Cisco Email Security Appliance °²È«·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-01-14·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-15453£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£º
Cisco Email Security Appliance 11.1.0-131
Cisco Email Security Appliance 0
Cisco Asyncos 11.1
Cisco Asyncos 11.0
Cisco Asyncos 9.0
Cisco Asyncos 10.5.2-061
Cisco Asyncos 10.5.2-042
Cisco Asyncos 10.5.2
Cisco Asyncos 10.5.1-296
Cisco Asyncos 10.5.1
Cisco Asyncos 10.0.0-203
Cisco Asyncos 10.0.0-125
Cisco Asyncos 10.0.0-124
Cisco Asyncos 10.0
²»ÊÜÓ°Ïì°æ±¾£º
Cisco Email Security Appliance 12.0.0-281
Cisco Email Security Appliance 11.1.1-042
Cisco Email Security Appliance 11.1.1-037
Cisco Email Security Appliance 11.0.2-044
·ì϶¸ÅÊö
Cisco Email Security Appliance(ESA)ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»¸öµç×ÓÓʼþ°²È«É豸¡£¡£¡£¡£¡£¡£AsyncOS SoftwareÊÇʹÓà ÔÚÆäÖеIJÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£
Cisco ESAµÄAsyncOS SoftwareÖеÄSecure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification»òS/MIME Public Key HarvestingÖ°ÄÜ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓжÔS/MIMEÊðÃûµÄÓʼþ½øÐÐÕýÈ·µØÊäÈëÑéÖ¤¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµÄS/MIMEÊðÃûµÄÓʼþÀûÓø÷ì϶Ôì³ÉÉ豸»Ø¾ø·þÎñ£¨ÏµÍ³ÄÚ´æ°Ü»µ£©¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP£¬£¬£¬£¬£¬Äܹ»Í¨¹ýÒÔÏ·½Ê½ÑéÖ¤£º
Ҫȷ¶¨ÊÇ·ñÔÚESAÉÏÅäÖÃÁËS / MIME Decryption and Verification£¬£¬£¬£¬£¬ÖÎÀíÔ±Äܹ»Ö´ÐÐÒÔϲÙ×÷£º
1. µ¼º½µ½Click Mail Policies > Mail Flow Policies
2. ä¯ÀÀËùÓÐÏÖÓеÄMail Flow Policies
3. ÏòϹö¶¯µ½Ã¿¸öMail Flow PolicyµÄSecurity Features²¿ÃÅ
4. ÔÚS/MIME Decryption/VerificationÏ£¬£¬£¬£¬£¬ÑéÖ¤ÊÇ·ñÆôÓÃÁËS/MIME decryption and
verification¡£¡£¡£¡£¡£¡£
Ҫȷ¶¨ÊÇ·ñÔÚESAÉÏÅäÖÃÁËS/MIME Public Key Harvesting£¬£¬£¬£¬£¬ÖÎÀíÔ±Äܹ»Ö´ÐÐÒÔϲÙ×÷£º
1. µ¼º½µ½Click Mail Policies > Mail Flow Policies
2. ä¯ÀÀËùÓÐÏÖÓеÄMail Flow Policies
3. ÏòϹö¶¯µ½Ã¿¸öMail Flow PolicyµÄSecurity Features²¿ÃÅ
4. ÔÚS/MIME Public Key HarvestingÏ£¬£¬£¬£¬£¬ÑéÖ¤ÊÇ·ñÆôÓÃÁËS/MIME Public Key
Harvesting¡£¡£¡£¡£¡£¡£
Ҫȷ¶¨ESAÉÏÊÇ·ñÔËÐÐÁËÒ×Êܹ¥»÷µÄCisco AsyncOSÈí¼þ°æ±¾£¬£¬£¬£¬£¬ÖÎÀíÔ±Äܹ»ÔÚESA CLI
ÖÐʹÓÃversionºÅÁî¡£¡£¡£¡£¡£¡£ÒÔÏÂʾÀýÏÔʾÁËÔËÐÐCisco AsyncOSÈí¼þ°æ±¾10.0.1-087µÄESAµÄºÅÁîÊä³ö£º
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬Óû§Ó¦ÊµÊ±¸üÐÂÉý¼¶½øÐзÀ»¤¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190109-esa-dos


¾©¹«Íø°²±¸11010802024551ºÅ