Management Console, Ãë¾àÇÑ ½Ã½ºÅÛ ¼³Á¤À¸·Î ÀÎÁõ ¿ìȸÇÏ´Â ±ÇÇÑ»ó½Â Ãë¾àÁ¡ ¹ß°ß
[º¸¾È´º½º ±è°æ¾Ö ±âÀÚ] ½Ã½ºÄÚ(Cisco)°¡ ÀÚ»ç Á¦Ç°ÀÇ Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ °øÁöÇß´Ù. °ø°ÝÀÚ°¡ ÇØ´ç Ãë¾àÁ¡À» ÀÌ¿ëÇØ ¿ø°ÝÄÚµå ½ÇÇà µîÀÇ ÇÇÇظ¦ ¹ß»ý½Ãų ¼ö ÀÖ¾î ÇØ´ç Á¦Ç°À» »ç¿ëÇÏ´Â ÀÌ¿ëÀÚµéÀº ÃֽŠ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÏ´Â °ÍÀÌ ¹Ù¶÷Á÷ÇÏ´Ù.
[À̹ÌÁö=½Ã½ºÄÚ È¨ÆäÀÌÁö]
À̹ø¿¡ ¹ß°ßµÈ Ãë¾àÁ¡Àº Cisco Unity Express(CUE)¿¡¼ ÀÚ¹Ù ¿ÀºêÁ§Æ®¸¦ ¿ªÁ÷·ÄÈÇÏ´Â °úÁ¤¿¡¼ ¹ß»ýÇÏ´Â ¿ø°ÝÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ Ãë¾àÁ¡(CVE-2018-15381)[1]°ú Cisco Stealthwatch EnterpriseÀÇ Management Console¿¡¼ Ãë¾àÇÑ ½Ã½ºÅÛ ¼³Á¤À¸·Î ÀÎÇØ °ø°ÝÀÚ°¡ ÀÎÁõÀ» ¿ìȸÇÏ¿© ±ÇÇÑ »ó½ÂÀÌ °¡´ÉÇÑ Ãë¾àÁ¡(CVE-2018-15394)[2]ÀÌ´Ù.
¿µÇâÀ» ¹Þ´Â Á¦Ç°Àº Cisco Unity Express- 9.0.6 ÀÌÀü ¹öÀü°ú Cisco Stealthwatch Enterprise- 6.10.2¸¦ Æ÷ÇÔÇÑ ÀÌÀü ¹öÀüÀÌ´Ù.
µû¶ó¼ Ãë¾àÁ¡ÀÌ ¹ß»ýÇÑ Cisco Á¦Ç° ÀÌ¿ëÀÚ´Â Âü°í»çÀÌÆ®¿¡ ¸í½ÃµÇ¾î ÀÖ´Â ¡®Fixed Software¡¯ ³»¿ëÀ» È®ÀÎÇØ ÆÐÄ¡¸¦ Àû¿ëÇÏ´Â °ÍÀÌ ¹Ù¶÷Á÷ÇÏ´Ù.
Á»´õ ÀÚ¼¼ÇÑ »çÇ×Àº Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ¿¡ ¹®ÀÇÇÏ¸é µÈ´Ù.
[Âü°í»çÀÌÆ®]
[1]https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-cue
[2]https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-smc-auth-bypass
[±è°æ¾Ö ±âÀÚ(boan3@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>