English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29035
À§Çèµµ 40
Æ÷Æ® 161
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù CISCO
»ó¼¼¼³¸í ÇØ´ç Cisco ºñ-IOS Àåºñ´Â ºñÁ¤»óÀûÀÎ SNMP ¸Þ½ÃÁö 󸮰úÁ¤ »óÀÇ Ãë¾àÁ¡µé(Cisco ¹ö±× ID CSCdw67458)À» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¼­ºñ½º°ÅºÎ °ø°Ý (DoS) °ø°ÝÀ» ¹Ýº¹ÀûÀ¸·Î ¼öÇàÇÏ´Â µ¥¿¡ µµ¿ëµÉ ¼ö ÀÖ´Ù. Ãë¾àÁ¡µéÀÌ µµ¿ëµÉ ¶§, Ãë¾àÁ¡µéÀº Ãë¾àÇÑ Cisco Á¦Ç°ÀÇ Å©·¡½¬, ȤÀº Àç½ÃÀÛ(Reload)À» À¯¹ßÇÑ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿­À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ­´Â Á¤Ã¥ ÆíÁý±â¿¡¼­ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿­À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cisco.com/warp/public/707/cisco-malformed-snmp-msgs-non-ios-pub.shtml
http://www.cert.org/advisories/CA-2002-03.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
À§ 'Âü°í »çÀÌÆ®'¿¡ ÀÖ´Â Cisco º¸¾È ±Ç°í¾È Âü°í
ÇØ°áÃ¥ ¹®Á¦°¡ ÇØ°áµÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. Catalyst 4000, Catalyst 5000, Catalyst 6000 ÆÐ¹Ð¸®¿¡ ´ëÇØ °¡Àå ¸ÕÀú ³ª¿Â ¸±¸®Áî´Â ´ÙÀ½°ú °°´Ù:
7.1(2), 7.1(1a), 6.3(5), 6.3(4a), 6.3(3a), 6.3(2a), 6.3(1a), 6.3(3)X1, 6.2(3a), 6.2(2a), 6.2(1a), 6.1(4b), 6.1(3a), 6.1(2a), 6.1(1e), 5.5(13a), 5.5(12a), 5.5(11a), 5.5(10a), 5.5(7a), 5.4(4a), 5.4(2a), 5.3(6a)CSX, 5.2(7a), 5.2(3a)CSX, 5.1(2b), 5.1(1a)CSX, 4.5(13a), 4.5(12a), 4.5(6a)

¸ðµç °æ¿ìµé¿¡ ÀÖ¾î, °í°´µéÀº ¾÷±×·¹ÀÌµå µÇ¾î¾ß ÇÏ´Â µð¹ÙÀ̽ºµéÀÌ ÃæºÐÇÑ ¸Þ¸ð¸®¸¦ °¡Áö°í ÀÖ´ÂÁö, ±×¸®°í ÇöÀçÀÇ Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î ¼³Á¤µéÀÌ »õ·Î¿î ¼ÒÇÁÆ®¿þ¾î ¸±¸®Áî¿¡¼­µµ °è¼ÓÀûÀ¸·Î Àß Áö¿øµÉ ¼ö ÀÖ´ÂÁö¸¦ È®ÀÎÇÏ¿©¾ß ÇÑ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â, ³×Æ®¿÷ °ü¸® ¿÷½ºÅ×À̼ǵ鿡 ´ëÇØ¼­¸¸ ½ºÀ§Ä¡ÀÇ °ü¸® ÀÎÅÍÆäÀ̽º·ÎÀÇ ¾×¼¼½º°¡ °¡´ÉÇϵµ·Ï SNMP¿¡ ´ëÇÑ IP Permit List¸¦ Àû¿ëÇÏ´Â °ÍÀÌ´Ù. ¹æ¹ý¿¡ °üÇÑ ¸í·ÉµéÀº ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¸é µÈ´Ù:
http://www.cisco.com/univercd/cc/td/doc/product/lan/cat5000/rel_6_3/config/ip_perm.htm.

ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ »çÀÌÆ®¿¡¼­ º¼ ¼ö ÀÖ´Ù:
http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml
°ü·Ã URL CVE-2002-0012,CVE-2002-0013 (CVE)
°ü·Ã URL 4088 (SecurityFocus)
°ü·Ã URL 8177 (ISS)