Cisco IMC SupervisorºÍUCS Director¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-22

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1938£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1935£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-1974£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨ 


Ó°Ïì°æ±¾


CVE-2019-1938
UCS Director releases 6.7.0.0 and 6.7.1.0
UCS Director Express for Big Data releases 3.7.0.0 and 3.7.1.0


CVE-2019-1935

Cisco IMC Supervisor releases:
2.1
2.2.0.0 through 2.2.0.6
Cisco UCS Director releases:
6.0
6.5
6.6.0.0 and 6.6.1.0
6.7.0.0 and 6.7.1.0
Cisco UCS Director Express for Big Data releases:
3.0
3.5
3.6
3.7.0.0 and 3.7.1.0


CVE-2019-1974

Cisco IMC Supervisor releases:
2.1
2.2.0.0 through 2.2.0.6
Cisco UCS Director releases:
5.5.0.0 through 5.5.0.2
6.0.0.0 through 6.0.1.3
6.5.0.0 through 6.5.0.3
6.6.0.0 and 6.6.1.0
6.7.0.0 through 6.7.2.0
Cisco UCS Director Express for Big Data releases:
2.1.0.0 through 2.1.0.2
3.0.0.0 through 3.0.1.3
3.5.0.0 through 3.5.0.3
3.6.0.0 and 3.6.1.0
3.7.0.0 through 3.7.2.0


Îó²î¸ÅÊö


Cisco Integrated Management Controller£¨IMC£©Supervisor SoftwareºÍUCS Director Software¶¼ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄ²úÆ·¡£¡£ ¡£¡£¡£


Cisco Integrated Management Controller£¨IMC£©SupervisorÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ÓÃÓÚ¶ÔUCS£¨Í³Ò»ÅÌËãϵͳ£©¾ÙÐÐÖÎÀíµÄ¹¤¾ß£¬£¬£¬£¬ËüÖ§³ÖHTTP¡¢SSH»á¼ûµÈ£¬£¬£¬£¬²¢¿É¶ÔЧÀÍÆ÷¾ÙÐпª»ú¡¢¹Ø»úºÍÖØÆôµÈ²Ù×÷¡£¡£ ¡£¡£¡£


Cisco UCS DirectorÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Èںϻù´¡ÉèÊ©ÖÎÃ÷È·¾ö¼Æ»®¡£¡£ ¡£¡£¡£¸Ã¼Æ»®Ö§³ÖÓû§´Ó¼òµ¥ÖÎÀí¿ØÖÆÌ¨ÖÎÀíÅÌËãÄÜÁ¦¡¢ÍøÂçЧÀÍ¡¢´æ´¢ºÍÐéÄâ»ú£¬£¬£¬£¬ÒÔ¸ü¿ìËٺ͵ͳÉÍâµØ°²ÅźÍÐû²¼ITЧÀÍ¡£¡£ ¡£¡£¡£


CVE-2019-1938

Cisco UCS DirectorºÍCisco UCS Director Express for Big DataµÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤²¢Ê¹ÓÃÊÜÓ°ÏìϵͳÉϵÄÖÎÀíԱȨÏÞÖ´ÐÐí§Òâ²Ù×÷¡£¡£ ¡£¡£¡£


¸ÃÎó²îÊÇÓÉÓÚ²»×¼È·µÄÉí·ÝÑéÖ¤ÇëÇó´¦Öóͷ£Ôì³ÉµÄ¡£¡£ ¡£¡£¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍÈ«ÐÄÉè¼ÆµÄHTTPÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£ ¡£¡£¡£ ÀÖ³ÉʹÓÿÉÒÔÔÊÐí·ÇÌØÈ¨¹¥»÷Õßͨ¹ýijЩAPI»á¼ûºÍÖ´ÐÐí§Òâ²Ù×÷¡£¡£ ¡£¡£¡£


CVE-2019-1935

˼¿Æ¼¯³ÉÖÎÀí¿ØÖÆÆ÷£¨IMC£©Supervisor£¬£¬£¬£¬Cisco UCS DirectorºÍCisco UCS Director Express for Big DataÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃSCPÓû§ÕÊ»§£¨scpuser£©µÇ¼ÊÜÓ°ÏìϵͳµÄCLI £¬£¬£¬£¬¾ßÓÐĬÈÏÓû§Æ¾Ö¤¡£¡£ ¡£¡£¡£


¸ÃÎó²îÊÇÓÉÓÚ±£´æÒѼͼµÄĬÈÏÕÊ»§£¬£¬£¬£¬ÆäÖаüÀ¨Î´¼Í¼µÄĬÈÏÃÜÂëºÍ¸ÃÕÊ»§µÄ¹ýʧȨÏÞÉèÖᣡ£ ¡£¡£¡£ ÔÚ×°ÖòúƷʱ´ú£¬£¬£¬£¬²»»áÇ¿ÖÆ¸ü¸Ä´ËÕÊ»§µÄĬÈÏÃÜÂë¡£¡£ ¡£¡£¡£ ¹¥»÷Õß¿ÉÒÔʹÓøÃÕÊ»§µÇ¼ÊÜÓ°ÏìµÄϵͳÀ´Ê¹ÓôËÎó²î¡£¡£ ¡£¡£¡£ ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÓÃscpuserÕÊ»§µÄȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£ ¡£¡£¡£ Õâ°üÀ¨¶ÔϵͳÊý¾Ý¿âµÄÍêÈ«¶Áд»á¼ûȨÏÞ¡£¡£ ¡£¡£¡£


CVE-2019-1974

˼¿Æ¼¯³ÉÖÎÀí¿ØÖÆÆ÷£¨IMC£©Ö÷¹Ü£¬£¬£¬£¬Cisco UCS DirectorºÍCisco UCS Director Express for Big DataµÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÓû§Éí·ÝÑéÖ¤²¢»ñµÃÖÎÀíÓû§µÄ»á¼ûȨÏÞ¡£¡£ ¡£¡£¡£


¸ÃÎó²îÊÇÓÉÓÚÉí·ÝÑéÖ¤Àú³ÌÖÐÇëÇó±êÍ·Ñé֤ȱ·¦Ôì³ÉµÄ¡£¡£ ¡£¡£¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍһϵÁжñÒâÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£ ¡£¡£¡£ ʹÓÃÎó²î¿ÉÒÔÈù¥»÷Õß»ñµÃ¶ÔÊÜÓ°Ïì×°±¸µÄÍêÈ«ÖÎÆÊÎö¼ûȨÏÞ¡£¡£ ¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£ ¡£¡£¡£


ÐÞ¸´½¨Òé


˼¿ÆÒѾ­Ðû²¼ÁË×îеĹ̼þ°æ±¾£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§Ó¦ÊµÊ±Éý¼¶¾ÙÐзÀ»¤£º


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-ucsd-authbypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-usercred
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-ucs-authbypass


²Î¿¼Á´½Ó


https://threatpost.com/cisco-patches-six-critical-bugs/147585/