English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29082
À§Çèµµ 30
Æ÷Æ® 161
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù CISCO
»ó¼¼¼³¸í ÇØ´ç Cisco IOS´Â VPNSM ºñÁ¤»óÀûÀÎ IKE ÆÐŶ Ãë¾àÁ¡ (CISCO ¹ö±× ID CSCed30113)À» °¡Áö°í ÀÖ´Ù.
VPNSM (Cisco IP Security (IPSec) VPN Services Module)Àº ÇϺα¸Á¶ ÅëÇÕÇü IPSec VPN ¼­ºñ½º¸¦ Á¦°øÇÏ´Â Cisco Catalyst 6500 ½Ã¸®Áî ½ºÀ§Ä¡ ¹× Cisco 7600 ½Ã¸®Áî ÀÎÅÍ³Ý ¶ó¿ìÅ͸¦ À§ÇÑ °í¼º´É ¸ðµâÀÌ´Ù. ºñÁ¤»óÀûÀÎ IKE (Internet Key Exchange) ÆÐŶÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â VPNSMÀÌ ¼³Ä¡µÈ Àåºñ°¡ Å©·¡½¬¸¦ ÀÏÀ¸Å°°Å³ª Àç½ÃÀÛµÇ°Ô ÇÒ ¼ö ÀÖ´Ù.
ÀÌ Ãë¾àÁ¡Àº 12.2SXA, 12.2SXB, 12.2SY, ±×¸®°í 12.2ZA Cisco IOS ¼ÒÇÁÆ®¿þ¾î ¸±¸®Áîµé¿¡ ÅëÇյǾú´ø ¼öÁ¤µÈ IKE Äڵ忡¸¸ Á¸ÀçÇÏ´Â °ÍÀ¸·Î ¾Ë·ÁÁ® ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿­À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ­´Â Á¤Ã¥ ÆíÁý±â¿¡¼­ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿­À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cisco.com/en/US/products/csa/cisco-sa-20040408-vpnsm.html
http://www.securityfocus.com/archive/1/359843

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Cisco Systems, Inc., Cisco 6500 Any version
Cisco Systems, Inc., Cisco 7600 Any version
Cisco Systems, Inc., Cisco IOS 12.2SXA
Cisco Systems, Inc., Cisco IOS 12.2SXB
Cisco Systems, Inc., Cisco IOS 12.2SY
Cisco Systems, Inc., Cisco IOS 12.2ZA
ÇØ°áÃ¥ ´ÙÀ½ Cisco º¸¾È ±Ç°í¾È(Cisco IPSec VPN Services Module Malformed IKE Packet Vulnerability)ÀÇ "Software Versions and Fixes" ¸¦ ÂüÁ¶ÇÏ¿© ¹®Á¦°¡ ÇØ°áµÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.cisco.com/en/US/products/csa/cisco-sa-20040408-vpnsm.html

¾÷±×·¹À̵åµéÀº Cisco À¥ »çÀÌÆ®ÀÎ http://www.cisco.com/tacpage/library/12.2/index.shtml ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù.

ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ »çÀÌÆ®¿¡¼­ º¼ ¼ö ÀÖ´Ù:
http://www.cisco.com/en/US/products/csa/cisco-sa-20040408-vpnsm.html
°ü·Ã URL (CVE)
°ü·Ã URL 10083 (SecurityFocus)
°ü·Ã URL 15797 (ISS)