[¸ßΣ·ì϶¾¯±¨] ˼¿Æ¸ßΣ·ì϶±»ÓÃÀ´¹¥»÷¹Ø¼ü»ù´¡ÉèÊ© £¬ÎÒ¹úÒÑÓлú¹¹Êܵ½¹¥»÷

°ä²¼¹¦·ò 2018-04-08

2018Äê3ÔÂ28ÈÕ £¬Ë¼¿Æ°ä²¼Á˸ßΣ·ì϶Ԥ¾¯³ÆË¼¿ÆIOS¡¢IOS XEºÍIOS XRÈí¼þÖдæÔÚ¶à¸ö·ì϶¡£¡£ÆäÖÐÔ̺¬2¸öÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2018-0171¡¢CVE-2018-0151¡£¡£¹¥»÷Õß¿ÉÀûÓ÷ì϶½øÐÐδÊÚȨ½Ó¼û¡¢ÌáȨ¡¢Ö´ÐÐËÁÒâ´úÂë»òµ¼Ö»ؾø·þÎñ¡£¡£



·ì϶ÃèÊö


Cisco Smart InstallÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-0171£©Î£º£º£º¦µÈ¼¶£º£º£º³¬Î£


Cisco IOS¡¢IOS XEÈí¼þSmart Install¿Í»§¶ËÖдæÔÚ»º³åÇø²Ö¿âÒç³ö·ì϶£¨CVE-2018-0171£© £¬¸Ã·ì϶ÊÇÓÉÓÚ¶Ô·Ö×éÊý¾ÝÑéÖ¤²»µ±Ôì³ÉµÄ¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß £¬Äܹ»Í¨¹ý»ú¹Ø¶ñÒâSmall InstallÐÂÎŰü £¬ÏòÊÜÓ°ÏìÉ豸µÄTCP 4786¶Ë¿Ú·¢Ë͸ÃÊý¾Ý°ü £¬ÖØÔØÖ¸±êÉ豸 £¬Ôì³ÉÉ豸»Ø¾ø·þÎñ£¨DoS£©»òÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£¡£


ÓÉÓÚ4786¶Ë¿ÚĬÈÏ¿ªÆô £¬ÇҸ÷ì϶pocÒѾ­±»¹«¿ª £¬·ì϶Σº£º£º¦Ë®Æ½¼«¸ß¡£¡£


¸Ã·ì϶´æÔÚÓÚÔËÐÐÁËCisco IOS/IOS EXÊÜÓ°Ïì°æ±¾Èí¼þ £¬ÇÒΪSmart Install ClientģʽµÄÉ豸¡£¡£Î´¿ªÆôCisco Smart Install £¬»ò±»ÉèÖÃΪSmart Install DirectorģʽµÄÉ豸²»ÔÚÓ°ÏìÖ®ÁС£¡£


Cisco QoSÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-0151£© Σº£º£º¦µÈ¼¶£º£º£º³¬Î£


¸Ã·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìÉ豸¶Ô´ïµ½ÆäUDP 18999¶Ë¿ÚµÄÊý¾Ý°üÖÐijЩֵµÄÌìǵ²é³­²»µ±Ôì³ÉµÄ¡£¡£¹¥»÷Õß¿Éͨ¹ýÏòÊÜÓ°ÏìÉ豸·¢ËͶñÒâ»ú¹ØµÄÊý¾Ý°üÀ´ÀûÓ÷ì϶ £¬ÊÜÓ°ÏìÉ豸ÔÚ´¦ÖÃÊý¾Ý°üʱ¿ÉÄܲúÉú»º³åÇøÒç³ö £¬µ¼ÖÂÉè±¸ÖØÔØ¡£¡£¸Ã·ì϶ӰÏìËùÓÐÔËÐÐÁËCisco IOS/IOS EXÊÜÓ°Ïì°æ±¾Èí¼þµÄÉ豸¡£¡£

 

Ŀǰ¹ú¼ÊÉÏ»òÐíÓжþÊ®ÍòÊÜÓ°ÏìÉ豸¶³öÔÚ¹«ÍøÉÏ£º£º£º

 

640?wx_fmt=png&tp=webp&wxfrom=5&wx_lazy=1

 

ÉÏÖÜ £¬Ò»¸öÃûΪ¡°JHT¡±µÄºÚ¿Í×éÖ¯ÀûÓÃ˼¿ÆCVE-2018-0171 ÖÇÄÜ×°Ö÷ì϶¹¥»÷ÁËÔ̺¬¶íÂÞ˹ºÍÒÁÀÊÔÚÄڵĶà¸ö¹ú¶ÈÍøÂç»ù´¡ÉèÊ©¡£¡£±»¹¥»÷µÄCisco·ÓÉÆ÷µÄÅäÖÃÎļþstartup.config»á±»¸²¸Ç £¬Â·ÓÉÆ÷½«ÖØÐÂÆô¶¯¡£¡£³ýÁ˵¼Ö´óÃæ»ýÍøÂçÖжÏÒÔÍâ £¬ÖÎÀíÔ±»¹»á·¢ÏÖ·ÓÉÆ÷ÅäÖÃÎļþ±»¸ü¸Ä³É£º£º£º¡°Don't mess with our elections.... -JHT usafreedom_jht@tutanota.com¡±¡£¡£


½ñÌì £¬ÎÒÃÇÂ½ÐøÊÕµ½¶à¸ö¹úÄÚ»ú¹¹Ôâ·êͬÑùµÄ¹¥»÷µÄÐÂÎÅ¡£¡£±»¹¥»÷µÄÉ豸³ý̱»¾Íâ £¬ÅäÖÃÎļþ»¹»áÏÔʾһ¸öÃÀ¹ú¹úÆì¡£¡£

 

gif;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAADUlEQVQImWNgYGBgAAAABQABh6FO1AAAAABJRU5ErkJggg==



½â¾ö¹æ»®


1.Cisco¹Ù·½ÒѾ­°ä²¼Á˸üв¹¶¡ £¬ £¬½¨ÒéÓйØÓû§¾¡¿ì¸üÐÂÉý¼¶¡£¡££¨https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2£©


2.OG¶«·½ÌüÒÑÓÚ4ÔÂ4ÈÕÉý¼¶ÊÂÎñ¿â £¬ÊÂÎñÃû³Æ£º£º£ºTCP_Cisco_SmartInstall_Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2018-0171) £¬Çë¿í´óÓû§ÊµÊ±Éý¼¶¡£¡£


ÌìãÙÈëÇÖ¼ì²âϵͳ±¨¾¯½ØÍ¼£º£º£º

 

640?wx_fmt=png&tp=webp&wxfrom=5&wx_lazy=1

 

ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º£º£º

 

640?wx_fmt=png&tp=webp&wxfrom=5&wx_lazy=1

 

ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º£º£º

 

640?wx_fmt=png&tp=webp&wxfrom=5&wx_lazy=1

2018Äê3ÔÂ28ÈÕ £¬Ë¼¿Æ°ä²¼Á˸ßΣ·ì϶Ԥ¾¯³ÆË¼¿ÆIOS¡¢IOS XEºÍIOS XRÈí¼þÖдæÔÚ¶à¸ö·ì϶¡£¡£ÆäÖÐÔ̺¬2¸öÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2018-0171¡¢CVE-2018-0151¡£¡£¹¥»÷Õß¿ÉÀûÓ÷ì϶½øÐÐδÊÚȨ½Ó¼û¡¢ÌáȨ¡¢Ö´ÐÐËÁÒâ´úÂë»òµ¼Ö»ؾø·þÎñ¡£¡£



·ì϶ÃèÊö


Cisco Smart InstallÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-0171£©Î£º£º£º¦µÈ¼¶£º£º£º³¬Î£


Cisco IOS¡¢IOS XEÈí¼þSmart Install¿Í»§¶ËÖдæÔÚ»º³åÇø²Ö¿âÒç³ö·ì϶£¨CVE-2018-0171£© £¬¸Ã·ì϶ÊÇÓÉÓÚ¶Ô·Ö×éÊý¾ÝÑéÖ¤²»µ±Ôì³ÉµÄ¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß £¬Äܹ»Í¨¹ý»ú¹Ø¶ñÒâSmall InstallÐÂÎŰü £¬ÏòÊÜÓ°ÏìÉ豸µÄTCP 4786¶Ë¿Ú·¢Ë͸ÃÊý¾Ý°ü £¬ÖØÔØÖ¸±êÉ豸 £¬Ôì³ÉÉ豸»Ø¾ø·þÎñ£¨DoS£©»òÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£¡£


ÓÉÓÚ4786¶Ë¿ÚĬÈÏ¿ªÆô £¬ÇҸ÷ì϶pocÒѾ­±»¹«¿ª £¬·ì϶Σº£º£º¦Ë®Æ½¼«¸ß¡£¡£


¸Ã·ì϶´æÔÚÓÚÔËÐÐÁËCisco IOS/IOS EXÊÜÓ°Ïì°æ±¾Èí¼þ £¬ÇÒΪSmart Install ClientģʽµÄÉ豸¡£¡£Î´¿ªÆôCisco Smart Install £¬»ò±»ÉèÖÃΪSmart Install DirectorģʽµÄÉ豸²»ÔÚÓ°ÏìÖ®ÁС£¡£


Cisco QoSÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-0151£© Σº£º£º¦µÈ¼¶£º£º£º³¬Î£


¸Ã·ì϶ÊÇÓÉÓÚÊÜÓ°ÏìÉ豸¶Ô´ïµ½ÆäUDP 18999¶Ë¿ÚµÄÊý¾Ý°üÖÐijЩֵµÄÌìǵ²é³­²»µ±Ôì³ÉµÄ¡£¡£¹¥»÷Õß¿Éͨ¹ýÏòÊÜÓ°ÏìÉ豸·¢ËͶñÒâ»ú¹ØµÄÊý¾Ý°üÀ´ÀûÓ÷ì϶ £¬ÊÜÓ°ÏìÉ豸ÔÚ´¦ÖÃÊý¾Ý°üʱ¿ÉÄܲúÉú»º³åÇøÒç³ö £¬µ¼ÖÂÉè±¸ÖØÔØ¡£¡£¸Ã·ì϶ӰÏìËùÓÐÔËÐÐÁËCisco IOS/IOS EXÊÜÓ°Ïì°æ±¾Èí¼þµÄÉ豸¡£¡£

 

Ŀǰ¹ú¼ÊÉÏ»òÐíÓжþÊ®ÍòÊÜÓ°ÏìÉ豸¶³öÔÚ¹«ÍøÉÏ£º£º£º

 

 

OG¶«·½Ìü¡¤(Öйú´ó½)

 

ÉÏÖÜ £¬Ò»¸öÃûΪ¡°JHT¡±µÄºÚ¿Í×éÖ¯ÀûÓÃ˼¿ÆCVE-2018-0171 ÖÇÄÜ×°Ö÷ì϶¹¥»÷ÁËÔ̺¬¶íÂÞ˹ºÍÒÁÀÊÔÚÄڵĶà¸ö¹ú¶ÈÍøÂç»ù´¡ÉèÊ©¡£¡£±»¹¥»÷µÄCisco·ÓÉÆ÷µÄÅäÖÃÎļþstartup.config»á±»¸²¸Ç £¬Â·ÓÉÆ÷½«ÖØÐÂÆô¶¯¡£¡£³ýÁ˵¼Ö´óÃæ»ýÍøÂçÖжÏÒÔÍâ £¬ÖÎÀíÔ±»¹»á·¢ÏÖ·ÓÉÆ÷ÅäÖÃÎļþ±»¸ü¸Ä³É£º£º£º¡°Don't mess with our elections.... -JHT usafreedom_jht@tutanota.com¡±¡£¡£


½ñÌì £¬ÎÒÃÇÂ½ÐøÊÕµ½¶à¸ö¹úÄÚ»ú¹¹Ôâ·êͬÑùµÄ¹¥»÷µÄÐÂÎÅ¡£¡£±»¹¥»÷µÄÉ豸³ý̱»¾Íâ £¬ÅäÖÃÎļþ»¹»áÏÔʾһ¸öÃÀ¹ú¹úÆì¡£¡£

 

OG¶«·½Ìü¡¤(Öйú´ó½)

 

½â¾ö¹æ»®


1.Cisco¹Ù·½ÒѾ­°ä²¼Á˸üв¹¶¡ £¬ £¬½¨ÒéÓйØÓû§¾¡¿ì¸üÐÂÉý¼¶¡£¡££¨https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2£©


2.OG¶«·½ÌüÒÑÓÚ4ÔÂ4ÈÕÉý¼¶ÊÂÎñ¿â £¬ÊÂÎñÃû³Æ£º£º£ºTCP_Cisco_SmartInstall_Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2018-0171) £¬Çë¿í´óÓû§ÊµÊ±Éý¼¶¡£¡£


ÌìãÙÈëÇÖ¼ì²âϵͳ±¨¾¯½ØÍ¼£º£º£º

 

OG¶«·½Ìü¡¤(Öйú´ó½)

 

ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º£º£º

 

OG¶«·½Ìü¡¤(Öйú´ó½)

 

 

ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º£º£º

 

OG¶«·½Ìü¡¤(Öйú´ó½)