÐÞ¸ÄÆä×éÖ¯ºÍÆäËû×éÖ¯ÖеÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄ±¬·¢ÊÇÓÉÓÚCisco Umbrella API½Ó¿ÚµÄÉí·ÝÑéÖ¤ÉèÖÃȱ·¦¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄÜÔÊÐí¹¥»÷Õß¿ç¶à¸ö×éÖ¯¶ÁÈ¡»òÐÞ¸ÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£


CVE-2018-0423 £º
Cisco RV110W Wireless-N VPN·À»ðǽ¡¢Cisco RV130W Wireless-N¶à¹¦Ð§VPN·ÓÉÆ÷ºÍCisco RV215W Wireless-N VPN·ÓÉÆ÷µÄWebÖÎÀí½çÃæÖб£´æµÄÎó²î¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼Ö¾ܾøÐ§À͹¥»÷»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚWebÖÎÀí½çÃæµÄGuestÓû§¹¦Ð§ÖжÔÓû§ÌṩµÄÊäÈë½çÏßÏÞÖÆ²»µ±Ôì³ÉµÄ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄ×°±¸·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬´Ó¶ø´¥·¢»º³åÇøÒç³ö¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄÜÔÊÐí¹¥»÷Õßʹװ±¸×èÖ¹ÏìÓ¦£¬£¬£¬£¬µ¼Ö¾ܾøÐ§À͹¥»÷£¬£¬£¬£¬»òÕßÔÊÐí¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


CVE-2018-0435 £º
˼¿ÆÒѾ­ÔÚCisco Umbrella production APIÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£ÎÞÐèÓû§²Ù×÷À´Ó¦Óò¹¶¡¡£¡£¡£¡£¡£¡£¡£
CVE-2018-0423 £º
¹ØÓÚCisco RV130W Wireless-N¶à¹¦Ð§VPN·ÓÉÆ÷£¬£¬£¬£¬Ë¼¿ÆÐû²¼ÁËÃâ·ÑµÄ¹Ì¼þ¸üУ¬£¬£¬£¬¿Í»§¿ÉÒÔͨ¹ýCisco.comÉϵÄÈí¼þÖÐÐÄÏÂÔØ¹Ì¼þ¸üÐÂhttps://software.cisco.com/download/home
¹ØÓÚCisco RV110W Wireless-N VPN·À»ðǽºÍCisco RV215W Wireless-N VPN·ÓÉÆ÷£¬£¬£¬£¬Ë¼¿ÆÉÐδÐû²¼²¢ÇÒ²»»áÐû²¼½â¾ö¸ÃÎó²îµÄ¹Ì¼þ¸üС£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-umbrella-api
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-rv-routers-overflow
https://www.zdnet.com/article/cisco-warns-customers-of-critical-security-flaws-advisory-includes-apache-struts/