Cisco SMC¼°UEÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-11-09

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-15394 £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8 £¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-15381 £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8 £¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Cisco Stealthwatch Enterprise releases  <= 6.10.2

Cisco Unity Express release < 9.0.6


Îó²î¸ÅÊö


ÍâµØÊ±¼ä11ÔÂ7ÈÕ £¬£¬£¬Cisco¹Ù·½Ðû²¼Ç徲ͨ¸æ³ÆÐÞ¸´ÁËStealthwatch Management ConsoleÒÔ¼°Unity ExpressµÄ2¸öÑÏÖØÎó²î ¡£¡£¡£¡£¡£¡£¡£
CVE-2018-15394 £¬£¬£¬¸ÃÎó²îÔ´ÓÚϵͳÉèÖñ£´æÒþ»¼ £¬£¬£¬Ò»¸öδÊÚȨµÄ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÈÆ¹ýÑéÖ¤Á÷³Ì £¬£¬£¬´Ó¶øÊÜÓ°ÏìµÄϵͳÉÏÒÔÖÎÀíÔ±Éí·ÝÖ´ÐдúÂë ¡£¡£¡£¡£¡£¡£¡£

CVE-2018-15381 £¬£¬£¬¸ÃÎó²îÔ´ÓÚ¶ÔÓû§ÌṩµÄÄÚÈݾÙÐз´ÐòÁл¯²Ù×÷ÊÇûÓоÙÐÐ×ã¹»µÄ¹ýÂË ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÏòÊÜÓ°ÏìµÄϵͳRMIЧÀÍ·¢ËÍÒ»¸ö¶ñÒâµÄjavaÐòÁл¯¹¤¾ßÀ´´¥·¢¸ÃÎó²î £¬£¬£¬´Ó¶øÒÔrootȨÏÞÖ´ÐÐí§ÒâshellÏÂÁî ¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP


ÐÞ¸´½¨Òé


Cisco¹Ù·½ÒѾ­Ðû²¼ÁËа汾ÐÞ¸´ÁËÉÏÊöÎó²î £¬£¬£¬ÊÜÓ°ÏìµÄÓû§¿ÉÒÔÔڵǼºó»á¼ûhttps://stealthwatch.flexnetoperations.com/¾ÙÐиüР¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-smc-auth-bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-cue