VMware NSXÏÂÁî×¢ÈëÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-25

Îó²î±àºÅ
CVE-2018-6961


Îó²î¼¶±ð
³§ÉÌ×ÔÆÀ£ºÖ÷Òª  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ°æ±¾£º
SD-WAN Edge 3.x, 2.x


Îó²î¸ÅÊö
Critical Start·¢Ã÷ÁËVMwareµÄNSX SD-WANÇéÐÎÖÐÒ»¸öδ¾­Éí·ÝÑéÖ¤µÄÏÂÁî×¢ÈëÎó²î²¢ÏòVMwareµÄÇå¾²ÏìÓ¦ÖÐÐÄ·¢³öÖÒÑÔ¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²îÔÊÐí¹¥»÷ÕßÔÚÔ¶³ÌЧÀÍÆ÷ÉÏÔËÐÐí§ÒâÏÂÁî¡£¡£¡£ ¡£¡£¡£¡£ÓÉÓÚÏÂÁî×¢ÈëÎó²î¿ÉÄܵ¼ÖÂÍйÜWebÓ¦ÓóÌÐòµÄЧÀÍÆ÷Êܵ½Ë𺦠£¬£¬£¬Òò´Ëͨ³£±»ÒÔΪÊÇÒ»¸öºÜÊÇÑÏÖØµÄȱÏÝ £¬£¬£¬¿ÉÄÜ»áÓ°ÏìÖÖÖÖÍøÂç×°±¸ £¬£¬£¬°üÀ¨Â·ÓÉÆ÷ £¬£¬£¬½»Á÷»úºÍ·À»ðǽ £¬£¬£¬´Ó¶ø½«Ãô¸ÐµÄ¡¢»ùÓÚÍøÂçµÄÐÅϢ̻¶¸øÎ´¾­ÊÚȨµÄ»á¼ûºÍʹÓᣡ£¡£ ¡£¡£¡£¡£VMwareÏàʶºóѸËÙÐû²¼ÁËÒ»¸ö²¹¶¡À´½â¾öÕâ¸öÎó²î¡£¡£¡£ ¡£¡£¡£¡£


ÔÚLuaÖÐ £¬£¬£¬ÀýÈç £¬£¬£¬µ±¿ª·¢Ö°Ô±Ê¹ÓÃδÂÄÀúÖ¤µÄÓû§Êý¾Ýͨ¹ýos.execute£¨£©»òio.popen£¨£©Luaº¯ÊýÔËÐвÙ×÷ϵͳÏÂÁîʱ £¬£¬£¬¾Í»á·ºÆðÕâÖÖÎó²î¡£¡£¡£ ¡£¡£¡£¡£Ò×Êܹ¥»÷µÄ´úÂëʾÀý£º
 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Îó²îʹÓÃ
´ËÎó²îµÄPOCÁ´½Ó£ºhttps://github.com/Critical-Start/Section-8¡£¡£¡£ ¡£¡£¡£¡£


ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´¸ÃÎó²î £¬£¬£¬Éý¼¶ÖÁ3.1.2°æ±¾£ºhttps://www.vmware.com/security/advisories/VMSA-2018-0011.html¡£¡£¡£ ¡£¡£¡£¡£


²Î¿¼Á´½Ó
https://www.criticalstart.com/2018/06/cve-2018-6961-unauthenticated-command-injection-vulnerability-in-vmware-nsx-sd-wan-by-velocloud/
https://github.com/Critical-Start/Section-8
https://www.vmware.com/security/advisories/VMSA-2018-0011.html