˼¿Æ¶à¿î²úÆ·ÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-20
Îó²î±àºÅ
CVE-2018-0376
CVE-2018-0377
CVE-2018-0374
CVE-2018-0375

µÈ25¸öÎó²î£¬£¬£¬¼ûÏÂÎÄÁÐ±í¡£¡£¡£¡£¡£¡£


Îó²î¼¶±ð
ÑÏÖØ

³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

Policy Suite¡¢SD-WAN¡¢WebEx ºÍ Nexus ²úÆ·


Îó²î¸ÅÊö

7ÔÂ18ÈÕ£¬£¬£¬Ë¼¿Æ¼û¸æ¿Í»§£¬£¬£¬ËüÒÑÔÚÆäPolicy Suite, SD-WAN, WebEx ºÍNexus²úÆ·Öз¢Ã÷²¢ÐÞ²¹ÁË25¸öÎó²î£¨4¸öcritical£¬£¬£¬9¸öhigh£¬£¬£¬12¸ömedium£©¡£¡£¡£¡£¡£¡£ÈçÏ£º


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


´Ó Policy Suite Öз¢Ã÷ËĸöÑÏÖØÈ±ÏÝ£¬£¬£¬ÆäÖÐÁ½¸öÇå¾²Îó²îÊÇδÈÏÖ¤»á¼ûȨÏÞÎÊÌ⣬£¬£¬¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õß»á¼û Policy Builder ½çÃæºÍ¿ª·ÅЧÀÍÍø¹Ø½¨Òé (OSGi) ½Ó¿Ú¡£¡£¡£¡£¡£¡£

CVE-2018-0376
Ò»µ©»ñµÃÓÉÓÚȱ·¦Éí·ÝÑéÖ¤¶øÌ»Â¶µÄPolicy Builder interfaceµÄ»á¼ûȨÏÞ£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔ¶ÔÏÖÓд洢¿â¾ÙÐиü¸Ä²¢½¨ÉèеĴ洢¿â¡£¡£¡£¡£¡£¡£ 
CVE-2018-0377
OSGi½Ó¿ÚÔÊÐí¹¥»÷Õß»á¼û»ò¸ü¸ÄOSGiÀú³Ì¿É»á¼ûµÄÈκÎÎļþ¡£¡£¡£¡£¡£¡£
CVE-2018-0374
ȱ·¦ÈÏÖ¤»úÖÆ»¹¿Éµ¼Ö Policy Builder Êý¾Ý¿âÔâ̻¶£¬£¬£¬´Ó¶øµ¼Ö¹¥»÷Õß»á¼û²¢¸ü¸Ä´æ´¢ÔÚÆäÖеÄÈκÎÊý¾Ý¡£¡£¡£¡£¡£¡£
CVE-2018-0375
Policy SuiteÖеÄCluster Manager±£´æÒ»¸ö¾ßÓÐĬÈÏ¡¢¾²Ì¬Æ¾Ö¤µÄrootÕÊ»§¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒԵǼ´ËÕÊ»§²¢Ê¹ÓÃrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£
˼¿Æ»¹ÐÞ¸´ÁË SD-WAN ½â¾ö¼Æ»®Öб£´æµÄÆß¸öÎó²î¡£¡£¡£¡£¡£¡£ÆäÖÐΨÖðÒ»¸öÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏÂÄÜÔâÔ¶³ÌʹÓõÄÎó²îÓ°Ïì Touch Provision ЧÀÍ£¬£¬£¬Ëü¿Éµ¼Ö¹¥»÷ÕßÒý·¢ DoS Ìõ¼þ¡£¡£¡£¡£¡£¡£
ÆäËüµÄ SD-WAN Çå¾²Îó²îÒªÇó¾ÙÐÐÈÏÖ¤£¬£¬£¬ÈçÔâʹÓ㬣¬£¬¿É¸²Ð´µ×²ã²Ù×÷ϵͳÉϵÄí§ÒâÎļþ²¢ÒÔ vmanage »ò¸ùȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£ÆäÖеÄÒ»¸ö SD-WAN Îó²îʹÓÃÒªÇóÈÏÖ¤ºÍÍâµØ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£
˼¿Æ»¹Í¨ÖªÏûºÄÕß³ÆÆä Nexus 9000 ϵÁÐµÄ Fabric ½»Á÷»ú£¬£¬£¬ÏêϸÊÇ DHCPv6 ¹¦Ð§£¬£¬£¬ËüÊÜÒ»¸ö¸ßΣȱÏÝÓ°Ï죬£¬£¬¿ÉÔâÔ¶³Ìδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÓÃÓÚÒý·¢ DoS Ìõ¼þ¡£¡£¡£¡£¡£¡£

˼¿Æ»¹½«¶à¸öÓ°Ïì˼¿Æ Webex Network Recording Player for AdvancedRecording Format (ARF) ºÍ WebexRecording Format (WRF) ÎļþµÄÎó²îÆÀΪ¸ßΣÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÈÃÄ¿µÄÓû§Ê¹ÓÃÊÜÓ°Ïì²¥·ÅÆ÷·­¿ªÌØÊâ½á¹¹µÄ ARF »ò WRF Îļþ¾ÍÄÜÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Ò飺

˼¿Æ¹Ù·½ÒѾ­Ðû²¼Ð°汾ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬Óû§Ó¦ÊµÊ±Éý¼¶¾ÙÐзÀ»¤¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó£º
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities
https://www.securityweek.com/cisco-finds-serious-flaws-policy-suite-sd-wan-products