漏洞信息详情
Cisco Catalyst 4500系列和Cisco Catalyst 4500-X系列转换器IOS和IOS XE Software 代码问题漏洞
漏洞简介
Cisco Catalyst 4500 Series Switches和Cisco Catalyst 4500-X Series Switches都是美国思科(Cisco)公司的产品。Cisco Catalyst 4500 Series Switches是一款4500系列交换机。Cisco Catalyst 4500-X Series Switches是一款4500-X系列交换机。
Cisco Catalyst 4500系列和Cisco Catalyst 4500-X系列转换器中的IOS和IOS XE Software的Bidirectional Forwarding Detection (BFD) offload实现存在代码问题漏洞,该漏洞源于程序没有充分的处理错误。远程攻击者可通过发送特制的BFD消息利用该漏洞造成拒绝服务(崩溃)。以下产品受到影响:Cisco Catalyst 4500 Supervisor Engine 6-E (K5);Catalyst 4500 Supervisor Engine 6L-E (K10);Catalyst 4500 Supervisor Engine 7-E (K10);Catalyst 4500 Supervisor Engine 7L-E (K10);Catalyst 4500E Supervisor Engine 8-E (K10);Catalyst 4500E Supervisor Engine 8L-E (K10);Catalyst 4500E Supervisor Engine 9-E (K10);Catalyst 4500-X Series Switches (K10);Catalyst 4900M Switch (K5);Catalyst 4948E Ethernet Switch (K5)。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-bfd
参考网址
来源:CONFIRM
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-bfd
来源:SECTRACK
链接:http://www.securitytracker.com/id/1040587
来源:BID
链接:https://www.securityfocus.com/bid/103565
来源:MISC
链接:https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-bfd
受影响实体
- Cisco Ios:3.6%282%29e<!--2000-1-1-->
- Cisco Ios_xe:3.6%282%29e<!--2000-1-1-->
- Cisco Ios_xe:3.6%282%29e<!--2000-1-1-->
- Cisco Ios:3.6%282%29e<!--2000-1-1-->
补丁
- Cisco Catalyst 4500系列和Cisco Catalyst 4500-X系列转换器IOS和IOS XE Software 安全漏洞的修复措施<!--2018-3-29-->
还没有评论,来说两句吧...