CVE-2020-7197 | HPE SSMCÔ¶³ÌÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-10-26

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-7197

ʱ   ¼ä

2020-10-26

Àà   ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

3.7.0.0֮ǰµÄHP 3PAR   StoreServ Management and Core Software Media

 

 

HPE SSMCÊÇÊÊÓÃÓÚHPE Primera´æ´¢Æ½Ì¨ºÍHPE 3PAR StoreServÈ«ÉÁ´æÕóÁÐϵͳµÄÊý¾ÝÖÐÐÄÕóÁÐÖÎÀíºÍ±¨¸æ¿ØÖÆÌ¨¡£¡£¡£Æäͨ¹ýHPE OneViewµÈHPEÖÎÀí¹¤¾ßÌṩÁËÏÖ´ú»¯µÄÍâ¹ÛÒÔ¼°Í¨ÓõĽçÃæºÍÓïÑÔ£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃ×îеÄAPIºÍUIÊÖÒÕ£¬£¬£¬£¬£¬£¬¿É½«ËùÓÐHP 3PAR StoreServÖÎÀí¼¯ÖÐÔÚÒ»¸ö¼òµ¥µÄ´°¸ñÖУ¬£¬£¬£¬£¬£¬ÌṩÎļþºÍ¿éµÄÈÚºÏÖÎÀíºÍ±¨¸æ¹¦Ð§¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

2020Äê10ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬HPEÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÆäÒѾ­ÐÞ¸´ÁËHPE StoreServÖÎÀí¿ØÖÆÌ¨£¨SSMC£©ÖеÄÒ»¸öÔ¶³ÌÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î(CVE-2020-9197)£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ10.0¡£¡£¡£

ÓÉÓÚHPE StoreServÖÎÀí¿ØÖÆÌ¨£¨SSMC£©3.7.0.0ÊÇÒ»¸ö·Ç½Úµã¶àÕóÁÐÖÎÀíÆ÷WebÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬²¢ÇÒÓëÍйÜÕóÁÐÉϵÄÊý¾Ý¸ôÀ룬£¬£¬£¬£¬£¬ÕâʹµÃSSMCºÜÈÝÒ×±»Ô¶³ÌÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚHPEÒѸüÐÂÁËHPE StoreServ Management Console (SSMC)3.7.0.0£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶µ½HPE 3PAR StoreServ Management Console 3.7.1.1»ò¸ü¸ß°æ±¾¡£¡£¡£

ÏÂÔØµØµã£º

https://myenterpriselicense.hpe.com/cwp-ui/free-software/SSMC_CONSOLE

 

0x03 ²Î¿¼Á´½Ó

https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbst04045en_us

https://securityaffairs.co/wordpress/109962/security/ssmc-critical-auth-bypass-issue.html?

0x04 ʱ¼äÏß

2020-10-23  HPEÊ×´ÎÐû²¼Ç徲ͨ¸æ

2020-10-24  HPE¸üÐÂÇ徲ͨ¸æ

2020-10-26  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

image.png