Cisco IOS/IOS XEÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-0171£©
2018-04-10
Ò». Îó²î¸ÅÊö
2018Äê3ÔÂ28ÈÕ£¬Cisco IOSÒÔ¼°IOS XEÈí¼þ±»·¢Ã÷±£´æÒ»¸öÑÏÖØÎó²îCVE-2018-0171¡£¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýÖØÐ¼ÓÔØ£¨reload£©×°±¸Ôì³É¾Ü¾ø·þÎñÌõ¼þ£¬»òÕßÔ¶³ÌÖ´ÐдúÂë¡£Smart InstallÊÇΪеÄLANÒÔÌ«Íø½»Á÷»úÌṩÁã´¥Ãþ°²Åŵﴲ弴ÓÃÉèÖúÍͼÐÎÖÎÀí¹¦Ð§£¬ÔÚTCP¶Ë¿Ú4786ÉÏÔËÐеÄCiscoרÓÃÐÒ飬Èô×°±¸ÆôÓÃÁËSmart Install¹¦Ð§ÇÒ¶ÔÍ⿪·Å4786¶Ë¿Ú£¬¹¥»÷Õ߾ͿÉͨ¹ý·¢ËÍ»ûÐÎSmart Install±¨ÎÄÀ´Ê¹ÓôËÎó²î£¬Ê¹µÃ×°±¸»º³åÇøÒç³ö£¬µ¼Ö¾ܾø·þÎñÒÔÖÂÔ¶³Ì´úÂëÖ´ÐеÈЧ¹û¡£
Ïà¹ØÁ´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2
4ÔÂ8ÈÕ£¬¹¥»÷ÕßÒÉËÆÊ¹ÓÃÁË˼¿ÆIOS/IOS XEÔ¶³Ì´úÂëÖ´ÐÐÎó²îcve-2018-0171¾ÙÐдó¹æÄ£¹¥»÷£¬ÆäÖаüÀ¨º£ÄÚ¶à¸ö»ú¹¹£¬ÔâÊܹ¥»÷µÄÆóÒµ»áµ¼ÖÂ×°±¸Ì±»¾£¬Í¬Ê±ÉèÖÃÎļþ±»Ð޸ġ£
Ëù±¬³öµÄÎó²îÓ°ÏìËùÓÐÔËÐÐCisco IOS»òIOS XEÈí¼þ²¢ÇÒ¿ªÆôÁËÖÇÄÜ×°Öã¨Smart Install£©ÌØÕ÷µÄ×°±¸£¬ÏêÇéÇë²Î¿¼Cisco¹Ù·½Í¨¸æ£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2
ÏÖÔÚÒÑÖªÊÜÓ°Ïì×°±¸/Èí¼þΪ£º
|
È·ÈÏÊÜÓ°ÏìµÄ×°±¸Ðͺţº ? Catalyst 4500 Supervisor Engines ? Cisco Catalyst 3850 Series Switches ? Cisco Catalyst 2960 Series Switches ¿ÉÄÜÊÜÓ°ÏìµÄ×°±¸Ðͺţº ? Catalyst 4500 Supervisor Engines ? Catalyst 3850 Series ? Catalyst 3750 Series ? Catalyst 3650 Series ? Catalyst 3560 Series ? Catalyst 2960 Series ? Catalyst 2975 Series ? IE 2000 ? IE 3000 ? IE 3010 ? IE 4000 ? IE 4010 ? IE 5000 ? SM-ES2 SKUs ? SM-ES3 SKUs ? NME-16ES-1G-P ? SM-X-ES3 SKUs |
Èý. Ó°ÏìÅŲé
Îó²îÓ°ÏìµÄÊÇÆôÓÃÁËSmart Install¹¦Ð§µÄ×°±¸£¬ÔÚTCP¶Ë¿Ú4786ÉÏÔËÐеÄCiscoרÓÃÐÒ飬µ±4780¶Ë¿Ú¿ª·ÅÓÚÍâÍøÊ±£¬¿ÉÔì³É¸ü´óµÄÓ°Ï죬¾ÅÓÎÀÏ¸ç¿Æ¼¼½¨Òéͨ¹ýÈçϼƻ®¾ÙÐÐÅŲ飺
3.1 ¾ÅÓÎÀÏ¸ç¿Æ¼¼»¥ÁªÍø×ʲúºË²é
ΪʹÆóÒµ¿Í»§ÏàÊ¶ÖØ´óÖØ´óµÄ×ʲúÀàÐÍÔÚ»¥ÁªÍøÉϵÄ̻¶ÇéÐΣ¬°üÀ¨¶Ë¿Ú¡¢Ó¦Óá¢ÏµÍ³ÀàÐÍ¡¢µØÀíÂþÑܵȣ¬Ô¤Öª¿ÉÄܱ£´æµÄΣº¦£¬²¢½ÓÄÉÏà¹ØµÄ¿ØÖƲ½·¥£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼Ìṩ»ùÓÚNTIµÄ»¥ÁªÍø×ʲúºË²é·þÎñ£¬¿ìËÙÅжÏÃæÏò»¥ÁªÍøµÄ×ʲúÊÇ·ñÊܵ½Cisco Smart InstallÎó²îÒÔ¼°ÆäËû¿ÉʹÓÃÎó²îµÄÓ°Ï죬ÈçÐèÐÖú£¬¿ÉÁªÏµNTI@nsfocus.com¡£
3.2 ÅŲéSmart InstallÊÇ·ñ¿ªÆô
- ¶Ë¿ÚɨÃè
¼ì²âÄ¿µÄ×°±¸ÊÇ·ñ¿ªÆô4786/TCP¶Ë¿Ú£¬Ê¹ÓÃnmapɨÃèÄ¿µÄ×°±¸¶Ë¿Ú£¬ÈôÊÇ¿ªÆôÔò¿ÉÄÜÊܵ½Ó°Ïì¡£
- Cisco Smart InstallÇå¾²¼ì²â¹¤¾ß
CiscoÕë¶ÔSmart Install¹¦Ð§ÌṩÓÅÖÊÇ徲ʵ¼ù½¨Ò飬²¢ÌṩÁËSmart Install¹¦Ð§µÄÇå¾²¼ì²é¾ç±¾£¬ÏÂÔØÁ´½Ó£ºhttps://github.com/Cisco-Talos/smi_check
¼ì²âÒªÁìÈçÏ£º
|
# python smi_check.py -i 192.168.1.2 [INFO] Sending TCP probe to targetip:4786 [INFO] Smart Install Client feature active on targetip:4786 [INFO] targetip is affected |
3.3 µÇ¼Cisco IOS×°±¸×Ô²é
- vstackÉèÖÃÐÅÏ¢ÅжÏ
ÔÚ×°±¸µÄEXECÖ¸ÁîÖÐÊäÈëshow vstack config ¿ÉÒÔÅÌÎÊ×°±¸ÊÇ·ñ¿ªÆôÁËSmart Install¡£Èô·µ»ØÐ§¹ûΪRole: Client (SmartInstall enabled) »òÕßOper Mode: EnabledÔòÌåÏÖ×°±¸¿ªÆôÁËSmart Install£¬×°±¸±£´æÎ£º¦¡£
- Cisco IOS×°±¸°æ±¾ÐÅÏ¢ÅжÏ
ÖÎÀíÔ±Óû§¿ÉÒԵǼµ½×°±¸ºóÔÙCLIÖÐÊäÈëshow versionÀ´ÅÌÎÊ×°±¸°æ±¾£¬Í¨¹ýÓ°Ïì°æ±¾ÅжÏ×°±¸ÊÇ·ñÔÚÓ°Ïì¹æÄ£ÄÚ¡£
|
ios-xe-device# show version
Cisco IOS Software Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M) Version Denali 16.2.1 RELEASE SOFTWARE (fc1) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2016 by Cisco Systems Inc. Compiled Sun 27-Mar-16 21:47 by mcpre |
ʹÓøð汾ÐÅÏ¢£¬Óû§¿ÉÒÔÔÚCisco¹Ù·½È·ÈÏÊÇ·ñÊÜÎó²îÓ°£¬²Î¿¼Á´½ÓÈçÏ£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2
»á¼ûÉÏÊöÁ´½Ó£¬½«°æ±¾ºÅÊäÈëÎı¾¿òºóµã»÷¡°Check¡±°´Å¥£¬ÒÔ16.2.1ΪÀý£¬ÈçÏÂͼËùʾ¡£
Ö®ºóµ¯³öµÄÒ³ÃæÖлáÁгö¸Ã°æ±¾¿ÉÄܱ£´æµÄÏà¹ØÎó²î£¬ÈôÊÇ¿´µ½±£´æÈçÏÂͼºì¿òµÄËùʾµÄÎó²îÃû³Æ£¬ËµÃ÷¸Ã×°±¸±£´æÎ£º¦
³ýÊÖ¶¯ÊäÈë°æ±¾¾ÙÐÐÅÌÎÊÍ⣬Cisco¹Ù·½Ò²ÌṩÁËshow versionÐÅÏ¢Ö±½ÓÅÌÎʵķ½·¨£¬½«show versionÏÂÁîÖ´ÐкóµÄ°æ±¾ÐÅÏ¢ÉúÑĵ½a.txtÎļþÖУ¬»á¼ûCisco¹Ù·½µÄCisco IOS Software CheckerÔÚÏß¼ì²â£¬²Î¿¼Á´½ÓÈçÏ£º
https://tools.cisco.com/security/center/softwarechecker.x
½«a.txtÎļþÉÏ´«£¬¾ÙÐÐÔÚÏß¼ì²â¡£
ÏêϸµÄʹÓÃ˵Ã÷¿É²Î¿¼ÈçÏÂÊÓÆµ½Ì³Ì£º
https://players.brightcove.net/1384193102001/41XYD7gTx_default/index.html?directedMigration=true&videoId=5755100470001&
ËÄ. ½â¾ö½¨Òé
4.1 ¹Ù·½Éý¼¶
Cisco¹Ù·½ÒѾÐû²¼Á˸üв¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬µ«Î´¹ûÕæ²¹¶¡µÄÏÂÔØÁ´½Ó£¬Óû§¿ÉÒÀ¸½ÒѾ¹ºÖõÄCisco licenseÉêÇëÉý¼¶·þÎñ£¬ÇëÊÜÓ°ÏìµÄÆóҵӦʵʱÓëCisco¹Ù·½ÁªÏµ£¬»ñÈ¡×îеIJ¹¶¡³ÌÐòÉý¼¶¾ÙÐзÀ»¤¡£
4.2 ÔÝʱ·À»¤
ÇëÏà¹ØÆóÒµÆÀ¹ÀÊÇ·ñÐèÒªSmart Install·þÎñ£¬ÈôÊÇÈ·¶¨²»ÐèÒª£¬¿ÉÒÀ´ÎÊäÈëÈçÏÂÏÂÁî¿É¹Ø±Õ·þÎñ£º
|
switch#conf t switch(config)#no vstack switch(config)#do wr switch(config)#exit |
4.3 Smart Install¹¦Ð§¹Ù·½Çå¾²½¨Òé
CiscoÕë¶ÔSmart Install¹¦Ð§ÌṩÁËÒÔÏÂÕë¶ÔÐÔµÄÇå¾²½¨Òé¡£
- ½ûÓÃSmart Install¹¦Ð§
ͨ¹ýshow vstackÏÂÁîÉó²éSmart Install¹¦Ð§µÄ״̬£¬±»½ûÓÃʱµÄÏÔʾÈçÏÂͼËùʾ£º
- µ±Ê¹ÓÃSmart Install¹¦Ð§ÇÒÖ»ÓÃÓÚÁã´¥Ãþ°²ÅÅʱ£¬Çå¾²½¨ÒéÈçÏÂ.
°²ÅÅÍê³Éºó£¬Ê¹ÓÃno vstackÏÂÁî½ûÓÃSmart Install¹¦Ð§£»
¹ØÓÚ²»Ö§³ÖvstackÏÂÁîµÄ×°±¸£¨µÍÓÚCisco IOS Release 12.2(55)SE02°æ±¾£©£¬ÔÚ½»Á÷»úÉÏͨ¹ýÉèÖÃACL×è¶Ï4786¶Ë¿Ú»á¼ûµÄ·½·¨¾ÙÐзÀ»¤¡£
- µ±ÓªÒµÔËÐÐÐèҪʹÓÃSmart Install¹¦Ð§Ê±£¬Çå¾²½¨ÒéÈçÏ£º
ÉèÖÃACL£¬ÏÞÖÆ°×Ãûµ¥µÄ×°±¸¿É»á¼û4786¶Ë¿Ú£¬²Î¿¼ÈçÏ£º
|
ip access-list extended SMI_HARDENING_LIST permit tcp host 10.10.10.1 host 10.10.10.200 eq 4786 deny tcp any any eq 4786 permit ip any any |
ÏêϸÐÅÏ¢¿É²Î¿¼Á´½ÓÈçÏ£º
https://www.cisco.com/c/en/us/td/docs/switches/lan/smart_install/configuration/guide/smart_install/concepts.html#23355
Îå. Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ





