English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210264
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í Cisco´Â ÀÎÅͳÝÀ̳ª ½Å·ÚÇÒ ¼ö ¾ø´Â ³×Æ®¿öÅ©¿¡ ³ëÃâµÉ ¶§ Cisco IOS XE ¼ÒÇÁÆ®¿þ¾îÀÇ À¥ UI ±â´É¿¡¼­ ÀÌÀü¿¡ ¾Ë·ÁÁöÁö ¾ÊÀº Ãë¾àÁ¡ÀÌ È°¹ßÇÏ°Ô ¾Ç¿ëµÇ°í ÀÖÀ½À» ¾Ë°í ÀÖ½À´Ï´Ù. ÀÌ Ãë¾àÁ¡À» ÅëÇØ ÀÎÁõµÇÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ¿¡ ±ÇÇÑ ¼öÁØ 15 ¾×¼¼½º ±ÇÇÑÀ» °¡Áø °èÁ¤À» »ý¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·± ´ÙÀ½ °ø°ÝÀÚ´Â ÇØ´ç °èÁ¤À» »ç¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛÀ» Á¦¾îÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ °ø°Ý º¤Å͸¦ Â÷´ÜÇÏ´Â ´Ü°è´Â ÀÌ ±Ç°íÀÇ ±ÇÀå »çÇ× ¼½¼ÇÀ» ÂüÁ¶ÇϽʽÿÀ. Cisco´Â ÀÌ Á¶»ç »óÅÂ¿Í ¼ÒÇÁÆ®¿þ¾î ÆÐÄ¡°¡ Á¦°øµÇ´Â ½Ã±â¿¡ ´ëÇÑ ¾÷µ¥ÀÌÆ®¸¦ Á¦°øÇÒ °ÍÀÔ´Ï´Ù.

* Âü°í »çÀÌÆ®:
https://arstechnica.com/security/2023/10/actively-exploited-cisco-0-day-with-maximum-10-severity-gives-full-network-control/
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z
https://www.cisa.gov/guidance-addressing-cisco-ios-xe-web-ui-vulnerabilities
https://www.darkreading.com/vulnerabilities-threats/critical-unpatched-cisco-zero-day-bug-active-exploit

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
À¥ UI ±â´ÉÀÌ È°¼ºÈ­µÈ °æ¿ì ÀÌ·¯ÇÑ Ãë¾àÁ¡Àº Cisco IOS XE ¼ÒÇÁÆ®¿þ¾î¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù.
ÇØ°áÃ¥ ´ÙÀ½ ¸µÅ©ÀÇ ¼³¸í¿¡ µû¶ó Á¶Ä¡ÇÑ´Ù.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z
°ü·Ã URL CVE-2023-20198 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)