˼¿Æ¶à¿î²úÆ·ÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-20
Îó²î±àºÅ
CVE-2018-0376
CVE-2018-0377
CVE-2018-0374
CVE-2018-0375

µÈ25¸öÎó²î£¬£¬£¬£¬£¬£¬£¬¼ûÏÂÎÄÁÐ±í¡£¡£ ¡£


Îó²î¼¶±ð
ÑÏÖØ

³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

Policy Suite¡¢SD-WAN¡¢WebEx ºÍ Nexus ²úÆ·


Îó²î¸ÅÊö

7ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬£¬Ë¼¿Æ¼û¸æ¿Í»§£¬£¬£¬£¬£¬£¬£¬ËüÒÑÔÚÆäPolicy Suite, SD-WAN, WebEx ºÍNexus²úÆ·Öз¢Ã÷²¢ÐÞ²¹ÁË25¸öÎó²î£¨4¸öcritical£¬£¬£¬£¬£¬£¬£¬9¸öhigh£¬£¬£¬£¬£¬£¬£¬12¸ömedium£©¡£¡£ ¡£ÈçÏ£º


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


´Ó Policy Suite Öз¢Ã÷ËĸöÑÏÖØÈ±ÏÝ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÁ½¸öÇå¾²Îó²îÊÇδÈÏÖ¤»á¼ûȨÏÞÎÊÌ⣬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õß»á¼û Policy Builder ½çÃæºÍ¿ª·ÅЧÀÍÍø¹Ø½¨Òé (OSGi) ½Ó¿Ú¡£¡£ ¡£

CVE-2018-0376
Ò»µ©»ñµÃÓÉÓÚȱ·¦Éí·ÝÑéÖ¤¶øÌ»Â¶µÄPolicy Builder interfaceµÄ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔ¶ÔÏÖÓд洢¿â¾ÙÐиü¸Ä²¢½¨ÉèеĴ洢¿â¡£¡£ ¡£ 
CVE-2018-0377
OSGi½Ó¿ÚÔÊÐí¹¥»÷Õß»á¼û»ò¸ü¸ÄOSGiÀú³Ì¿É»á¼ûµÄÈκÎÎļþ¡£¡£ ¡£
CVE-2018-0374
ȱ·¦ÈÏÖ¤»úÖÆ»¹¿Éµ¼Ö Policy Builder Êý¾Ý¿âÔâ̻¶£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¹¥»÷Õß»á¼û²¢¸ü¸Ä´æ´¢ÔÚÆäÖеÄÈκÎÊý¾Ý¡£¡£ ¡£
CVE-2018-0375
Policy SuiteÖеÄCluster Manager±£´æÒ»¸ö¾ßÓÐĬÈÏ¡¢¾²Ì¬Æ¾Ö¤µÄrootÕÊ»§¡£¡£ ¡£Ô¶³Ì¹¥»÷Õß¿ÉÒԵǼ´ËÕÊ»§²¢Ê¹ÓÃrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£ ¡£
˼¿Æ»¹ÐÞ¸´ÁË SD-WAN ½â¾ö¼Æ»®Öб£´æµÄÆß¸öÎó²î¡£¡£ ¡£ÆäÖÐΨÖðÒ»¸öÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏÂÄÜÔâÔ¶³ÌʹÓõÄÎó²îÓ°Ïì Touch Provision ЧÀÍ£¬£¬£¬£¬£¬£¬£¬Ëü¿Éµ¼Ö¹¥»÷ÕßÒý·¢ DoS Ìõ¼þ¡£¡£ ¡£
ÆäËüµÄ SD-WAN Çå¾²Îó²îÒªÇó¾ÙÐÐÈÏÖ¤£¬£¬£¬£¬£¬£¬£¬ÈçÔâʹÓ㬣¬£¬£¬£¬£¬£¬¿É¸²Ð´µ×²ã²Ù×÷ϵͳÉϵÄí§ÒâÎļþ²¢ÒÔ vmanage »ò¸ùȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£ ¡£ÆäÖеÄÒ»¸ö SD-WAN Îó²îʹÓÃÒªÇóÈÏÖ¤ºÍÍâµØ»á¼ûȨÏÞ¡£¡£ ¡£
˼¿Æ»¹Í¨ÖªÏûºÄÕß³ÆÆä Nexus 9000 ϵÁÐµÄ Fabric ½»Á÷»ú£¬£¬£¬£¬£¬£¬£¬ÏêϸÊÇ DHCPv6 ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ËüÊÜÒ»¸ö¸ßΣȱÏÝÓ°Ï죬£¬£¬£¬£¬£¬£¬¿ÉÔâÔ¶³Ìδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÓÃÓÚÒý·¢ DoS Ìõ¼þ¡£¡£ ¡£

˼¿Æ»¹½«¶à¸öÓ°Ïì˼¿Æ Webex Network Recording Player for AdvancedRecording Format (ARF) ºÍ WebexRecording Format (WRF) ÎļþµÄÎó²îÆÀΪ¸ßΣÎó²î¡£¡£ ¡£¹¥»÷Õßͨ¹ýÈÃÄ¿µÄÓû§Ê¹ÓÃÊÜÓ°Ïì²¥·ÅÆ÷·­¿ªÌØÊâ½á¹¹µÄ ARF »ò WRF Îļþ¾ÍÄÜÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£


ÐÞ¸´½¨Ò飺

˼¿Æ¹Ù·½ÒѾ­Ðû²¼Ð°汾ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬£¬£¬£¬Óû§Ó¦ÊµÊ±Éý¼¶¾ÙÐзÀ»¤¡£¡£ ¡£


²Î¿¼Á´½Ó£º
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities
https://www.securityweek.com/cisco-finds-serious-flaws-policy-suite-sd-wan-products