English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29080
À§Çèµµ 40
Æ÷Æ® 23
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù TELNET
»ó¼¼¼³¸í APC ÀåºñÀÇ Telnet ¼­ºñ½º´Â "¹éµµ¾î" ÆÐ½º¿öµå¸¦ ÅëÇØ ¾×¼¼½ºµÇ¾î Áú ¼ö ÀÖ´Ù.
APC (American Power Conversion) SmartSwitch¿Í UPS (uninterruptible power supply) Á¦Ç°µéÀº ·ÎÄà ½Ã¸®¾ó ÄܼÖ, TELNET, À¥ ¹× SNMPÀÇ °ü¸®, ¸ð´ÏÅ͸µ ±×¸®°í ºÎÂøµÈ ÀåÄ¡µéÀÇ ÆÄ¿ö ÄÁÆ®·ÑÀÇ °ü¸®¸¦ À§ÇØ ¼³Ä¡µÈ À¥ ¹× SNMP °ü¸®¿ë Ä«µå¸¦ °¡Áö°í ÀÖ´Ù.
APC SmartSlot Web/SNMP °ü¸®¿ë Ä«µå´Â ¸ðµç °èÁ¤µé¿¡ ´ëÇÑ ºñ¾Ïȣȭ ÅØ½ºÆ®·Î µÈ ±¸Ã¼ÀûÀÎ »ç¿ëÀÚ¸í/ÆÐ½º¿öµå¸¦ ²ø¾î³»´Âµ¥ µµ¿ëµÇ°Å³ª, ³ª¾Æ°¡ Àåºñ¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ¾ò¾î³¾ ¼ö ÀÖ´Â ÇϳªÀÇ "¹éµµ¾î" ÆÐ½º¿öµå¸¦ °¡Áö°í ÀÖ´Ù. "¹éµµ¾î" ÆÐ½º¿öµå´Â MAC ÁÖ¼Ò, ÀÏ·Ã ¹øÈ£ µî°ú °°Àº Ä«µåÀÇ Ãʱ⠼³Á¤À» À§ÇØ °øÀå¿¡¼­ »ç¿ëÇÏ´Â ¸ñÀûÀ¸·Î °í¾ÈµÇ¾ú´Ù. ÀÓÀÇÀÇ »ç¿ëÀÚ¸í°ú °øÀå ÆÐ½º¿öµåÀÎ 'TENmanUFactOryPOWER'À» °¡Áö°í ·ÎÄà ½Ã¸®¾ó Æ÷Æ®·ÎÀÇ ÄܼÖÀ̳ª Ä«µå·ÎÀÇ TELNET ¼­ºñ½º¿¡ Á¢¼ÓÇÔÀ¸·Î½á, °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â Àåºñ¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù. ±×¸®°í À̸¦ ÅëÇØ °èÁ¤ »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµåµéÀ» Æ÷ÇÔÇÏ¿© ¿©·¯ °¡Áö °ÍµéÀ» ÀúÀåÇϰí ÀÖ´Â EEPROMÀÇ ³»¿ëµéÀ» º¼ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/354169
http://www.securiteam.com/securitynews/5MP0E2AC0M.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SmartUPS 3000RM (AP9606 AOS v3.2.1 ±×¸®°í SmartUPS App v3.2.6À» °¡Áø Àåºñ)
MasterSwitch AP9212 (AP9606 AOS v3.0.3 ±×¸®°í MasterSwitch App v2.2.0À» °¡Áø Àåºñ)
Silcon DP3320E (Web/SNMP Management Card AP9606 - AOS v3.0.1À» °¡Áø Àåºñ)
Silcon DP340E (Web/SNMP Management Card AP9606 - AOS v3.0.1À» °¡Áø Àåºñ)
ÇØ°áÃ¥ ´ÙÀ½ APC º¸¾È ±Ç°í¾È, 'Static Factory Password Vulnerability'¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_sid=XvzUth4h&p_lva=&p_faqid=3131&p_created=1077139129&p_sp=cF9zcmNoPSZwX2dyaWRzb3J0PSZwX3Jvd19jbnQ9MTQxOSZwX3BhZ2U9MQ**&p_li=

¸¸¾à ¸î¸î ÀÌÀ¯·Î ÆÐÄ¡¸¦ Àû¿ëÇÒ ¼ö ¾ø´Ù¸é:

A. ÆÐÄ¡°¡ Àû¿ëµÇ±â Àü±îÁö Telnet ÇÁ·ÎÅäÄÝÀ» »ç¿ëÁßÁö ½ÃŲ´Ù (¹æ¹ýÀº À§ÀÇ URL¿¡ ÀÖ´Â Appendix A¸¦ Âü°í). ¸¸¾à À̰ÍÀÌ ºÒ°¡´ÉÇÏ´Ù¸é ÆÐÄ¡°¡ Àû¿ëµÇ±â Àü±îÁö ³×Æ®¿öÅ©·ÎºÎÅÍ Á¦Ç°À» ´ÜÀý½ÃÄÑ ³õ´Â´Ù.
B. ¸¸¾à ÄÜ¼Ö Æ÷Æ® ¼­¹ö°¡ Ãë¾àÇÑ Á¦Ç°ÀÇ ·ÎÄà ½Ã¸®¾ó Æ÷Æ®¿¡ ¿¬°áµÇ¾î ÀÖ´Ù¸é Á¦Ç°À¸·ÎÀÇ ·Î±×ÀÎÀ» Çã¿ëÇϱ⿡ ¾Õ¼­ ÄÜ¼Ö Æ÷Æ® ¼­¹ö°¡ ¹Ýµå½Ã »ç¿ëÀÚ ÀÎÁõÀ» °ÅÄ¡µµ·Ï ÇØ ³õ¾Æ¾ß ÇÑ´Ù. ¸¸¾à À̰ÍÀÌ ºÒ°¡´ÉÇÏ´Ù¸é ÆÐÄ¡°¡ Àû¿ëµÇ±â Àü±îÁö ÄÜ¼Ö Æ÷Æ® ¼­¹ö·ÎºÎÅÍ Á¦Ç°À» ´ÜÀý½ÃÄÑ ³õ´Â´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 9681 (SecurityFocus)
°ü·Ã URL (ISS)