漏洞信息详情
Cisco FXOS Software和NX-OS Software 输入验证漏洞
漏洞简介
Cisco Firepower 4100 Series Next-Generation Firewalls等都是美国思科(Cisco)公司的产品。Cisco Firepower 4100 Series Next-Generation Firewalls是一款4100系列的防火墙设备。Nexus 1000V Series Switches是一款1000V系列的交换机设备。FXOS Software是一套运行在思科安全设备中的防火墙软件。NX-OS Software是运行在思科交换机设备中的一套数据中心级操作系统软件。
Cisco FXOS Software和NX-OS Software中的Link Layer Discovery Protocol (LLDP)实现存在输入验证漏洞,该漏洞源于程序没有对LLDP frame包头的type、length、value(TLV)字段执行正确的输入验证。攻击者可通过向界面发送特制的LLDP数据包利用该漏洞造成设备重新加载,导致拒绝服务。以下产品受到影响:Cisco Firepower 4100 Series Next-Generation Firewall;Firepower 9300 Security Appliance;MDS 9000 Series Multilayer Switches;Nexus 2000 Series Switches;Nexus 3000 Series Switches;Nexus 3500 Platform Switches;Nexus 5500 Platform Switches;Nexus 5600 Platform Switches;Nexus 6000 Platform Switches;Nexus 7000 Series Switches;Nexus 7700 Series Switches;Nexus 9000 Series Fabric Switches(处于Application Centric Infrastructure (ACI)模式);Unified Computing System (UCS) 6100 Series Fabric Interconnects;UCS 6200 Series Fabric Interconnects;UCS 6300 Series Fabric Interconnects。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181017-fxnx-os-dos
参考网址
来源:SECTRACK
链接:http://www.securitytracker.com/id/1041919
来源:CISCO
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181017-fxnx-os-dos
来源:BID
链接:https://www.securityfocus.com/bid/105674
来源:BID
链接:http://www.securityfocus.com/bid/105674
受影响实体
暂无
补丁
- Cisco FXOS Software和NX-OS Software 输入验证漏洞的修复措施<!--2018-10-18-->
还没有评论,来说两句吧...