±× ¿Ü ¿©·¯ ¼ÒÇÁÆ®¿þ¾î¿¡¼ 20°³ ³Ñ´Â Ãë¾àÁ¡ ³ª¿Í...»¡¸® ÆÐÄ¡ÇÒ¼ö·Ï ¾ÈÀüÇØÁ®
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ½Ã½ºÄÚÀÇ ÆÄÀ̾îÆÄ¿ö °ü¸®¼¾ÅÍ(Firepower Management Center, FMC)¿¡¼ Ä¡¸íÀûÀÎ À§ÇèµµÀÇ Ãë¾àÁ¡ÀÌ ¹ß°ßµÆ´Ù. À̸¦ ¼º°øÀûÀ¸·Î ÀͽºÇ÷ÎÀÕ ÇÒ °æ¿ì, ¿ø°Ý¿¡¼ ÀÎÁõ ½Ã½ºÅÛÀ» ÇÇÇÏ°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù°í ÇÑ´Ù.
[À̹ÌÁö = iclickart]
½Ã½ºÄÚ¿¡ ÀÇÇϸé ÀÌ Ãë¾àÁ¡Àº ¿ÜºÎ ¼¹ö·ÎºÎÅÍ ¿À´Â LDAP ÀÎÁõ ÀÀ´äÀ» Á¦´ë·Î ó¸®ÇÏÁö ¸øÇؼ ¹ß»ýÇÏ´Â °ÍÀ̶ó°í ÇÑ´Ù. °ø°ÝÀÚ°¡ ±³¹¦È÷ Á¶ÀÛµÈ HTTP ¿äûÀ» Ãë¾àÇÑ Àåºñ·Î Àü¼ÛÇÔÀ¸·Î½á FMCÀÇ °ü¸®ÀÚ ±ÇÇÑÀ» ÃëµæÇÒ ¼ö ÀÖ°Ô µÈ´Ù°í ½Ã½ºÄÚ´Â °æ°íÇϱ⵵ Çß´Ù.
´Ù¸¸ FMC°¡ ¿ÜºÎ LDAP ¼¹ö·ÎºÎÅÍ Á¶ÀÛ°ú »ç¿ëÀÌ °¡´ÉÇϵµ·Ï ¼³Á¤ÀÌ µÇ¾î ÀÖ´Â °æ¿ì¿¡¸¸ Ãë¾àÁ¡ÀÌ ¹ßµ¿µÈ´Ù. ÀÌ Ãë¾àÁ¡Àº CVE-2019-16028À̶ó´Â ¹øÈ£°¡ ºÙ¾úÀ¸¸ç CVSS ±âÁØÀ¸·Î 9.8Á¡À̶ó´Â ³ôÀº Á¡¼ö¸¦ ¹Þ¾Ò´Ù.
½Ã½ºÄÚ´Â FMC 6.4.0.7°ú 6.5.0.2 ¹öÀüÀ» ÅëÇØ Ãë¾àÁ¡À» ÇØ°áÇß´Ù. 6.2.3.16°ú 6.3.0.6 ¹öÀüµµ °¢°¢ 2¿ù°ú 5¿ù¿¡ °³¹ß ¿Ï·áÇØ ¹èÆ÷ÇÒ ¿¹Á¤À̶ó°í ÇÑ´Ù.
±× ¿Ü¿¡µµ ½Ã½ºÄÚ´Â À̹ø ÁÖ ´ÙÀ½¿¡¼ ¹ß°ßµÈ 8°³ÀÇ °íÀ§Ç豺 Ãë¾àÁ¡À» À§ÇÑ 7°³ ÆÐÄ¡¸¦ ¹ßÇ¥Çϱ⵵ Çß´Ù.
1) Telepresence Collaboration Endpoint
2) Telepresence Codec
3) RoomOS Software - IOS XE SD-WAN Software, SD-WAN Solution vManage, Smart Software Manager On-Prem, IOS XR Software.
ÀÌ Ãë¾àÁ¡µéÀ» ¼º°øÀûÀ¸·Î ÀͽºÇ÷ÎÀÕ ÇÒ °æ¿ì µð·ºÅ丮 º¯°æ °ø°Ý, ºñ½ÂÀÎ Á¢±Ù, ±ÇÇÑ »ó½Â, µðµµ½º °ø°Ý µîÀ» ÇÒ ¼ö ÀÖ´Â °ÍÀ¸·Î ¾Ë·ÁÁ® ÀÖ´Ù. ½Ã½ºÄÚ´Â ÆÐÄ¡¸¦ ¹ßÇ¥ÇÏ¸ç °í°´µé¿¡°Ô ¡°ÃÖ´ëÇÑ »¡¸® ÆÐÄ¡¸¦ Àû¿ëÇØ º¸´Ù ¾ÈÀüÇÑ È¯°æÀ» ±¸¼ºÇ϶󡱰í Ã˱¸Çϱ⵵ Çß´Ù. ¾ÆÁ÷ ½ÇÁ¦ °ø°Ý¿¡ À§ ¸ðµç Ãë¾àÁ¡µéÀÌ È°¿ëµÈ »ç·Ê´Â ¾ø´Ù°í ÇÑ´Ù.
Áß°£±Þ À§Çèµµ¸¦ °¡Áø Ãë¾àÁ¡ 18°³¿¡ ´ëÇÑ ÆÐÄ¡µµ ÁøÇàµÆ´Ù. ´ÙÀ½ ¼ÒÇÁÆ®¿þ¾î¿¡¼ ¹ß°ßµÈ °ÍµéÀÌ´Ù.
1) Webex Teams for Windows
2) Unified Communications Manager
3) Jabber Guest
4) Application Policy Infrastructure Controller
5) Email Security Appliance
6) Unity Connection Software
7) Web Security Appliance and Content Security Management Appliance
8) Umbrella Roaming Client for Windows
9) SD-WAN Solution
10) Small Business Smart and Managed Switches
11) IOS XR Software
12) Hosted Collaboration Mediation Fulfillment
ÀÌ Ãë¾àÁ¡µéÀ» ¼º°øÀûÀ¸·Î ÀͽºÇ÷ÎÀÕ ÇÒ °æ¿ì µðµµ½º, CSRF, XSS, IP Å×ÀÌºí ¿ìȸ, ÄÜÅÙÃ÷ ÇÊÅ͸µ ¿ìȸ, µð·ºÅ丮 º¯°æ, HTTP Çì´õ ÁÖÀÔ, SQL ÁÖÀÔ, ¸í·É ÁÖÀÔ, Á¤º¸ À¯Ãâ °ø°Ý µîÀ» ½Ç½ÃÇÒ ¼ö ÀÖ°Ô µÈ´Ù°í ÇÑ´Ù.
3ÁÙ ¿ä¾à
1. ½Ã½ºÄÚ, À̹ø ÁÖ ´ë·®ÀÇ ÆÐÄ¡ ¹ßÇ¥ÇÔ.
2. Ä¡¸íÀûÀÎ Ãë¾àÁ¡, °íÀ§Ç豺 Ãë¾àÁ¡, Áß°£±Þ À§Çèµµ Ãë¾àÁ¡ÀÌ °í·ç°í·ç.
3. °¢ Á¦Ç° »ç¿ëÀÚµéÀº »¡¸® ÆÐÄ¡ Àû¿ëÇÒ¼ö·Ï ¾ÈÀü.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>