English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29067
À§Çèµµ 30
Æ÷Æ® 161
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù CISCO
»ó¼¼¼³¸í ÇØ´ç Cisco VPN 3000 ½Ã¸®Áî concentrator´Â ´ÙÀ½°ú °°Àº XML ÇÊÅÍ¿Í À¥ ÀÎÅÍÆäÀ̽º¿¡ ´ÙÁß Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù:

1. XML public rule Ãë¾àÁ¡ (¹ö±× ID CSCdx07754) - ¸¸¾à XML ÇÊÅÍ ¼³Á¤ÀÌ ÀÛµ¿µÇ°í ÀÖ´Ù¸é, "HTTPS on Public Inbound (XML-Auto)(forward/in)" ·êÀÌ public filter¿¡ Ãß°¡µÇ¸ç, À̶§ "443"À¸·Î ¼³Á¤µÈ ¸ñÀûÁö Æ÷Æ®¸¦ °¡Áø ä ÇÁ·ÎÅäÄÝÀÇ °ªÀÌ "ANY"·Î À߸ø ¼³Á¤µÇ°Ô µÈ´Ù. ÀÌ´Â ÀÓÀÇÀÇ ÇÁ·ÎÅäÄÝÀÌ ÀÓÀÇÀÇ Æ÷Æ®¸¦ ÅëÇØ¼­ Concentrator¸¦ ¾×¼¼½ºÇÏ°Ô ÇØ ÁÖ´Â °ÍÀ̹ǷΠ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡°Ô ³×Æ®¿öÅ©¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.
2. HTML ÆäÀÌÁö ¾×¼¼½º Ãë¾àÁ¡ (¹ö±× ID CSCdx24622) - Ãë¾àÇÑ Àåºñ´Â ¿ø°ÝÁöÀÇ »ç¿ëÀÚ°¡ ƯÁ¤ HTML ÆäÀÌÁöµéÀ» Á÷Á¢ ¾×¼¼½º ÇÑ´Ù¸é ÀÎÁõ¾øÀÌ Áß¿äÇÑ Á¤º¸¸¦ ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
3. HTML ·Î±×ÀΠó¸® Ãë¾àÁ¡ (¹ö±× ID CSCdx24632) - VPN concentrator »ó¿¡ ÀÖ´Â HTML ÀÎÅÍÆäÀ̽º¸¦ ¾×¼¼½ºÇÒ ¶§, HTML ÆÄÀÏÀ» ¼öÁ¤ÇÏ¿© »ç¿ëÀÚ¸í/ÆÐ½º¿öµå·Î ¸Å¿ì ±ä ¹®ÀÚ¿­µéÀ» Æ÷½ºÆÃ ÇÏ°Ô µÇ¸é Ãë¾àÇÑ Àåºñ°¡ Àç½ÃÀÛÀ» ÀÏÀ¸Å³ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿­À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ­´Â Á¤Ã¥ ÆíÁý±â¿¡¼­ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿­À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Cisco VPN 3000 series concentrator release 3.5.3 ¹Ì¸¸
Cisco VPN 3000 series concentrator release 3.1.x
Cisco VPN 3000 series concentrator release 3.0.x
Cisco VPN 3000 series concentrator release 2.x.x
ÇØ°áÃ¥ Cisco VPN concentratorÀÇ °¡Àå ÃֽйöÀü(3.6(Rel) ȤÀº 3.5.3 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÀÌ ¾÷±×·¹À̵åµéÀº CiscoÀÇ À¥ »çÀÌÆ®ÀÎ www.cisco.com/cisco/pub/software/portal/select.html?i=!s&mdfid=268438163 ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù.

´õ ÀÚ¼¼ÇÑ Á¤º¸¿Í Àӽà Á¶Ä¡¹æ¹ýµéÀº ´ÙÀ½ »çÀÌÆ®¿¡¼­ º¼ ¼ö ÀÖ´Ù:
http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml
°ü·Ã URL CVE-2002-1098,CVE-2002-1099,CVE-2002-1100 (CVE)
°ü·Ã URL 5609,5614,5616,5617 (SecurityFocus)
°ü·Ã URL 10023,10024,10025 (ISS)