CVE-2016-9214, CVE-2016-9215
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 12¿ù 13ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 13ÀÏ¿¡¼ 14ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
1. CVE-2016-9210
Cisco Unified Reporting ¾÷·Îµå ÅøÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÆÄÀÏ ½Ã½ºÅÛÀ¸·ÎºÎÅÍ ÀÓÀÇÀÇ ÆÄÀϵ鿡 Á¢¼ÓÇØ ¼öÁ¤ÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù. CSCvb61698°ú µ¿ÀÏÇϸç, 12.0(0.98000.168) 12.0(0.98000.178) 12.0(0.98000.399) 12.0(0.98000.510) 12.0(0.98000.536) 12.0(0.98500.7) ÇȽº°¡ ¹èÆ÷µÇ¾ú´Ù.
2. CVE-2016-9211
Cisco ONS 15454 Series Multiservice Provisioning PlatformsÀÇ TCP Æ÷Æ® °ü¸®ÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÅëÁ¦ Ä«µå¸¦ °©Àڱ⠸®·Îµå ½Ãų ¼ö ÀÖ°Ô µÈ´Ù. CSCuw26032¿Í µ¿ÀÏÇÑ Ãë¾àÁ¡ÀÌ´Ù.
3. CVE-2016-9212
Cisco AsyncOS SoftwareÀÇ Decrypt for End-User Notification ¼³Á¤ ¸Å°³º¯¼öÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ À¥ »çÀÌÆ® Á¢±Ù Â÷´Ü ¼³Á¤À» ÇØÁ¦ÇÒ ¼ö ÀÖ´Ù. CSCvb49012¿Í µ¿ÀÏÇÑ Ãë¾àÁ¡À¸·Î 9.0.1-162, 9.1.1-074 ¹öÀü¿¡ ¿µÇâÀÌ ÀÖ´Ù.
4. CVE-2016-9214
Cisco Identity Services Engine(ISE)ÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ XSS °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. CSCvb86332¿Í CSCvb86760°ú µ¿ÀÏÇÑ Ãë¾àÁ¡ÀÌ´Ù. 2.0(101.130) ¹öÀü¿¡ ¿µÇâÀÌ ÀÖ´Ù.
5. CVE-2016-9215
Cisco IOS XR SoftwareÀÇ Ãë¾àÁ¡À¸·Î ·ÎÄÃÀÇ °ø°ÝÀÚ°¡ ±â±â¿¡ ·Î±×ÀÎÀ» ÇÏ°í ·çÆ® »ç¿ëÀÚ ±ÇÇÑÀ» Å»ÃëÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù. CSCva38434¿Í µ¿ÀÏÇÑ Ãë¾àÁ¡À̸ç 6.1.1.BASE ¹öÀü¿¡ ¿µÇâÀÌ ÀÖ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>