AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

Cisco IOS/IOS XEÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-0171£©

2018-04-10

Ðû²¼ÕߣºAG¹«Ë¾¿Æ¼¼

Ò».      Îó²î¸ÅÊö


2018Äê3ÔÂ28ÈÕ£¬Cisco IOSÒÔ¼°IOS XEÈí¼þ±»·¢Ã÷±£´æÒ»¸öÑÏÖØÎó²îCVE-2018-0171¡£¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýÖØÐ¼ÓÔØ£¨reload£©×°±¸Ôì³É¾Ü¾ø·þÎñÌõ¼þ£¬»òÕßÔ¶³ÌÖ´ÐдúÂë¡£Smart InstallÊÇΪеÄLANÒÔÌ«Íø½»Á÷»úÌṩÁã´¥Ãþ°²Åŵﴲ弴ÓÃÉèÖúÍͼÐÎÖÎÀí¹¦Ð§£¬ÔÚTCP¶Ë¿Ú4786ÉÏÔËÐеÄCiscoרÓÃЭÒ飬Èô×°±¸ÆôÓÃÁËSmart Install¹¦Ð§ÇÒ¶ÔÍ⿪·Å4786¶Ë¿Ú£¬¹¥»÷Õ߾ͿÉͨ¹ý·¢ËÍ»ûÐÎSmart Install±¨ÎÄÀ´Ê¹ÓôËÎó²î£¬Ê¹µÃ×°±¸»º³åÇøÒç³ö£¬µ¼Ö¾ܾø·þÎñÒÔÖÂÔ¶³Ì´úÂëÖ´ÐеÈЧ¹û¡£

Ïà¹ØÁ´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2

4ÔÂ8ÈÕ£¬¹¥»÷ÕßÒÉËÆÊ¹ÓÃÁË˼¿ÆIOS/IOS XEÔ¶³Ì´úÂëÖ´ÐÐÎó²îcve-2018-0171¾ÙÐдó¹æÄ£¹¥»÷£¬ÆäÖаüÀ¨º£ÄÚ¶à¸ö»ú¹¹£¬ÔâÊܹ¥»÷µÄÆóÒµ»áµ¼ÖÂ×°±¸Ì±»¾£¬Í¬Ê±ÉèÖÃÎļþ±»Ð޸ġ£


¶þ.       Îó²îÓ°Ïì


Ëù±¬³öµÄÎó²îÓ°ÏìËùÓÐÔËÐÐCisco IOS»òIOS XEÈí¼þ²¢ÇÒ¿ªÆôÁËÖÇÄÜ×°Öã¨Smart Install£©ÌØÕ÷µÄ×°±¸£¬ÏêÇéÇë²Î¿¼Cisco¹Ù·½Í¨¸æ£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2

ÏÖÔÚÒÑÖªÊÜÓ°Ïì×°±¸/Èí¼þΪ£º

È·ÈÏÊÜÓ°ÏìµÄ×°±¸Ðͺţº

?  Catalyst 4500 Supervisor Engines

?  Cisco Catalyst 3850 Series Switches

?  Cisco Catalyst 2960 Series Switches

¿ÉÄÜÊÜÓ°ÏìµÄ×°±¸Ðͺţº

?  Catalyst 4500 Supervisor Engines

?  Catalyst 3850 Series

?  Catalyst 3750 Series

?  Catalyst 3650 Series

?  Catalyst 3560 Series

?  Catalyst 2960 Series

?  Catalyst 2975 Series

?  IE 2000

?  IE 3000

?  IE 3010

?  IE 4000

?  IE 4010

?  IE 5000

?  SM-ES2 SKUs

?  SM-ES3 SKUs

?  NME-16ES-1G-P

?  SM-X-ES3 SKUs


Èý.       Ó°ÏìÅŲé


Îó²îÓ°ÏìµÄÊÇÆôÓÃÁËSmart Install¹¦Ð§µÄ×°±¸£¬ÔÚTCP¶Ë¿Ú4786ÉÏÔËÐеÄCiscoרÓÃЭÒ飬µ±4780¶Ë¿Ú¿ª·ÅÓÚÍâÍøÊ±£¬¿ÉÔì³É¸ü´óµÄÓ°Ï죬AG¹«Ë¾¿Æ¼¼½¨Òéͨ¹ýÈçϼƻ®¾ÙÐÐÅŲ飺


3.1         AG¹«Ë¾¿Æ¼¼»¥ÁªÍø×ʲúºË²é

ΪʹÆóÒµ¿Í»§ÏàÊ¶ÖØ´óÖØ´óµÄ×ʲúÀàÐÍÔÚ»¥ÁªÍøÉϵÄ̻¶ÇéÐΣ¬°üÀ¨¶Ë¿Ú¡¢Ó¦Óá¢ÏµÍ³ÀàÐÍ¡¢µØÀíÂþÑܵÈ£¬Ô¤Öª¿ÉÄܱ£´æµÄΣº¦£¬²¢½ÓÄÉÏà¹ØµÄ¿ØÖƲ½·¥£¬AG¹«Ë¾¿Æ¼¼Ìṩ»ùÓÚNTIµÄ»¥ÁªÍø×ʲúºË²é·þÎñ£¬¿ìËÙÅжÏÃæÏò»¥ÁªÍøµÄ×ʲúÊÇ·ñÊܵ½Cisco Smart InstallÎó²îÒÔ¼°ÆäËû¿ÉʹÓÃÎó²îµÄÓ°Ï죬ÈçÐèЭÖú£¬¿ÉÁªÏµNTI@nsfocus.com¡£


3.2         ÅŲéSmart InstallÊÇ·ñ¿ªÆô

  • ¶Ë¿ÚɨÃè

¼ì²âÄ¿µÄ×°±¸ÊÇ·ñ¿ªÆô4786/TCP¶Ë¿Ú£¬Ê¹ÓÃnmapɨÃèÄ¿µÄ×°±¸¶Ë¿Ú£¬ÈôÊÇ¿ªÆôÔò¿ÉÄÜÊܵ½Ó°Ïì¡£

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


  • Cisco Smart InstallÇå¾²¼ì²â¹¤¾ß

CiscoÕë¶ÔSmart Install¹¦Ð§ÌṩÓÅÖÊÇ徲ʵ¼ù½¨Ò飬²¢ÌṩÁËSmart Install¹¦Ð§µÄÇå¾²¼ì²é¾ç±¾£¬ÏÂÔØÁ´½Ó£ºhttps://github.com/Cisco-Talos/smi_check

¼ì²âÒªÁìÈçÏ£º

# python smi_check.py -i 192.168.1.2

[INFO] Sending TCP probe to targetip:4786

[INFO] Smart Install Client feature active on targetip:4786

[INFO] targetip is affected


3.3         µÇ¼Cisco IOS×°±¸×Ô²é

  • vstackÉèÖÃÐÅÏ¢ÅжÏ

ÔÚ×°±¸µÄEXECÖ¸ÁîÖÐÊäÈëshow vstack config ¿ÉÒÔÅÌÎÊ×°±¸ÊÇ·ñ¿ªÆôÁËSmart Install¡£Èô·µ»ØÐ§¹ûΪRole: Client (SmartInstall enabled) »òÕßOper Mode: EnabledÔòÌåÏÖ×°±¸¿ªÆôÁËSmart Install£¬×°±¸±£´æÎ£º¦¡£


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø



  • Cisco IOS×°±¸°æ±¾ÐÅÏ¢ÅжÏ

ÖÎÀíÔ±Óû§¿ÉÒԵǼµ½×°±¸ºóÔÙCLIÖÐÊäÈëshow versionÀ´ÅÌÎÊ×°±¸°æ±¾£¬Í¨¹ýÓ°Ïì°æ±¾ÅжÏ×°±¸ÊÇ·ñÔÚÓ°Ïì¹æÄ£ÄÚ¡£

ios-xe-device# show version


Cisco IOS Software Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M) Version Denali 16.2.1 RELEASE SOFTWARE (fc1)

Technical Support: http://www.cisco.com/techsupport

Copyright (c) 1986-2016 by Cisco Systems Inc.

Compiled Sun 27-Mar-16 21:47 by mcpre

ʹÓøð汾ÐÅÏ¢£¬Óû§¿ÉÒÔÔÚCisco¹Ù·½È·ÈÏÊÇ·ñÊÜÎó²îÓ°£¬²Î¿¼Á´½ÓÈçÏ£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2

»á¼ûÉÏÊöÁ´½Ó£¬½«°æ±¾ºÅÊäÈëÎı¾¿òºóµã»÷¡°Check¡±°´Å¥£¬ÒÔ16.2.1ΪÀý£¬ÈçÏÂͼËùʾ¡£


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


Ö®ºóµ¯³öµÄÒ³ÃæÖлáÁгö¸Ã°æ±¾¿ÉÄܱ£´æµÄÏà¹ØÎó²î£¬ÈôÊÇ¿´µ½±£´æÈçÏÂͼºì¿òµÄËùʾµÄÎó²îÃû³Æ£¬ËµÃ÷¸Ã×°±¸±£´æÎ£º¦


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


³ýÊÖ¶¯ÊäÈë°æ±¾¾ÙÐÐÅÌÎÊÍ⣬Cisco¹Ù·½Ò²ÌṩÁËshow versionÐÅÏ¢Ö±½ÓÅÌÎʵķ½·¨£¬½«show versionÏÂÁîÖ´ÐкóµÄ°æ±¾ÐÅÏ¢ÉúÑĵ½a.txtÎļþÖУ¬»á¼ûCisco¹Ù·½µÄCisco IOS Software CheckerÔÚÏß¼ì²â£¬²Î¿¼Á´½ÓÈçÏ£º

https://tools.cisco.com/security/center/softwarechecker.x

½«a.txtÎļþÉÏ´«£¬¾ÙÐÐÔÚÏß¼ì²â¡£


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


ÏêϸµÄʹÓÃ˵Ã÷¿É²Î¿¼ÈçÏÂÊÓÆµ½Ì³Ì£º

https://players.brightcove.net/1384193102001/41XYD7gTx_default/index.html?directedMigration=true&videoId=5755100470001&


ËÄ.       ½â¾ö½¨Òé


4.1         ¹Ù·½Éý¼¶

Cisco¹Ù·½ÒѾ­Ðû²¼Á˸üв¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬µ«Î´¹ûÕæ²¹¶¡µÄÏÂÔØÁ´½Ó£¬Óû§¿ÉÒÀ¸½ÒѾ­¹ºÖõÄCisco licenseÉêÇëÉý¼¶·þÎñ£¬ÇëÊÜÓ°ÏìµÄÆóҵӦʵʱÓëCisco¹Ù·½ÁªÏµ£¬»ñÈ¡×îеIJ¹¶¡³ÌÐòÉý¼¶¾ÙÐзÀ»¤¡£


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


4.2         ÔÝʱ·À»¤

ÇëÏà¹ØÆóÒµÆÀ¹ÀÊÇ·ñÐèÒªSmart Install·þÎñ£¬ÈôÊÇÈ·¶¨²»ÐèÒª£¬¿ÉÒÀ´ÎÊäÈëÈçÏÂÏÂÁî¿É¹Ø±Õ·þÎñ£º


switch#conf t

switch(config)#no vstack 

switch(config)#do wr

switch(config)#exit


4.3         Smart Install¹¦Ð§¹Ù·½Çå¾²½¨Òé

CiscoÕë¶ÔSmart Install¹¦Ð§ÌṩÁËÒÔÏÂÕë¶ÔÐÔµÄÇå¾²½¨Òé¡£

  • ½ûÓÃSmart Install¹¦Ð§

ͨ¹ýshow vstackÏÂÁîÉó²éSmart Install¹¦Ð§µÄ״̬£¬±»½ûÓÃʱµÄÏÔʾÈçÏÂͼËùʾ£º


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


  • µ±Ê¹ÓÃSmart Install¹¦Ð§ÇÒÖ»ÓÃÓÚÁã´¥Ãþ°²ÅÅʱ£¬Çå¾²½¨ÒéÈçÏÂ.

 °²ÅÅÍê³Éºó£¬Ê¹ÓÃno vstackÏÂÁî½ûÓÃSmart Install¹¦Ð§£»

¹ØÓÚ²»Ö§³ÖvstackÏÂÁîµÄ×°±¸£¨µÍÓÚCisco IOS Release 12.2(55)SE02°æ±¾£©£¬ÔÚ½»Á÷»úÉÏͨ¹ýÉèÖÃACL×è¶Ï4786¶Ë¿Ú»á¼ûµÄ·½·¨¾ÙÐзÀ»¤¡£

  • µ±ÓªÒµÔËÐÐÐèҪʹÓÃSmart Install¹¦Ð§Ê±£¬Çå¾²½¨ÒéÈçÏ£º

ÉèÖÃACL£¬ÏÞÖÆ°×Ãûµ¥µÄ×°±¸¿É»á¼û4786¶Ë¿Ú£¬²Î¿¼ÈçÏ£º

ip access-list extended SMI_HARDENING_LIST

permit tcp host 10.10.10.1 host 10.10.10.200 eq 4786

deny tcp any any eq 4786

permit ip any any

ÏêϸÐÅÏ¢¿É²Î¿¼Á´½ÓÈçÏ£º

https://www.cisco.com/c/en/us/td/docs/switches/lan/smart_install/configuration/guide/smart_install/concepts.html#23355


Îå.       Éù Ã÷


±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£

AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾­AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£




?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼