Cisco Small Business ์‹œ๋ฆฌ์ฆˆ ์Šค์œ„์น˜์˜ ์น˜๋ช…์ ์ธ ์ทจ์•ฝ์ 

Cisco Small Business ์‹œ๋ฆฌ์ฆˆ ์Šค์œ„์น˜์—์„œ ์ธ์ฆ ์—†์ด ์›๊ฒฉ ๊ณต๊ฒฉ์ž๊ฐ€ ๋ฃจํŠธ ๊ถŒํ•œ์œผ๋กœ ์žฅ์น˜์— ๋Œ€ํ•œ ์ „์ฒด ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์–ป์„ ์ˆ˜ ์žˆ๋„๋ก ํ—ˆ์šฉํ•˜๋Š” ๋„ค ๊ฐ€์ง€ ์ทจ์•ฝ์ ์ด ํ™•์ธ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋ฌธ์ œ๋ฅผ ์•…์šฉํ•˜๋ ค๋ฉด ๊ณต๊ฒฉ์ž๊ฐ€ ์›น ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ œ๊ณตํ•˜๋Š” ๋„คํŠธ์›Œํฌ ํฌํŠธ์— ์š”์ฒญ์„ ๋ณด๋‚ผ ์ˆ˜ ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋ฌธ์ œ์—๋Š” ์‹ฌ๊ฐํ•œ ์œ„ํ—˜ ์ˆ˜์ค€(4์  ์ค‘ 9.8์ )์ด ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค. ์ž‘๋™ํ•˜๋Š” ์ต์Šคํ”Œ๋กœ์ž‡ ํ”„๋กœํ† ํƒ€์ž…์ด ๋ณด๊ณ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

ํ™•์ธ๋œ ์ทจ์•ฝ์ (CVE-2023-20159, CVE-2023-20160, CVE-2023-20161, CVE-2023-20189)์€ ์‚ฌ์ „ ์ธ์ฆ ๋‹จ๊ณ„์—์„œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๋‹ค์–‘ํ•œ ํ•ธ๋“ค๋Ÿฌ์˜ ๋ฉ”๋ชจ๋ฆฌ ์ฒ˜๋ฆฌ ์˜ค๋ฅ˜๋กœ ์ธํ•ด ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. ์ทจ์•ฝ์ ์œผ๋กœ ์ธํ•ด ํŠน๋ณ„ํžˆ ํฌ๋งท๋œ ์™ธ๋ถ€ ๋ฐ์ดํ„ฐ๋ฅผ ์ฒ˜๋ฆฌํ•  ๋•Œ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. ๋˜ํ•œ ์„œ๋น„์Šค ๊ฑฐ๋ถ€๋ฅผ ์›๊ฒฉ์œผ๋กœ ์‹œ์ž‘ํ•  ์ˆ˜ ์žˆ๋Š” ๋œ ์‹ฌ๊ฐํ•œ ์ทจ์•ฝ์  2023๊ฐœ(CVE-20024-2023, CVE-20156-2023, CVE-20157-2023, CVE-20158-2023)๊ฐ€ Cisco Small Business ์‹œ๋ฆฌ์ฆˆ์—์„œ ํ™•์ธ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. , ์ธ์ฆ ์—†์ด ์žฅ์น˜ ๊ตฌ์„ฑ ์ •๋ณด๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์  20162๊ฐœ(CVE-XNUMX-XNUMX)๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ์ทจ์•ฝ์ ์€ Smart Switch 250, 350, 350X, 550X, Business 250, Business 350 ์‹œ๋ฆฌ์ฆˆ์™€ Small Business 200, 300, 500 ์‹œ๋ฆฌ์ฆˆ์— ์˜ํ–ฅ์„ ๋ฏธ์น˜๋ฉฐ, 220๊ณผ Business 220 ์‹œ๋ฆฌ์ฆˆ ์Šค์œ„์น˜๋Š” ์˜ํ–ฅ์„ ๋ฐ›์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋ฌธ์ œ๋Š” ํŽŒ์›จ์–ด ์—…๋ฐ์ดํŠธ 2.5.9.16 ๋ฐ 3.3.0.16์—์„œ ์ˆ˜์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค. Small Business 200, 300 ๋ฐ 500 ์‹œ๋ฆฌ์ฆˆ์˜ ๊ฒฝ์šฐ ํ•ด๋‹น ๋ชจ๋ธ์˜ ์ˆ˜๋ช… ์ฃผ๊ธฐ๊ฐ€ ์ด๋ฏธ ์™„๋ฃŒ๋˜์—ˆ์œผ๋ฏ€๋กœ ํŽŒ์›จ์–ด ์—…๋ฐ์ดํŠธ๊ฐ€ ์ƒ์„ฑ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€