Cisco ACI MSO APIÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2021-1388£©

Ðû²¼Ê±¼ä 2021-02-25

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-1388

ʱ   ¼ä

2021-02-25

Àà   ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ   ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Cisco ACI MSO 3.0

 

0x01 Îó²îÏêÇé

image.png

 

Cisco Multi-Site Orchestrator£¨MSO£©¿Éͨ¹ýÔËÓªÉÌ¿ÉÒÔʵÏÖ»ìÏýÔÆ¼Æ»®£¬£¬£¬£¬ÔÚDCNM¡¢ACI¡¢ÔƺͿçÓòµÄ±ßÑØ¹æÄ£ÄÚ½ç˵ºÍЭµ÷ÍøÂçÕ½ÂÔ ¡£¡£¡£¡£

2021Äê02ÔÂ24ÈÕ£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ÐÞ¸´ÁËCisco ACI MSO API½Ó¿ÚÉϵÄÒ»¸öÑÏÖØµÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2021-1388£©£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ10.0 ¡£¡£¡£¡£

¸ÃÎó²îÊÇÌØ¶¨API½Ó¿ÚÉϵÄtokenÑéÖ¤²»×¼È·Ôì³ÉµÄ ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄAPI·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î ¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»»ñµÃ¾ßÓÐÖÎÀíԱȨÏÞµÄtoken£¬£¬£¬£¬×îÖÕÈÆ¹ýÊÜÓ°ÏìÉè±¹ØÁ¬ÄÉí·ÝÑéÖ¤ ¡£¡£¡£¡£

¸ÃÎó²î½öÓ°ÏìCisco ACI MSO 3.0°æ±¾£¨Cisco ACI MSO 3.0(1i)°æ±¾²»ÊÜÓ°Ï죩£¬£¬£¬£¬²¢ÇÒ½öÔÚ°²ÅÅÓÚCisco Application Services EngineͳһӦÓÃÍÐ¹ÜÆ½Ì¨ÉÏʱ²ÅÊÜÓ°Ïì ¡£¡£¡£¡£

±ðµÄ£¬£¬£¬£¬Cisco»¹ÐÞ¸´ÁËCisco Application Services Engine£¨CisocÓ¦ÓÃЧÀÍÒýÇæ£©ÖеÄÒ»¸öÑÏÖØµÄδÊÚȨ»á¼ûÎó²î£¨CVE-2021-1393£©ºÍCisco NX-OSÖеÄÒ»¸öí§ÒâÎļþ²Ù×÷Îó²î£¨CVE-2021-1361£©£¬£¬£¬£¬Õâ2¸öÎó²îµÄCVSSÆÀ·Ö¾ùΪ9.8 ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÕâЩÎó²îδÊÚȨ»á¼û×°±¸¡¢¸ü¸ÄÉèÖᢽ¨É衢ɾ³ý»òÒÔrootȨÏÞÁýÕÖí§ÒâÎļþ ¡£¡£¡£¡£ 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¸ÃÎó²îÒѱ»ÐÞ¸´£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶µ½Cisco ACI MSO 3.0£¨3m£©°æ±¾ ¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/home

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mso-authbyp-bb5GmBQv?

https://www.bleepingcomputer.com/news/security/cisco-fixes-maximum-severity-mso-auth-bypass-vulnerability/

 

0x04 ʱ¼äÏß

2021-02-24  CiscoÐû²¼Ç徲ͨ¸æ

2021-02-25  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png