Intel¶à¿î²úÆ·ÌáȨÎó²î
2017-05-02
ÍâµØÊ±¼ä5ÔÂ1ÈÕ£¨±±¾©Ê±¼ä5ÔÂ2ÈÕÉÏÎ磩£¬Ó¢Ìضû£¨Intel£©¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬Í¨¸æÅú×¢IntelÆìϲúÆ·Ó¢ÌØ¶û×Ô¶¯ÖÎÀíÊÖÒÕ£¨AMT£©£¬Ó¢Ìضû±ê×¼¿ÉÖÎÀíÐÔ£¨ISM£©ºÍÓ¢ÌØ¶ûСÐÍÆóÒµÊÖÒÕ°æ±¾ÖеĹ̼þ°æ±¾6.x£¬7.x£¬8.x 9.x£¬10 .x£¬11.0£¬11.5ºÍ11.6±£´æÌáȨÎó²î£¬¿ÉÒÔʹÎÞÌØÈ¨¹¥»÷Õß»ñÈ¡ÕâЩ²úÆ·µÄ¸ß¼¶ÖÎÀí¹¦Ð§È¨ÏÞ£¬CVE±àºÅ£ºCVE-2017-5689¡£ ͨË×Óû§»ùÓÚIntelµÄPC²»ÊÜÓ°Ïì¡£
²Î¿¼Á´½Ó£º
https://www.us-cert.gov/ncas/current-activity/2017/05/01/Intel-Firmware-Vulnerability
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr
Îó²îÐÎò
ÓÐÁ½ÖÖÒªÁì¿ÉÒÔʹÓôËÎó²î£¬Çë×¢ÖØ£¬Ó¢ÌضûСÐÍÆóÒµÊÖÒÕ½ûÖ¹Ò×Êܵ½µÚÒ»¸öÎÊÌâµÄÓ°Ïì¡£
1¡¢ÎÞÌØÈ¨µÄÍøÂç¹¥»÷Õß¿ÉÒÔ»ñµÃÉèÖÃÓ¢ÌØ¶û¿ÉÖÎÀíÐÔSKUµÄϵͳȨÏÞ£ºÓ¢Ìضû×Ô¶¯ÖÎÀíÊÖÒÕ£¨AMT£©ºÍÓ¢ÌØ¶û±ê×¼¿ÉÖÎÀíÐÔ£¨ISM£©¡£
CVSSv3 9.8ÁÙ½ç/ AV£ºN / AC£ºL / PR£ºN / UI£ºN / S£ºU / C£ºH / I£ºH / A£ºH
2¡¢ÎÞÌØÈ¨µÄÍâµØ¹¥»÷Õß¿ÉÒÔÎªÓ¢ÌØ¶û¿ÉÖÎÀíÐÔSKUÌṩÎÞÌØÈ¨ÍøÂç»òÍâµØÏµÍ³È¨Ï޵ĿÉÖÎÀíÐÔ¹¦Ð§£ºÓ¢Ìضû×Ô¶¯ÖÎÀíÊÖÒÕ£¨AMT£©£¬Ó¢Ìضû±ê×¼¿ÉÖÎÀíÐÔ£¨ISM£©ºÍÓ¢ÌØ¶ûСÐÍÆóÒµÊÖÒÕ£¨SBT£©¡£
CVSSv3 8.4¸ß/ AV£ºL / AC£ºL / PR£ºN / UI£ºN / S£ºU / C£ºH / I£ºH / A£ºH
ÊÜÓ°ÏìµÄ°æ±¾
Intel manageability firmware versions 6.x 7.x 8.x 9.x 10.x 11.0 11.5 and 11.6
²»ÊÜÓ°ÏìµÄ°æ±¾
Intel manageability firmware versions < 6
Intel manageability firmware versions > 11.6
¹æ±Ü¼Æ»®
¹Ù·½ÌṩÁËÏêϸµÄ²Ù×÷°ì·¨À´¹æ±Ü´ËÎó²î£¬ÈçÏ£º
°ì·¨1£º
È·¶¨ÄúÊÇ·ñÓµÓÐÓ¢ÌØ¶ûAMT£¬Ó¢ÌضûSBA»òÖ§³ÖÓ¢ÌØ¶ûISM¹¦Ð§µÄϵͳ£ºhttps£º//communities.intel.com/docs/DOC-5693¡£ÈôÊÇÄúÈ·¶¨ÄúûÓÐÉÏÊöϵͳ£¬Ôò²»ÐèÒª½øÒ»²½µÄ²Ù×÷¡£
°ì·¨2£º
ʹÓá°¼ì²âÖ¸ÄÏ¡±À´ÆÀ¹ÀϵͳÊÇ·ñ¾ßÓÐÊÜÓ°ÏìµÄ¹Ì¼þ£ºhttps£º//downloadcenter.intel.com/download/26755¡£ÈôÊÇÄúÔÚ¡°Òѽâ¾öµÄ¹Ì¼þ¡±ÁÐÖÐÓÐÒ»¸ö°æ±¾£¬Ôò²»ÐèÒª½ÓÄɽøÒ»²½µÄ²Ù×÷À´±£»¤ÏµÍ³ÃâÊÜ´ËÎó²îµÄÓ°Ïì¡£
°ì·¨3£º
Ó¢ÌØ¶ûÇ¿ÁÒ½¨ÒéÄúÓëϵͳOEM¼ì²é¸üеĹ̼þ¡£½â¾öÎÊÌâµÄ¹Ì¼þ°æ±¾¾ßÓÐÒÔ¡°3¡±£¨X.X.XX.3XXX£©Ex£º8.1.71.3608¿ªÍ·µÄËÄλÄÚÖð汾ºÅ¡£
°ì·¨4£º
ÈôÊÇÄúµÄOEMÎÞ·¨Ê¹Óù̼þ¸üУ¬±¾ÎĵµÖÐÌṩµÄ»º½â²½·¥ÈçÏ£ºhttps£º//downloadcenter.intel.com/download/26754
ÒªÐÖúʵÑé±¾ÎĵµÖÐÌṩµÄ»º½â°ì·¨£¬ÇëÁªÏµÓ¢Ìضû¿Í»§Ö§³Ö£¨http://www.intel.com/content/www/us/en/support/contact-support.html#@23£©;´ÓÊÖÒÕ²¿·Ö£¬Ñ¡ÔñÓ¢ÌØ¶û×Ô¶¯ÖÎÀíÊÖÒÕ£¨Ó¢ÌضûAMT£©¡£
¸½Â¼
ÊÜÓ°ÏìµÄ²úÆ·¼°°æ±¾ÈçÏ£º
Zoom TelephonicsInc 3252
BN-Mux BCW700J
BN-Mux BCW710J
BN-Mux BCW 710J2
Netgear C3000-100NAS
Netgear CGD24G-100NAS
Netgear CGD25G-1CHNAS
Netgear CM5100
Netgear CM5100-51
Castlenet CBV734EW
Castlenet CBV38Z4EC
Castlenet CBV38Z4ECNIT
Castlenet CBV383G4J
Castlenet CBV38G4J
TEKNOTEL CBW700N
CG2001-AN22A
UDBNA CG2001
UN2NA CG2001
UN2NA CG2002
UN2NA CG2200
Comtrend CM-6300n
Arris DCX-3200
Arris DG9501
Ubee DDW2600
Ubee DDW2602
Cisco DPC2100
Cisco DPC2320
Cisco DPC2420
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







