˼¿Æ¶à¿î²úÆ·ÑϳÁ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-07-20CVE-2018-0376
CVE-2018-0377
CVE-2018-0374
CVE-2018-0375
µÈ25¸ö·ì϶£¬£¬£¬£¬£¬¼ûÏÂÎÄÁÐ±í¡£¡£¡£¡£¡£¡£¡£¡£
ÑϳÁ
³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Policy Suite¡¢SD-WAN¡¢WebEx ºÍ Nexus ²úÆ·
7ÔÂ18ÈÕ£¬£¬£¬£¬£¬Ë¼¿Æ·î¸æ¿Í»§£¬£¬£¬£¬£¬ËüÒÑÔÚÆäPolicy Suite, SD-WAN, WebEx ºÍNexus²úÆ·Öз¢ÏÖ²¢½¨²¹ÁË25¸ö·ì϶£¨4¸öcritical£¬£¬£¬£¬£¬9¸öhigh£¬£¬£¬£¬£¬12¸ömedium£©¡£¡£¡£¡£¡£¡£¡£¡£ÈçÏ£º
´Ó Policy Suite Öз¢ÏÖËĸöÑϳÁȱµã£¬£¬£¬£¬£¬ÆäÖÐÁ½¸ö°²È«·ì϶ÊÇδÈÏÖ¤½Ó¼ûȨÏÞÎÊÌ⣬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õß½Ó¼û Policy Builder ½çÃæºÍÊ¢¿ª·þÎñÍø¹Ø½¨Òé (OSGi) ½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2018-0376Ò»µ©»ñµÃÓÉÓÚ²»×ãÉí·ÝÑéÖ¤¶øÂ¶³öµÄPolicy Builder interfaceµÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÄܹ»¶ÔÏÖÓд洢¿â½øÐиü¸Ä²¢´´½¨ÐµĴ洢¿â¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2018-0377
OSGi½Ó¿ÚÔÊÐí¹¥»÷Õß½Ó¼û»ò¸ü¸ÄOSGi¹ý³Ì¿É½Ó¼ûµÄÈκÎÎļþ¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2018-0374
²»×ãÈÏÖ¤»úÔ컹¿Éµ¼Ö Policy Builder Êý¾Ý¿âÔâ¶³ö£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¹¥»÷Õß½Ó¼û²¢¸ü¸Ä´æ´¢ÔÚÆäÖеÄÈκÎÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2018-0375
Policy SuiteÖеÄCluster Manager´æÔÚÒ»¸öÓµÓÐĬÈÏ¡¢¾²Ì¬Í´´¦µÄrootÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÄܹ»µÇ¼´ËÕÊ»§²¢Ê¹ÓÃrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
˼¿Æ»¹½¨¸´ÁË SD-WAN ½â¾ö¹æ»®ÖдæÔÚµÄÆß¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐΨÖðÒ»¸öÔÚÎÞÐèÈÏÖ¤µÄÇé¿öÏÂÄÜÔâÔ¶³ÌÀûÓõķì϶ӰÏì Touch Provision ·þÎñ£¬£¬£¬£¬£¬Ëü¿Éµ¼Ö¹¥»÷ÕßÒý·¢ DoS ǰÌá¡£¡£¡£¡£¡£¡£¡£¡£
ÆäËüµÄ SD-WAN °²È«·ì϶ҪÇó½øÐÐÈÏÖ¤£¬£¬£¬£¬£¬ÈçÔâÀûÓ㬣¬£¬£¬£¬¿É¸²Ð´µ×²ã²Ù×÷ϵͳÉϵÄËÁÒâÎļþ²¢ÒÔ vmanage »ò¸ùȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖеÄÒ»¸ö SD-WAN ·ì϶ÀûÓÃÒªÇóÈÏÖ¤ºÍ±¾µØ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
˼¿Æ»¹Í¨ÖªÏû·ÑÕß³ÆÆä Nexus 9000 ϵÁÐµÄ Fabric »¥»»»ú£¬£¬£¬£¬£¬¾ßÌåÊÇ DHCPv6 Ö°ÄÜ£¬£¬£¬£¬£¬ËüÊÜÒ»¸ö¸ßΣȱµãÓ°Ï죬£¬£¬£¬£¬¿ÉÔâÔ¶³Ìδ¾ÈÏÖ¤µÄ¹¥»÷ÕßÓÃÓÚÒý·¢ DoS ǰÌá¡£¡£¡£¡£¡£¡£¡£¡£
˼¿Æ»¹½«¶à¸öÓ°Ïì˼¿Æ Webex Network Recording Player for AdvancedRecording Format (ARF) ºÍ WebexRecording Format (WRF) ÎļþµÄ·ì϶ÆÀΪ¸ßΣ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÈÃÖ¸±êÓû§Ê¹ÓÃÊÜÓ°Ïì²¥·ÅÆ÷´ò¿ª³ö¸ñ»ú¹ØµÄ ARF »ò WRF Îļþ¾ÍÄÜÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
˼¿Æ¹Ù·½ÒѾ°ä²¼Ð°汾½¨¸´ÁËÉÏÊö·ì϶£¬£¬£¬£¬£¬Óû§Ó¦ÊµÊ±Éý¼¶½øÐзÀ»¤¡£¡£¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities
https://www.securityweek.com/cisco-finds-serious-flaws-policy-suite-sd-wan-products


¾©¹«Íø°²±¸11010802024551ºÅ