Cisco SD-WAN Solution Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-01-25Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1651£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1648£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì²úÆ·£º
CVE-2019-1651£º
´ËÎó²î»áÓ°ÏìÔËÐÐCisco SD-WAN Solution 18.4.0֮ǰ°æ±¾µÄÒÔÏÂ˼¿Æ²úÆ·£º
vSmart Controller Software
CVE-2019-1648£º
´ËÎó²î»áÓ°ÏìÔËÐÐCisco SD-WAN Solution 18.4.0֮ǰ°æ±¾µÄÒÔÏÂ˼¿Æ²úÆ·£º
vBond Orchestrator Software
vEdge 100 Series Routers
vEdge 1000 Series Routers
vEdge 2000 Series Routers
vEdge 5000 Series Routers
vEdge Cloud Router Platform
vManage Network Management Software
vSmart Controller Software
Îó²î¸ÅÊö
Cisco vEdge 100 Series RoutersµÈ¶¼ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£¡£SD-WAN SolutionÊÇÔËÐÐÔÚÆäÖеÄÒ»Ì×ÍøÂçÀ©Õ¹½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£Cisco SD-WAN Solution 18.4.0֮ǰ°æ±¾Öб£´æÒÔÏÂÎó²î£¬£¬£¬£¬£¬£¬£¬ÏêÇéÈçÏ£º
CVE-2019-1651
˼¿ÆSD-WAN SolutionµÄvContainerÖеÄÎó²î¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßµ¼Ö¾ܾøÐ§ÀÍÌõ¼þ²¢ÒÔrootÓû§Éí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇÓÉvContainerµÄ²»×¼È·½çÏß¼ì²éÒýÆðµÄ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÎļþÀ´Ê¹ÓôËÎó²îÊÜÓ°ÏìµÄvContainerʵÀý¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓÿÉÒÔÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄvContainerÉϵ¼Ö»º³åÇøÒç³öÇéÐΣ¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö¹¥»÷Õß¿ÉÒÔʹÓÃDoSÌõ¼þÒÔrootÓû§Éí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
CVE-2019-1648
Cisco SD-WAN SolutionµÄÓû§×éÉèÖÃÖеÄÎó²î¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÍâµØ¹¥»÷Õß»ñµÃÊÜÓ°ÏìÉè±¹ØÁ¬ÄȨÏÞÌáÉý¡£¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇÓÉÓÚδÄÜ׼ȷÑé֤ijЩÎó²î×éÉèÖÃÖаüÀ¨µÄ²ÎÊý¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½«È«ÐÄÉè¼ÆµÄÎļþдÈëĿ¼À´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬Óû§×éÉèÖÃλÓڵײã²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£Àֳɹ¥»÷¿ÉÄÜÔÊÐí¹¥»÷Õß»ñµÃ¸ùroot ȨÏÞ²¢ÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-bo
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-sol-escal
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-bo
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-sol-escal