Cisco ¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-06-21Îó²î±àºÅºÍ¼¶±ð
CVE-2018-0301 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0304 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0308 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0312 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-0314 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
Îó²îÓ°ÏìCisco FXOSÈí¼þºÍNX-OSÈí¼þ£¬£¬£¬£¬£¬Éæ¼°µÄ²úÆ·MDS¡¢Nexus¡¢Firepower¡¢UCS£¬£¬£¬£¬£¬Ïêϸ°æ±¾¼ûÎó²î¸ÅÊö¡£¡£¡£
Îó²î¸ÅÊö
6ÔÂ20ÈÕ£¬£¬£¬£¬£¬Cisco¹Ù·½Ðû²¼Ç徲ͨ¸æÐÞ¸´Á˶à¸ö²î±ðˮƽµÄÇå¾²Îó²î£¬£¬£¬£¬£¬ÆäÖаüÀ¨5¸öÑÏÖØÎó²î¡£¡£¡£Ïà¹ØÁ´½Ó£º
https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-67770¡£¡£¡£
CVE-2018-0301 (Critical)
Cisco NX-OSÈí¼þµÄNX-API¹¦Ð§Öб£´æµÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÏòÊÜÓ°ÏìϵͳµÄÖÎÀí½Ó¿Ú·¢ËͶñÒâÊý¾Ý°ü£¬£¬£¬£¬£¬´Ó¶øµ¼Ö»º³åÇøÒç³ö¡£¡£¡£
¸ÃÎó²îÊÇÓÉÓÚNX-API×ÓϵͳµÄÉí·ÝÑé֤ģ¿£¿£¿£¿éÖÐÊäÈëÑéÖ¤²»×¼È·µ¼Öµġ£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½«È«ÐĽṹµÄHTTP»òHTTPSÊý¾Ý°ü·¢Ë͵½ÆôÓÃÁËNX-API¹¦Ð§µÄÊÜÓ°ÏìϵͳµÄÖÎÀí½çÃæÀ´Ê¹ÓôËÎó²î¡£¡£¡£¸ÃÎó²î¿ÉÄÜÔÊÐí¹¥»÷ÕßÒÔrootÉí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£×¢ÖØ£ºNX-APIĬÈÏÊǽûÓõġ£¡£¡£
ÊÜÓ°Ïì²úÆ·¼°°æ±¾£º
ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´ËÎó²îÓ°Ï죺
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco NX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo#fs
CVE-2018-0304 (Critical)
Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶ÁÈ¡Ãô¸ÐÄÚ´æÄÚÈÝ£¬£¬£¬£¬£¬´´Á¢¾Ü¾øÐ§ÀÍÌõ¼þ»òÒÔrootÉí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
±£´æ´ËÎó²îÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°ü±êÍ·¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍÌØÖÆµÄCisco Fabric ServicesÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£¡£¡£Ò»´ÎÀֳɵĹ¥»÷¿ÉÄÜ»áÔÊÐí¹¥»÷ÕßÔÚCisco Fabric Services×é¼þÖе¼Ö»º³åÇøÒç³ö»ò»º³åÇø¹ý¶Á£¬£¬£¬£¬£¬Õâ¿ÉÄÜÔÊÐí¹¥»÷Õß¶ÁÈ¡Ãô¸ÐÄÚ´æÐÅÏ¢£¬£¬£¬£¬£¬´´Á¢¾Ü¾øÐ§ÀÍÌõ¼þ»òÒÔrootÉí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
ÊÜÓ°Ïì²úÆ·¼°°æ±¾£º
ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´ËÎó²îÓ°Ï죺
Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects
ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-ace#fs
CVE-2018-0308 (Critical)
Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë»òµ¼Ö¾ܾøÐ§À͹¥»÷¡£¡£¡£
±£´æ´ËÎó²îÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°üÖеıêÍ·Öµ¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍÌØÖÆµÄCisco Fabric ServicesÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£¡£¡£Ò»´ÎÀֳɵĹ¥»÷¿ÉÄÜ»áÔì³É»º³åÇøÒç³ö£¬£¬£¬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔÖ´ÐÐí§Òâ´úÂë»òµ¼ÖÂDoS¡£¡£¡£
ÊÜÓ°Ïì²úÆ·¼°°æ±¾£º
ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´ËÎó²îÓ°Ï죺
Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects
ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace#fs
CVE-2018-0312 (Critical)
Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë»òÔÚÊÜÓ°ÏìµÄÉè±¹ØÁ¬¼Ö¾ܾøÐ§À͹¥»÷¡£¡£¡£
±£´æ´ËÎó²îÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þÔÚ´¦Öóͷ£Êý¾Ý°üʱδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°ü±êÍ·¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËͶñÒâ½á¹¹µÄCisco Fabric ServicesÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£¡£¡£Ò»´ÎÀֳɵĹ¥»÷¿ÉÄÜ»áÔÊÐí¹¥»÷ÕßÔÚ×°±¸ÉÏÔì³É»º³åÇøÒç³ö£¬£¬£¬£¬£¬´Ó¶øÔÊÐí¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë»òÔÚÉè±¹ØÁ¬¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£
ÊÜÓ°ÏìµÄ°æ±¾£º
ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´ËÎó²îÓ°Ï죺
Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects
ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-cli-execution#fs
CVE-2018-0314 (Critical)
Cisco FXOSÈí¼þºÍNX-OSÈí¼þÖÐCisco Fabric Services£¨CFS£©×é¼þÀïµÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
±£´æ´ËÎó²îÊÇÓÉÓÚÊÜÓ°ÏìµÄÈí¼þÔÚ´¦Öóͷ£Êý¾Ý°üʱδ³ä·ÖÑéÖ¤Cisco Fabric ServicesÊý¾Ý°ü±êÍ·¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËͶñÒâ½á¹¹µÄCisco Fabric ServicesÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£¡£¡£Ò»´ÎÀֳɵĹ¥»÷¿ÉÄÜ»áÔÊÐí¹¥»÷ÕßÔÚ×°±¸ÉÏÔì³É»º³åÇøÒç³ö£¬£¬£¬£¬£¬´Ó¶øÔÊÐí¹¥»÷ÕßÔÚ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
ÊÜÓ°ÏìµÄ°æ±¾£º
ÒÔÏÂ˼¿Æ²úÆ·ÊÜ´ËÎó²îÓ°Ï죺
Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
MDS 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
Nexus 9500 R-Series Line Cards and Fabric Modules
UCS 6100 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6300 Series Fabric Interconnects
ÒÔÉϲúÆ·ÖÐÊÜÓ°ÏìµÄCisco FXOS»òNX-OSÈí¼þ°æ±¾Ïê¼û £º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution#fs
ÐÞ¸´½¨Ò飺
Éý¼¶ÖÁ²Î¿¼Á´½ÓÖÐÌáÐѵÄÇå¾²°æ±¾¡£¡£¡£
²Î¿¼Á´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo#fs
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-ace#fs
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace#fs
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-cli-execution#fs
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution#fs