Ãë¾àÁ¡ID |
29048 |
À§Çèµµ |
30 |
Æ÷Æ® |
161 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
CISCO |
»ó¼¼¼³¸í |
ÇØ´ç Cisco catalyst 5000 ½Ã¸®Áî ½ºÀ§Ä¡´Â 802.1x ÇÁ·¹ÀÓ ÀçÀü¼Û Ãë¾àÁ¡(Cisco ¹ö±× ID CSCdt62732)À» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ¼ºñ½º °ÅºÎ(DoS) °ø°ÝÀ» À¯µµÇÏ´Â µ¥¿¡ µµ¿ëµÉ ¼ö ÀÖ´Ù. Ãë¾àÇÑ Catalyst 5000 ½Ã¸®Áî ½ºÀ§Ä¡´Â STP(Spanning Tree Protocol)ÀÇ Â÷´ÜµÈ Æ÷Æ®·Î 802.1x (Æ÷Æ® ±â¹ÝÀÇ ³×Æ®¿öÅ© Á¢±ÙÁ¦¾î¸¦ À§ÇÑ IEEE Ç¥ÁØ) ÇÁ·¹ÀÓ(frame)À» ¹ÞÀ» ¶§ À̸¦ ¹ö¸®Áö ¾Ê°í VLAN (Virtual Local Area Network)À¸·Î ÀçÀü¼ÛÇÑ´Ù. À̰ÍÀº Catalyst 5000 ½Ã¸®Áî ½ºÀ§Ä¡¿¡ ÀÇÇØ VLAN ³×Æ®¿öÅ©¿¡ ¼º´É Ãæ°ÝÀ» ÁÖ´Â 802.1x ÇÁ·¹ÀÓ ³×Æ®¿öÅ© ÆøÇ³(strom)À» ÀÏÀ¸Å²´Ù. ÀÌ ³×Æ®¿öÅ© ÆøÇ³Àº ³×Æ®¿öÅ©ÀÇ ¼º´ÉÀ» ±Þ°ÝÈ÷ ÀúÇϽÃŲ´Ù. Catalyst 5000 ½Ã¸®Áî ½ºÀ§Ä¡ »ó¿¡´Â Æ÷Æ®µéÀÇ ¹ÝÀÀ¼Óµµ°¡ ´À·ÁÁ® »ç¿ëÀÚ µ¥ÀÌÅ͸¦ ó¸®ÇÏÁö ¸øÇÑ´Ù. °á±¹ ½ºÀ§Ä¡´Â SNMP, Telnet ȤÀº HTTP¸¦ °æÀ¯ÇÑ ¾î¶² °ü¸®ÀûÀÎ ÁúÀǵ鿡µµ ÀÀ´äÇÏÁö ¾Ê´Â´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ´Â Á¤Ã¥ ÆíÁý±â¿¡¼ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.cisco.com/warp/public/707/cat5k-8021x-vuln-pub.shtml
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Cisco Catalyst 5000 4.5 (11) ÀÌÇÏ Cisco Catalyst 5000 5.5 (6) ÀÌÇÏ Cisco Catalyst 5000 6.1 (2) ÀÌÇÏ |
ÇØ°áÃ¥ |
Cisco Catalyst 5000 ½Ã¸®Áî ½ºÀ§Ä¡ÀÇ °¡Àå ÃֽйöÀü(4.5(12) ȤÀº 5.5(7) ȤÀº 6.1(3) ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÀÌ ¾÷±×·¹À̵åµéÀº CiscoÀÇ À¥ »çÀÌÆ®ÀÎ http://www.cisco.com ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù.
Àӽà Á¶Ä¡¹æ¹ýµé·Î½á´Â Catalyst 5000 ½Ã¸®Áî ½ºÀ§Ä¡ ³×Æ®¿÷¿¡¼ 802.1x frames ³×Æ®¿÷¿¡¼ ÆøÇ³ÀÌ ¹ß»ýÇÏÁö ¾Êµµ·Ï 802.1x frameµéÀ» Â÷´ÜÇÏ¿©¾ß ÇÑ´Ù. ÀÌ Á¶Ä¡¹æ¹ýµéÀº ¶ÇÇÑ 802.1x frames ³×Æ®¿÷ ÆøÇ³À» ÀÏÀ¸Å³ ¼ö ÀÖ´Â ³×Æ®¿÷¿¡ Àû¿ëµÇ¾î¾ß ÇÑ´Ù.
ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ »çÀÌÆ®¿¡¼ º¼ ¼ö ÀÖ´Ù: http://www.cisco.com/warp/public/707/cat5k-8021x-vuln-pub.shtml |
°ü·Ã URL |
CVE-2001-0429 (CVE) |
°ü·Ã URL |
2604 (SecurityFocus) |
°ü·Ã URL |
6379 (ISS) |
|