使用IIS的Cisco产品和应用程序存在着一个漏洞,导致攻击者在服务器上运行恶意的代码或进行拒绝服务攻击。 需要说明的是这并不是因为Cisco产品或应用程序的原因,而是由IIS的漏洞引起的。此漏洞已在Microsoft 安全公告MS02-018中被公布。 如果你想得到更详细的描述,请点击: http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml IIS的这个漏洞可导致缓冲溢出和拒绝服务攻击。攻击者如果成功利用此漏洞的话,将能在服务器上运行随意的代码或破坏它的正常运行。 所有使用IIS的Cisco产品和应用程序都有可能存在这个漏洞,所以为了检测你的产品是否存在漏洞,请将你的软件版本和配置信息对照下表(仅仅表中的组合存在漏洞)。 * Cisco CallManager 3.0, 3.1, 3.2 * Cisco ICS 7750 * Cisco Unity * Cisco Building Broadband Service Manager 4.x, 5.x * Cisco uOne Enterprise Edition * Cisco E-mail Manager (CEM) * Cisco Network Registrar (CNR) * Cisco Intelligent Contact Manager (ICM) 大部分的 Cisco 网络管理产品都是安装在Microsoft的平台上,并且运行的IIS都是有漏洞的。 许多老版本的CiscoWorks 2000 RWAN/CWSI Campus v2.x and Cisco Voice Manager v1.x也因为IIS被默认安装,所以直接受此影响,这些系统可能都在缺省端口上提供HTTP服务。但是这些老版本的软件包已经不再被提供技术支持,所以我们需要警告他们赶快升级新的版本。 . 解决方案: 1。为IIS下载补丁 http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml 2。部分软件版本和相关的修复 Cisco CallManager +--------------------------------------------------+ | 受影响 | Fixed Regular Release (available | | | now) | | 版本 | Fix carries forward into all later | | | versions | |-----------+--------------------------------------| | Version | Install | | 3.0 | win-OS-Upgrade.2000-1-3spA.exe from | | | our Software Center | |-----------+--------------------------------------| | Version | Install | | 3.1 | win-OS-Upgrade.2000-1-3spA.exe from | | | our Software Center | |-----------+--------------------------------------| | Version | Install | | 3.2 | win-OS-Upgrade.2000-1-3spA.exe from | | | our Software Center | +--------------------------------------------------+ Cisco Unity +--------------------------------------------------+ | Version | Fixed Regular Release (available | | Affected | now) | | | Fix carries forward into all | | | later versions | |--------------+-----------------------------------| | All Versions | Install patch for MS02-018 | +--------------------------------------------------+ Cisco Building Broadband Service Manager +--------------------------------------------------+ | Version | Fixed Regular Release (available | | Affected | now) | | | Fix carries forward into all | | | later versions | |--------------+-----------------------------------| | Version 4.x | Install patch for MS02-018 | |--------------+-----------------------------------| | Version 5.x | Install patch for MS02-018 | +--------------------------------------------------+