Cisco IMC SupervisorºÍUCS Director¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-08-22? Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1935£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1974£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
? Ó°Ïì°æ±¾
UCS Director releases 6.7.0.0 and 6.7.1.0
UCS Director Express for Big Data releases 3.7.0.0 and 3.7.1.0
CVE-2019-1935
Cisco IMC Supervisor releases:2.1
2.2.0.0 through 2.2.0.6
Cisco UCS Director releases:
6.0
6.5
6.6.0.0 and 6.6.1.0
6.7.0.0 and 6.7.1.0
Cisco UCS Director Express for Big Data releases:
3.0
3.5
3.6
3.7.0.0 and 3.7.1.0
CVE-2019-1974
Cisco IMC Supervisor releases:2.1
2.2.0.0 through 2.2.0.6
Cisco UCS Director releases:
5.5.0.0 through 5.5.0.2
6.0.0.0 through 6.0.1.3
6.5.0.0 through 6.5.0.3
6.6.0.0 and 6.6.1.0
6.7.0.0 through 6.7.2.0
Cisco UCS Director Express for Big Data releases:
2.1.0.0 through 2.1.0.2
3.0.0.0 through 3.0.1.3
3.5.0.0 through 3.5.0.3
3.6.0.0 and 3.6.1.0
3.7.0.0 through 3.7.2.0
? Îó²î¸ÅÊö
Cisco Integrated Management Controller£¨IMC£©Supervisor SoftwareºÍUCS Director Software¶¼ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£
Cisco Integrated Management Controller£¨IMC£©SupervisorÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ÓÃÓÚ¶ÔUCS£¨Í³Ò»ÅÌËãϵͳ£©¾ÙÐÐÖÎÀíµÄ¹¤¾ß£¬£¬£¬£¬ËüÖ§³ÖHTTP¡¢SSH»á¼ûµÈ£¬£¬£¬£¬²¢¿É¶ÔЧÀÍÆ÷¾ÙÐпª»ú¡¢¹Ø»úºÍÖØÆôµÈ²Ù×÷¡£¡£¡£¡£¡£
Cisco UCS DirectorÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Èںϻù´¡ÉèÊ©ÖÎÃ÷È·¾ö¼Æ»®¡£¡£¡£¡£¡£¸Ã¼Æ»®Ö§³ÖÓû§´Ó¼òµ¥ÖÎÀí¿ØÖÆÌ¨ÖÎÀíÅÌËãÄÜÁ¦¡¢ÍøÂçЧÀÍ¡¢´æ´¢ºÍÐéÄâ»ú£¬£¬£¬£¬ÒÔ¸ü¿ìËٺ͵ͳÉÍâµØ°²ÅźÍÐû²¼ITЧÀÍ¡£¡£¡£¡£¡£
Cisco UCS DirectorºÍCisco UCS Director Express for Big DataµÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤²¢Ê¹ÓÃÊÜÓ°ÏìϵͳÉϵÄÖÎÀíԱȨÏÞÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇÓÉÓÚ²»×¼È·µÄÉí·ÝÑéÖ¤ÇëÇó´¦Öóͷ£Ôì³ÉµÄ¡£¡£¡£¡£¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍÈ«ÐÄÉè¼ÆµÄHTTPÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£ ÀÖ³ÉʹÓÿÉÒÔÔÊÐí·ÇÌØÈ¨¹¥»÷Õßͨ¹ýijЩAPI»á¼ûºÍÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£¡£¡£
˼¿Æ¼¯³ÉÖÎÀí¿ØÖÆÆ÷£¨IMC£©Supervisor£¬£¬£¬£¬Cisco UCS DirectorºÍCisco UCS Director Express for Big DataÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃSCPÓû§ÕÊ»§£¨scpuser£©µÇ¼ÊÜÓ°ÏìϵͳµÄCLI £¬£¬£¬£¬¾ßÓÐĬÈÏÓû§Æ¾Ö¤¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇÓÉÓÚ±£´æÒѼͼµÄĬÈÏÕÊ»§£¬£¬£¬£¬ÆäÖаüÀ¨Î´¼Í¼µÄĬÈÏÃÜÂëºÍ¸ÃÕÊ»§µÄ¹ýʧȨÏÞÉèÖᣡ£¡£¡£¡£ ÔÚ×°ÖòúƷʱ´ú£¬£¬£¬£¬²»»áÇ¿ÖÆ¸ü¸Ä´ËÕÊ»§µÄĬÈÏÃÜÂë¡£¡£¡£¡£¡£ ¹¥»÷Õß¿ÉÒÔʹÓøÃÕÊ»§µÇ¼ÊÜÓ°ÏìµÄϵͳÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£ ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÓÃscpuserÕÊ»§µÄȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£ Õâ°üÀ¨¶ÔϵͳÊý¾Ý¿âµÄÍêÈ«¶Áд»á¼ûȨÏÞ¡£¡£¡£¡£¡£
˼¿Æ¼¯³ÉÖÎÀí¿ØÖÆÆ÷£¨IMC£©Ö÷¹Ü£¬£¬£¬£¬Cisco UCS DirectorºÍCisco UCS Director Express for Big DataµÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÓû§Éí·ÝÑéÖ¤²¢»ñµÃÖÎÀíÓû§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇÓÉÓÚÉí·ÝÑéÖ¤Àú³ÌÖÐÇëÇó±êÍ·Ñé֤ȱ·¦Ôì³ÉµÄ¡£¡£¡£¡£¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍһϵÁжñÒâÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£ ʹÓÃÎó²î¿ÉÒÔÈù¥»÷Õß»ñµÃ¶ÔÊÜÓ°Ïì×°±¸µÄÍêÈ«ÖÎÆÊÎö¼ûȨÏÞ¡£¡£¡£¡£¡£
? Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
? ÐÞ¸´½¨Òé
˼¿ÆÒѾÐû²¼ÁË×îеĹ̼þ°æ±¾£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§Ó¦ÊµÊ±Éý¼¶¾ÙÐзÀ»¤£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-usercred
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-ucs-authbypass
? ²Î¿¼Á´½Ó