تحديثات Cisco
3100تاريخ التحذير
مستوى الخطورة
رقم التحذير
القطاع المستهدف
27 أغسطس, 2020
● عالي
2020-1694
الكل
الوصف:
أصدرت Cisco عدة تحديثات لمعالجة عدد من الثغرات في المنتجات التالية:
- Cisco UCS Manager Software
- Cisco FXOS or NX-OS
- Firepower 4100 Series (CSCvt46839)
- Firepower 9300 Security Appliances (CSCvt46839)
- MDS 9000 Series Multilayer Switches (CSCvt46835)
- Nexus 3000 Series Switches (CSCvt39630)
- Nexus 5500 Platform Switches (CSCvt46837)
- Nexus 5600 Platform Switches (CSCvt46837)
- Nexus 6000 Series Switches (CSCvt46837)
- Nexus 7000 Series Switches (CSCvt46835)
- Nexus 9000 Series Switches in standalone NX-OS mode (CSCvt39630)
- UCS 6200 Series Fabric Interconnects (CSCvt46838)
- UCS 6300 Series Fabric Interconnects (CSCvt46838)
- UCS 6400 Series Fabric Interconnects (CSCvt46877)
- Cisco IMC Software
- UCS C-Series and S-Series Servers in standalone mode
- UCS E-Series Servers
- 5000 Series Enterprise Network Compute System (ENCS) Platforms
التهديدات:
يمكن للمهاجم استغلال الثغرات وتنفيذ ما يلي:
- هجمة حجب الخدمة (DoS attack)
- رفع الصلاحيات لزيادة قدرته على التعديل في النظام
- تنفيذ برمجيات خبيثة
الإجراءات الوقائية:
يوصي المركز بتحديث النسخ المتأثرة حيث أصدرت Cisco توضيحًا لهذه التحديثات:
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-cli-dos-GQUxCnTe
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fxos-nxos-cfs-dos-dAmnymbd
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-dme-rce-cbE3nhZS
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n3n9k-priv-escal-3QhXJBC
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxosbgp-mvpn-dos-K8kbCrJp
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxosbgp-nlri-dos-458rG2OQ
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-callhome-cmdinj-zkxzSCY
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nx-os-cli-injection
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nx-os-cli-execution
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-pim-memleak-dos-tC8eP7uw
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imc-cmdinject-1896