Ãë¾àÁ¡ID |
210264 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
Cisco´Â ÀÎÅͳÝÀ̳ª ½Å·ÚÇÒ ¼ö ¾ø´Â ³×Æ®¿öÅ©¿¡ ³ëÃâµÉ ¶§ Cisco IOS XE ¼ÒÇÁÆ®¿þ¾îÀÇ À¥ UI ±â´É¿¡¼ ÀÌÀü¿¡ ¾Ë·ÁÁöÁö ¾ÊÀº Ãë¾àÁ¡ÀÌ È°¹ßÇÏ°Ô ¾Ç¿ëµÇ°í ÀÖÀ½À» ¾Ë°í ÀÖ½À´Ï´Ù. ÀÌ Ãë¾àÁ¡À» ÅëÇØ ÀÎÁõµÇÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ¿¡ ±ÇÇÑ ¼öÁØ 15 ¾×¼¼½º ±ÇÇÑÀ» °¡Áø °èÁ¤À» »ý¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·± ´ÙÀ½ °ø°ÝÀÚ´Â ÇØ´ç °èÁ¤À» »ç¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛÀ» Á¦¾îÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ °ø°Ý º¤Å͸¦ Â÷´ÜÇÏ´Â ´Ü°è´Â ÀÌ ±Ç°íÀÇ ±ÇÀå »çÇ× ¼½¼ÇÀ» ÂüÁ¶ÇϽʽÿÀ. Cisco´Â ÀÌ Á¶»ç »óÅÂ¿Í ¼ÒÇÁÆ®¿þ¾î ÆÐÄ¡°¡ Á¦°øµÇ´Â ½Ã±â¿¡ ´ëÇÑ ¾÷µ¥ÀÌÆ®¸¦ Á¦°øÇÒ °ÍÀÔ´Ï´Ù.
* Âü°í »çÀÌÆ®: https://arstechnica.com/security/2023/10/actively-exploited-cisco-0-day-with-maximum-10-severity-gives-full-network-control/ https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z https://www.cisa.gov/guidance-addressing-cisco-ios-xe-web-ui-vulnerabilities https://www.darkreading.com/vulnerabilities-threats/critical-unpatched-cisco-zero-day-bug-active-exploit
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: À¥ UI ±â´ÉÀÌ È°¼ºÈµÈ °æ¿ì ÀÌ·¯ÇÑ Ãë¾àÁ¡Àº Cisco IOS XE ¼ÒÇÁÆ®¿þ¾î¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù. |
ÇØ°áÃ¥ |
´ÙÀ½ ¸µÅ©ÀÇ ¼³¸í¿¡ µû¶ó Á¶Ä¡ÇÑ´Ù. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z |
°ü·Ã URL |
CVE-2023-20198 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|