¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

Cisco IOS/IOS XEÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-0171£©

2018-04-10

Ðû²¼Õߣº¾ÅÓÎÀÏ¸ç¿Æ¼¼

Ò».      Îó²î¸ÅÊö


2018Äê3ÔÂ28ÈÕ £¬Cisco IOSÒÔ¼°IOS XEÈí¼þ±»·¢Ã÷±£´æÒ»¸öÑÏÖØÎó²îCVE-2018-0171¡£¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýÖØÐ¼ÓÔØ£¨reload£©×°±¸Ôì³É¾Ü¾ø·þÎñÌõ¼þ £¬»òÕßÔ¶³ÌÖ´ÐдúÂë¡£Smart InstallÊÇΪеÄLANÒÔÌ«Íø½»Á÷»úÌṩÁã´¥Ãþ°²Åŵﴲ弴ÓÃÉèÖúÍͼÐÎÖÎÀí¹¦Ð§ £¬ÔÚTCP¶Ë¿Ú4786ÉÏÔËÐеÄCiscoרÓÃЭÒé £¬Èô×°±¸ÆôÓÃÁËSmart Install¹¦Ð§ÇÒ¶ÔÍ⿪·Å4786¶Ë¿Ú £¬¹¥»÷Õ߾ͿÉͨ¹ý·¢ËÍ»ûÐÎSmart Install±¨ÎÄÀ´Ê¹ÓôËÎó²î £¬Ê¹µÃ×°±¸»º³åÇøÒç³ö £¬µ¼Ö¾ܾø·þÎñÒÔÖÂÔ¶³Ì´úÂëÖ´ÐеÈЧ¹û¡£

Ïà¹ØÁ´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2

4ÔÂ8ÈÕ £¬¹¥»÷ÕßÒÉËÆÊ¹ÓÃÁË˼¿ÆIOS/IOS XEÔ¶³Ì´úÂëÖ´ÐÐÎó²îcve-2018-0171¾ÙÐдó¹æÄ£¹¥»÷ £¬ÆäÖаüÀ¨º£ÄÚ¶à¸ö»ú¹¹ £¬ÔâÊܹ¥»÷µÄÆóÒµ»áµ¼ÖÂ×°±¸Ì±»¾ £¬Í¬Ê±ÉèÖÃÎļþ±»Ð޸ġ£


¶þ.       Îó²îÓ°Ïì


Ëù±¬³öµÄÎó²îÓ°ÏìËùÓÐÔËÐÐCisco IOS»òIOS XEÈí¼þ²¢ÇÒ¿ªÆôÁËÖÇÄÜ×°Öã¨Smart Install£©ÌØÕ÷µÄ×°±¸ £¬ÏêÇéÇë²Î¿¼Cisco¹Ù·½Í¨¸æ£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2

ÏÖÔÚÒÑÖªÊÜÓ°Ïì×°±¸/Èí¼þΪ£º

È·ÈÏÊÜÓ°ÏìµÄ×°±¸Ðͺţº

?  Catalyst 4500 Supervisor Engines

?  Cisco Catalyst 3850 Series Switches

?  Cisco Catalyst 2960 Series Switches

¿ÉÄÜÊÜÓ°ÏìµÄ×°±¸Ðͺţº

?  Catalyst 4500 Supervisor Engines

?  Catalyst 3850 Series

?  Catalyst 3750 Series

?  Catalyst 3650 Series

?  Catalyst 3560 Series

?  Catalyst 2960 Series

?  Catalyst 2975 Series

?  IE 2000

?  IE 3000

?  IE 3010

?  IE 4000

?  IE 4010

?  IE 5000

?  SM-ES2 SKUs

?  SM-ES3 SKUs

?  NME-16ES-1G-P

?  SM-X-ES3 SKUs


Èý.       Ó°ÏìÅŲé


Îó²îÓ°ÏìµÄÊÇÆôÓÃÁËSmart Install¹¦Ð§µÄ×°±¸ £¬ÔÚTCP¶Ë¿Ú4786ÉÏÔËÐеÄCiscoרÓÃЭÒé £¬µ±4780¶Ë¿Ú¿ª·ÅÓÚÍâÍøÊ± £¬¿ÉÔì³É¸ü´óµÄÓ°Ïì £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼½¨Òéͨ¹ýÈçϼƻ®¾ÙÐÐÅŲ飺


3.1         ¾ÅÓÎÀÏ¸ç¿Æ¼¼»¥ÁªÍø×ʲúºË²é

ΪʹÆóÒµ¿Í»§ÏàÊ¶ÖØ´óÖØ´óµÄ×ʲúÀàÐÍÔÚ»¥ÁªÍøÉϵÄ̻¶ÇéÐÎ £¬°üÀ¨¶Ë¿Ú¡¢Ó¦Óá¢ÏµÍ³ÀàÐÍ¡¢µØÀíÂþÑܵÈ £¬Ô¤Öª¿ÉÄܱ£´æµÄΣº¦ £¬²¢½ÓÄÉÏà¹ØµÄ¿ØÖƲ½·¥ £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼Ìṩ»ùÓÚNTIµÄ»¥ÁªÍø×ʲúºË²é·þÎñ £¬¿ìËÙÅжÏÃæÏò»¥ÁªÍøµÄ×ʲúÊÇ·ñÊܵ½Cisco Smart InstallÎó²îÒÔ¼°ÆäËû¿ÉʹÓÃÎó²îµÄÓ°Ïì £¬ÈçÐèЭÖú £¬¿ÉÁªÏµNTI@nsfocus.com¡£


3.2         ÅŲéSmart InstallÊÇ·ñ¿ªÆô

  • ¶Ë¿ÚɨÃè

¼ì²âÄ¿µÄ×°±¸ÊÇ·ñ¿ªÆô4786/TCP¶Ë¿Ú £¬Ê¹ÓÃnmapɨÃèÄ¿µÄ×°±¸¶Ë¿Ú £¬ÈôÊÇ¿ªÆôÔò¿ÉÄÜÊܵ½Ó°Ïì¡£

¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾


  • Cisco Smart InstallÇå¾²¼ì²â¹¤¾ß

CiscoÕë¶ÔSmart Install¹¦Ð§ÌṩÓÅÖÊÇ徲ʵ¼ù½¨Òé £¬²¢ÌṩÁËSmart Install¹¦Ð§µÄÇå¾²¼ì²é¾ç±¾ £¬ÏÂÔØÁ´½Ó£ºhttps://github.com/Cisco-Talos/smi_check

¼ì²âÒªÁìÈçÏ£º

# python smi_check.py -i 192.168.1.2

[INFO] Sending TCP probe to targetip:4786

[INFO] Smart Install Client feature active on targetip:4786

[INFO] targetip is affected


3.3         µÇ¼Cisco IOS×°±¸×Ô²é

  • vstackÉèÖÃÐÅÏ¢ÅжÏ

ÔÚ×°±¸µÄEXECÖ¸ÁîÖÐÊäÈëshow vstack config ¿ÉÒÔÅÌÎÊ×°±¸ÊÇ·ñ¿ªÆôÁËSmart Install¡£Èô·µ»ØÐ§¹ûΪRole: Client (SmartInstall enabled) »òÕßOper Mode: EnabledÔòÌåÏÖ×°±¸¿ªÆôÁËSmart Install £¬×°±¸±£´æÎ£º¦¡£


¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾



  • Cisco IOS×°±¸°æ±¾ÐÅÏ¢ÅжÏ

ÖÎÀíÔ±Óû§¿ÉÒԵǼµ½×°±¸ºóÔÙCLIÖÐÊäÈëshow versionÀ´ÅÌÎÊ×°±¸°æ±¾ £¬Í¨¹ýÓ°Ïì°æ±¾ÅжÏ×°±¸ÊÇ·ñÔÚÓ°Ïì¹æÄ£ÄÚ¡£

ios-xe-device# show version


Cisco IOS Software Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M) Version Denali 16.2.1 RELEASE SOFTWARE (fc1)

Technical Support: http://www.cisco.com/techsupport

Copyright (c) 1986-2016 by Cisco Systems Inc.

Compiled Sun 27-Mar-16 21:47 by mcpre

ʹÓøð汾ÐÅÏ¢ £¬Óû§¿ÉÒÔÔÚCisco¹Ù·½È·ÈÏÊÇ·ñÊÜÎó²îÓ° £¬²Î¿¼Á´½ÓÈçÏ£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2

»á¼ûÉÏÊöÁ´½Ó £¬½«°æ±¾ºÅÊäÈëÎı¾¿òºóµã»÷¡°Check¡±°´Å¥ £¬ÒÔ16.2.1ΪÀý £¬ÈçÏÂͼËùʾ¡£


¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾


Ö®ºóµ¯³öµÄÒ³ÃæÖлáÁгö¸Ã°æ±¾¿ÉÄܱ£´æµÄÏà¹ØÎó²î £¬ÈôÊÇ¿´µ½±£´æÈçÏÂͼºì¿òµÄËùʾµÄÎó²îÃû³Æ £¬ËµÃ÷¸Ã×°±¸±£´æÎ£º¦


¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾


³ýÊÖ¶¯ÊäÈë°æ±¾¾ÙÐÐÅÌÎÊÍâ £¬Cisco¹Ù·½Ò²ÌṩÁËshow versionÐÅÏ¢Ö±½ÓÅÌÎʵķ½·¨ £¬½«show versionÏÂÁîÖ´ÐкóµÄ°æ±¾ÐÅÏ¢ÉúÑĵ½a.txtÎļþÖÐ £¬»á¼ûCisco¹Ù·½µÄCisco IOS Software CheckerÔÚÏß¼ì²â £¬²Î¿¼Á´½ÓÈçÏ£º

https://tools.cisco.com/security/center/softwarechecker.x

½«a.txtÎļþÉÏ´« £¬¾ÙÐÐÔÚÏß¼ì²â¡£


¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾


ÏêϸµÄʹÓÃ˵Ã÷¿É²Î¿¼ÈçÏÂÊÓÆµ½Ì³Ì£º

https://players.brightcove.net/1384193102001/41XYD7gTx_default/index.html?directedMigration=true&videoId=5755100470001&


ËÄ.       ½â¾ö½¨Òé


4.1         ¹Ù·½Éý¼¶

Cisco¹Ù·½ÒѾ­Ðû²¼Á˸üв¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î £¬µ«Î´¹ûÕæ²¹¶¡µÄÏÂÔØÁ´½Ó £¬Óû§¿ÉÒÀ¸½ÒѾ­¹ºÖõÄCisco licenseÉêÇëÉý¼¶·þÎñ £¬ÇëÊÜÓ°ÏìµÄÆóҵӦʵʱÓëCisco¹Ù·½ÁªÏµ £¬»ñÈ¡×îеIJ¹¶¡³ÌÐòÉý¼¶¾ÙÐзÀ»¤¡£


¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾


4.2         ÔÝʱ·À»¤

ÇëÏà¹ØÆóÒµÆÀ¹ÀÊÇ·ñÐèÒªSmart Install·þÎñ £¬ÈôÊÇÈ·¶¨²»ÐèÒª £¬¿ÉÒÀ´ÎÊäÈëÈçÏÂÏÂÁî¿É¹Ø±Õ·þÎñ£º


switch#conf t

switch(config)#no vstack 

switch(config)#do wr

switch(config)#exit


4.3         Smart Install¹¦Ð§¹Ù·½Çå¾²½¨Òé

CiscoÕë¶ÔSmart Install¹¦Ð§ÌṩÁËÒÔÏÂÕë¶ÔÐÔµÄÇå¾²½¨Òé¡£

  • ½ûÓÃSmart Install¹¦Ð§

ͨ¹ýshow vstackÏÂÁîÉó²éSmart Install¹¦Ð§µÄ״̬ £¬±»½ûÓÃʱµÄÏÔʾÈçÏÂͼËùʾ£º


¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾


  • µ±Ê¹ÓÃSmart Install¹¦Ð§ÇÒÖ»ÓÃÓÚÁã´¥Ãþ°²ÅÅʱ £¬Çå¾²½¨ÒéÈçÏÂ.

 °²ÅÅÍê³Éºó £¬Ê¹ÓÃno vstackÏÂÁî½ûÓÃSmart Install¹¦Ð§£»

¹ØÓÚ²»Ö§³ÖvstackÏÂÁîµÄ×°±¸£¨µÍÓÚCisco IOS Release 12.2(55)SE02°æ±¾£© £¬ÔÚ½»Á÷»úÉÏͨ¹ýÉèÖÃACL×è¶Ï4786¶Ë¿Ú»á¼ûµÄ·½·¨¾ÙÐзÀ»¤¡£

  • µ±ÓªÒµÔËÐÐÐèҪʹÓÃSmart Install¹¦Ð§Ê± £¬Çå¾²½¨ÒéÈçÏ£º

ÉèÖÃACL £¬ÏÞÖÆ°×Ãûµ¥µÄ×°±¸¿É»á¼û4786¶Ë¿Ú £¬²Î¿¼ÈçÏ£º

ip access-list extended SMI_HARDENING_LIST

permit tcp host 10.10.10.1 host 10.10.10.200 eq 4786

deny tcp any any eq 4786

permit ip any any

ÏêϸÐÅÏ¢¿É²Î¿¼Á´½ÓÈçÏ£º

https://www.cisco.com/c/en/us/td/docs/switches/lan/smart_install/configuration/guide/smart_install/concepts.html#23355


Îå.       Éù Ã÷


±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌâ £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ £¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ £¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ £¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾­¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí £¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ £¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£




?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼ £¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼