1
1

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

More than 5 years have passed since last update.

port 4786 (Cisco Smart Install用) を閉じる

Last updated at Posted at 2016-10-23
  • port 4786はCisco Smart Installで使われる。
    • 初期設定でポート開放されている。

現象

以下のようなログがshow logで出力された。

Oct 21 20:12:46 MDT: %SM-4-BADEVENT: Event 'ibcs_e_download_msg_req_recv' is invalid for the current state 'ibcs_s_accept': smi_ibc_serv SMI IBCS sm
-Traceback= XXXXXXX 1C2E850 1C1AC2C 1C2EDF4 1C2F5EC 1C2F7B8 1C1C40C 1C1C5BC 1C1C74C 1C1CA60 1C1B0B4 1B9774C 1B8E1D8
Oct 21 20:12:46 MDT: %SM-4-BADEVENT: Event 'ibcs_e_download_msg_resp_send' is invalid for the current state 'ibcs_s_accept': smi_ibc_serv SMI IBCS sm
-Traceback= XXXXXXX 1C2E878 1C1AD58 1C2EDF4 1C2F5EC 1C2F7B8 1C1C40C 1C1C5BC 1C1C74C 1C1CA60 1C1B0B4 1B9774C 1B8E1D8
Oct 21 20:12:46 MDT: VSTACK_ERR: smi_ibc_dl_handle_events : invalid message
  1. ibcs_e_download_msg_req_recvで検索すると以下該当あり。
  2. InfoSec Handlers Diary Blog - Request for Packets TCP 4786 - CVE-2016-6385
  3. CVE-2016-6385で検索すると以下ページがヒット。
  4. JVNDB-2016-005153 - JVN iPedia - 脆弱性対策情報データベース

対処

(config)# no vstack
  • port 4786が閉じたことを確認。
# show vstack config
- Role: Client (SmartInstall enabled)
+ Role: Client (SmartInstall disabled)
  Vstack Director IP address: 0.0.0.0

  *** Following configurations will be effective only on director ***
  Vstack default management vlan: 1
  Vstack management Vlans: none
  Join Window Details:
     Window: Open (default)
     Operation Mode: auto (default)
  Vstack Backup Details:
     Mode: On (default)
     Repository: 
1
1
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
1
1

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?