Cisco IOS&IOS XE Software CMP Ô¶³ÌÖ´ÐдúÂëÎó²î
2017-03-30
ÃÀ¹úʱ¼ä2017Äê3ÔÂ17ÈÕ£¬Ë¼¿Æ¹Ù·½ÍøÕ¾Ðû²¼Í¨¸æ³ÆCisco IOS&IOS XE Software ¼¯ÈºÖÎÀíÐÒé(Cluster Management Protocol)±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2017-3881£¬CNNVD-201703-840£©¡£
¸ÃÎó²îÊÇ˼¿ÆÔÚÑо¿CIA×ß©Îĵµ¡°ñ·¶¥7ºÅ¡±µÄÀú³ÌÖз¢Ã÷¡£¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂÔ¶³ÌÖØÆôÊÜÓ°ÏìµÄ×°±¸»òԽȨִÐдúÂë¡£Ôì³É¸ÃÎó²îµÄÖ÷ÒªÔµ¹ÊÔÓÉÊÇÓÉÓÚûÓÐÏÞÖÆCMP-specific Telnet½ö¿ÉÓÃÓÚÄÚ²¿ÓëÍâµØµÄ¼¯Èº³ÉÔ±Ö®¼äµÄͨѶ£¬¶øÊÇ¿ÉÓÃÓÚÅþÁ¬ÈκÎÊÜÓ°ÏìµÄ×°±¸£¬ÒÔ¼°¹ØÓÚ±äÐιýµÄCMP-specific TelnetÑ¡ÏîÉèÖõĹýʧ´¦Öóͷ£¡£µ±ÓÃTelnetÅþÁ¬Ò»¸öÊÜÓ°Ïì×°±¸µÄÀú³ÌÖУ¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÒ»¸ö±äÐιýµÄCMP-specific TelnetÑ¡ÏîÉèÖÃÀ´½¨ÉèÓë¸Ã×°±¸µÄÅþÁ¬£¬Ê¹ÓôËÒªÁì¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂëÀ´ÍêÈ«¿ØÖÆ´Ë×°±¸»òÕßʹµÃ¸Ã×°±¸ÖØÆô¡£
Ïà¹ØÁ´½ÓÈçÏ£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp
http://www.cnnvd.org.cn/vulnerability/show/cv_id/2017030840
ÊÜÓ°ÏìµÄ²úÆ·¼°°æ±¾
˼¿ÆÐû²¼ÏÖÔÚÓÐ318¿î²úÆ·ÊÜ´ËÎó²îÓ°Ï죬Ïêϸ²úÆ·Áбí¼û±¨¸æºó¸½Â¼¡£
²»ÊÜÓ°ÏìµÄ²úÆ·
? ÏÖÔÚûÓÐÆäËûÒÑÖªµÄ²úÆ·ÊÜ´ËÎó²îÓ°Ïì¡£? ÔËÐÐCisco IOS Software ¿ÉÊÇûÓÐÔÚÉÏÊöÊÜÓ°ÏìÁбíÄÚµÄ×°±¸²»ÊÜÓ°Ïì¡£
? ÔËÐÐCisco IOS XE Software¿ÉÊDz»°üÀ¨CMPÐÒé×ÓϵͳµÄ²úÆ·²»ÊÜÓ°Ïì¡£
¼ì²âÒªÁì
ÔËÐÐCisco IOS ÓëIOS XE Èí¼þµÄ×°±¸¾ùÐèҪȷÈÏTelnetµÄÉèÖÃÑ¡ÏîÊÇ·ñΪ½ÓÊÜÈκÎÅþÁ¬ÇëÇó¡£ÔËÐÐCisco IOS XEÈí¼þµÄ×°±¸»¹ÐèÒªÌØÊâÈ·ÈÏÈí¼þ¾µÏñÖÐÊÇ·ñ±£´æCMP×Óϵͳ¡£
¹ØÓÚÔËÐÐCisco IOS XEÈí¼þµÄ×°±¸£¬ÒªÈ·ÈÏÈí¼þ¾µÏñÏÂÊÇ·ñ±£´æCMP×Óϵͳ£¬¿ÉÒÔÔÚ¸Ã×°±¸µÄCLIÏÂÊäÈëÒÔÏÂÏÂÁî:
ÏÂÃæµÄÀý×ÓΪÈí¼þ¾µÏñÖб£´æCMP×ÓϵͳµÄЧ¹û£º
ÏÂÃæµÄÀý×ÓΪÈí¼þ¾µÏñÖв»±£´æCMP×ÓϵͳµÄЧ¹û£º
ҪȷÈÏ×°±¸ÊÇ·ñÉèÖÃΪ½ÓÊÜÈκÎTelnetÅþÁ¬ÇëÇ󣬿ÉÒÔÔÚ¸Ã×°±¸µÄCLIÏÂÊäÈëÒÔÏÂÏÂÁ
ÔËÐдËÏÂÁî¿É»ñµÃ¶àÖÖЧ¹û£¬ÒÔϾÙÀý˵Ã÷£º
? ÔÚline vtyÉèÖÃÐкóȱÉÙtransport inputÉèÖÃÐÐ˵Ã÷¸Ã×°±¸ÔÚ´¦Öóͷ£À´×ÔÐéÄâÖÕ¶Ë£¨VTY£©µÄÁ´½Ó»á¼ûʱ½ÓÄɵÄÊÇһϵÁÐĬÈÏÐÒ飬ÕâЩÐÒé°üÀ©TelnetµÄÐÒ飬¸Ã×°±¸½«½ÓÊÜÈκÎÀ´×ÔVTYµÄTelnetÅþÁ¬ÇëÇó£¬Òò´ËÕâÊÇÒ»¸öÊܸÃÎó²îÓ°ÏìµÄÉèÖá£
ÒªÅÌÎÊCisco IOS SoftwareµÄ°æ±¾ÐÅÏ¢£¬ÖÎÀíÔ±¿ÉÒԵǼµ½×°±¸£¬ÔÚCLIÏÂʹÓÃshow versionÏÂÁîÀ´Éó²éϵͳÏà¹ØÐÅÏ¢¡£ÈôÊǸÃ×°±¸ÔÚÔËÐÐCisco IOS Software£¬ÏµÍ³ÐÅÏ¢»áÓÐÀàËÆÓÚCisco Internetwork Operating System Software or Cisco IOS SoftwareÌõÄ¿µÄ·ºÆð¡£ÒªÅÌÎÊCisco IOS XE SoftwareµÄ°æ±¾ÐÅÏ¢£¬¿ÉÒÔͬÑùÔÚCLIÏÂʹÓÃshow versionÏÂÁîÀ´ÅÌÎÊ£¬ÈôÊǸÃ×°±¸ÔÚÔËÐÐCisco IOS XE Software£¬»áÓÐÀàËÆÓÚCisco IOS XE SoftwareµÄÌõÄ¿·ºÆð¡£
¹æ±Ü¼Æ»®
? ½ûÓÃTelnetÐÒé˼¿Æ¹Ù·½½¨Òé½ûÓÃTelnetÐÒé¶ø½ÓÄÉSSHÐÒéÀ´´¦Öóͷ£ÅþÁ¬ÇëÇó¡£ÏêϸµÄ²Ù×÷ÒªÁì¼ûÈçÏÂÁ´½Ó£º
http://www.cisco.com/c/en/us/support/docs/ip/access-lists/13608-21.html
http://www.cisco.com/c/en/us/support/docs/ip/access-lists/13608-21.html#anc41
http://www.cisco.com/c/en/us/support/docs/ip/access-lists/43920-iacl.html
http://tools.cisco.com/security/center/selectIOSVersion.x
×¢£º
ÏÖÔÚ˼¿Æ¹Ù·½»¹Ã»ÓÐÌṩ¿ÉÓõÄÏà¹Ø²¹¶¡ÓÃÀ´Éý¼¶½â¾ö´ËÎÊÌ⣬Çëʱ¿Ì¹Ø×¢Ë¼¿Æ¹Ù·½Ðû²¼µÄ²¹¶¡ºÍ×îиüС£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ





