複数の Cisco 製品に脆弱性

最終更新日: 2016/10/14

情報源

US-CERT Current Activity
Cisco Releases Security Updates
https://www.us-cert.gov/ncas/current-activity/2016/10/05/Cisco-Releases-Security-Updates

概要

複数の Cisco 製品には、脆弱性があります。結果として、遠隔の第三者が、任意のコードを実行したり、サービス運用妨害 (DoS) 攻撃を行ったりするなどの可能性があります。
対象となる製品は以下の通りです。

– Multilayer Director Switches
– Nexus 1000V Series Switches
– Nexus 2000 Series Fabric Extenders
– Nexus 3000 Series Switches
– Nexus 3500 Platform Switches
– Nexus 4000 Series Switches
– Nexus 5000 Series Switches
– Nexus 5500 Platform Switches
– Nexus 5600 Platform Switches
– Nexus 6000 Series Switches
– Nexus 7000 Series Switches
– Nexus 7700 Series Switches
– Nexus 9000 Series Switches in Application Centric Infrastructure (ACI) mode
– Nexus 9000 Series Switches in NX-OS mode

この問題は、該当する製品を、Cisco が提供する修正済みのバージョンに更新することで解決します。詳細は、Cisco が提供する情報を参照してください。

 

関連文書(英語)

Cisco Security Advisory

Cisco NX-OS Software-Based Products Authentication, Authorization, and Accounting Bypass Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-nxaaa

Cisco Security Advisory

Cisco Nexus 7000 and 7700 Series Switches Overlay Transport Virtualization Buffer Overflow Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-otv

Cisco Security Advisory

Cisco NX-OS Border Gateway Protocol Denial of Service Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-bgp

Cisco Security Advisory

Cisco NX-OS Software Crafted DHCPv4 Packet Denial of Service Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-dhcp1

Cisco Security Advisory

Cisco NX-OS Software Malformed DHCPv4 Packet Denial of Service Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-dhcp2

 


引用元:JPCERTコーディネーションセンター
「JPCERT/CC WEEKLY REPORT 2016-10-13」
https://www.jpcert.or.jp/wr/2016/wr164001.html