Ãë¾àÁ¡ID |
29080 |
À§Çèµµ |
40 |
Æ÷Æ® |
23 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
TELNET |
»ó¼¼¼³¸í |
APC ÀåºñÀÇ Telnet ¼ºñ½º´Â "¹éµµ¾î" ÆÐ½º¿öµå¸¦ ÅëÇØ ¾×¼¼½ºµÇ¾î Áú ¼ö ÀÖ´Ù. APC (American Power Conversion) SmartSwitch¿Í UPS (uninterruptible power supply) Á¦Ç°µéÀº ·ÎÄà ½Ã¸®¾ó ÄܼÖ, TELNET, À¥ ¹× SNMPÀÇ °ü¸®, ¸ð´ÏÅ͸µ ±×¸®°í ºÎÂøµÈ ÀåÄ¡µéÀÇ ÆÄ¿ö ÄÁÆ®·ÑÀÇ °ü¸®¸¦ À§ÇØ ¼³Ä¡µÈ À¥ ¹× SNMP °ü¸®¿ë Ä«µå¸¦ °¡Áö°í ÀÖ´Ù. APC SmartSlot Web/SNMP °ü¸®¿ë Ä«µå´Â ¸ðµç °èÁ¤µé¿¡ ´ëÇÑ ºñ¾ÏÈ£È ÅØ½ºÆ®·Î µÈ ±¸Ã¼ÀûÀÎ »ç¿ëÀÚ¸í/ÆÐ½º¿öµå¸¦ ²ø¾î³»´Âµ¥ µµ¿ëµÇ°Å³ª, ³ª¾Æ°¡ Àåºñ¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ¾ò¾î³¾ ¼ö ÀÖ´Â ÇϳªÀÇ "¹éµµ¾î" ÆÐ½º¿öµå¸¦ °¡Áö°í ÀÖ´Ù. "¹éµµ¾î" ÆÐ½º¿öµå´Â MAC ÁÖ¼Ò, ÀÏ·Ã ¹øÈ£ µî°ú °°Àº Ä«µåÀÇ Ãʱ⠼³Á¤À» À§ÇØ °øÀå¿¡¼ »ç¿ëÇÏ´Â ¸ñÀûÀ¸·Î °í¾ÈµÇ¾ú´Ù. ÀÓÀÇÀÇ »ç¿ëÀÚ¸í°ú °øÀå ÆÐ½º¿öµåÀÎ 'TENmanUFactOryPOWER'À» °¡Áö°í ·ÎÄà ½Ã¸®¾ó Æ÷Æ®·ÎÀÇ ÄܼÖÀ̳ª Ä«µå·ÎÀÇ TELNET ¼ºñ½º¿¡ Á¢¼ÓÇÔÀ¸·Î½á, °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â Àåºñ¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù. ±×¸®°í À̸¦ ÅëÇØ °èÁ¤ »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµåµéÀ» Æ÷ÇÔÇÏ¿© ¿©·¯ °¡Áö °ÍµéÀ» ÀúÀåÇϰí ÀÖ´Â EEPROMÀÇ ³»¿ëµéÀ» º¼ ¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/354169 http://www.securiteam.com/securitynews/5MP0E2AC0M.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: SmartUPS 3000RM (AP9606 AOS v3.2.1 ±×¸®°í SmartUPS App v3.2.6À» °¡Áø Àåºñ) MasterSwitch AP9212 (AP9606 AOS v3.0.3 ±×¸®°í MasterSwitch App v2.2.0À» °¡Áø Àåºñ) Silcon DP3320E (Web/SNMP Management Card AP9606 - AOS v3.0.1À» °¡Áø Àåºñ) Silcon DP340E (Web/SNMP Management Card AP9606 - AOS v3.0.1À» °¡Áø Àåºñ) |
ÇØ°áÃ¥ |
´ÙÀ½ APC º¸¾È ±Ç°í¾È, 'Static Factory Password Vulnerability'¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_sid=XvzUth4h&p_lva=&p_faqid=3131&p_created=1077139129&p_sp=cF9zcmNoPSZwX2dyaWRzb3J0PSZwX3Jvd19jbnQ9MTQxOSZwX3BhZ2U9MQ**&p_li=
¸¸¾à ¸î¸î ÀÌÀ¯·Î ÆÐÄ¡¸¦ Àû¿ëÇÒ ¼ö ¾ø´Ù¸é:
A. ÆÐÄ¡°¡ Àû¿ëµÇ±â Àü±îÁö Telnet ÇÁ·ÎÅäÄÝÀ» »ç¿ëÁßÁö ½ÃŲ´Ù (¹æ¹ýÀº À§ÀÇ URL¿¡ ÀÖ´Â Appendix A¸¦ Âü°í). ¸¸¾à À̰ÍÀÌ ºÒ°¡´ÉÇÏ´Ù¸é ÆÐÄ¡°¡ Àû¿ëµÇ±â Àü±îÁö ³×Æ®¿öÅ©·ÎºÎÅÍ Á¦Ç°À» ´ÜÀý½ÃÄÑ ³õ´Â´Ù. B. ¸¸¾à ÄÜ¼Ö Æ÷Æ® ¼¹ö°¡ Ãë¾àÇÑ Á¦Ç°ÀÇ ·ÎÄà ½Ã¸®¾ó Æ÷Æ®¿¡ ¿¬°áµÇ¾î ÀÖ´Ù¸é Á¦Ç°À¸·ÎÀÇ ·Î±×ÀÎÀ» Çã¿ëÇϱ⿡ ¾Õ¼ ÄÜ¼Ö Æ÷Æ® ¼¹ö°¡ ¹Ýµå½Ã »ç¿ëÀÚ ÀÎÁõÀ» °ÅÄ¡µµ·Ï ÇØ ³õ¾Æ¾ß ÇÑ´Ù. ¸¸¾à À̰ÍÀÌ ºÒ°¡´ÉÇÏ´Ù¸é ÆÐÄ¡°¡ Àû¿ëµÇ±â Àü±îÁö ÄÜ¼Ö Æ÷Æ® ¼¹ö·ÎºÎÅÍ Á¦Ç°À» ´ÜÀý½ÃÄÑ ³õ´Â´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
9681 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|