˼¿ÆÐÞ¸´DCNM¶à¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-28

Îó²î±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-1620£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1619£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1621£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.5

CVE±àºÅ£ºCVE-2019-1622£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º5.3 



Ó°Ïì°æ±¾



ÊÜÓ°ÏìµÄ°æ±¾


Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾



Îó²î¸ÅÊö



Cisco Data Center Network ManagerÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Êý¾ÝÖÐÐÄÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£¸ÃϵͳÊÊÓÃÓÚCisco NexusºÍMDSϵÁн»Á÷»ú£¬£¬£¬£¬£¬£¬Ìṩ´æ´¢¿ÉÊÓ»¯¡¢ÉèÖú͹ÊÕÏɨ³ýµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£Ë¼¿ÆÐû²¼DCNMµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸öÎó²î£º


CVE-2019-1620

Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖеĻùÓÚWebµÄÖÎÀí½çÃæ±£´æÈ¨ÏÞÔÊÐíºÍ»á¼û¿ØÖÆÎÊÌâÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ²»×¼È·µÄȨÏÞÉèÖᣡ£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÖƵÄÊý¾ÝʹÓøÃÎó²îдÈëí§ÒâÎļþ²¢rootȨÏÞÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£


CVE-2019-1619

Cisco Data Center Network Manager (DCNM)11.1(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ±£´æ»á¼û¿ØÖƹýʧÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷÖÎÆÊÎö»°¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄHTTPÇëÇóʹÓøÃÎó²îÈÆ¹ýÉí·ÝÑéÖ¤²¢ÒÔÖÎÀíȨÏÞÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£¡£¡£¡£


CVE-2019-1621

Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ±£´æÈ¨ÏÞÔÊÐíºÍ»á¼û¿ØÖÆÎÊÌâÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ²»×¼È·µÄȨÏÞÉèÖᣡ£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý½«¸Ã½çÃæÅþÁ¬µ½ÊÜÓ°Ïì×°±¸²¢ÇëÇóURLsʹÓøÃÎó²î»ñÈ¡Ãô¸ÐÐÅÏ¢µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£


CVE-2019-1622

Cisco Data Center Network Manager (DCNM)ÖлùÓÚWebµÄÖÎÀí½çÃæ±£´æ»á¼û¿ØÖƹýʧÎó²î¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÅþÁ¬µ½»ùÓÚWebµÄÖÎÀí½çÃæ²¢ÇëÇóURLsʹÓøÃÎó²î¼ìË÷Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£



Îó²îÑéÖ¤



ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£



ÐÞ¸´½¨Òé



ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó¼û²Î¿¼Á´½Ó¡£¡£¡£¡£¡£¡£



²Î¿¼Á´½Ó



https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-codex
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-file-dwnld
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-infodiscl