Cisco ACI MSO APIÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2021-1388£©
Ðû²¼Ê±¼ä 2021-02-250x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-1388 | ʱ ¼ä | 2021-02-25 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Cisco ACI MSO 3.0 |
0x01 Îó²îÏêÇé
Cisco Multi-Site Orchestrator£¨MSO£©¿Éͨ¹ýÔËÓªÉÌ¿ÉÒÔʵÏÖ»ìÏýÔÆ¼Æ»®£¬£¬£¬£¬ÔÚDCNM¡¢ACI¡¢ÔƺͿçÓòµÄ±ßÑØ¹æÄ£ÄÚ½ç˵ºÍе÷ÍøÂçÕ½ÂÔ¡£¡£¡£¡£
2021Äê02ÔÂ24ÈÕ£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ÐÞ¸´ÁËCisco ACI MSO API½Ó¿ÚÉϵÄÒ»¸öÑÏÖØµÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2021-1388£©£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ10.0¡£¡£¡£¡£
¸ÃÎó²îÊÇÌØ¶¨API½Ó¿ÚÉϵÄtokenÑéÖ¤²»×¼È·Ôì³ÉµÄ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄAPI·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»»ñµÃ¾ßÓÐÖÎÀíԱȨÏÞµÄtoken£¬£¬£¬£¬×îÖÕÈÆ¹ýÊÜÓ°ÏìÉè±¹ØÁ¬ÄÉí·ÝÑéÖ¤¡£¡£¡£¡£
¸ÃÎó²î½öÓ°ÏìCisco ACI MSO 3.0°æ±¾£¨Cisco ACI MSO 3.0(1i)°æ±¾²»ÊÜÓ°Ï죩£¬£¬£¬£¬²¢ÇÒ½öÔÚ°²ÅÅÓÚCisco Application Services EngineͳһӦÓÃÍÐ¹ÜÆ½Ì¨ÉÏʱ²ÅÊÜÓ°Ïì¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬Cisco»¹ÐÞ¸´ÁËCisco Application Services Engine£¨CisocÓ¦ÓÃЧÀÍÒýÇæ£©ÖеÄÒ»¸öÑÏÖØµÄδÊÚȨ»á¼ûÎó²î£¨CVE-2021-1393£©ºÍCisco NX-OSÖеÄÒ»¸öí§ÒâÎļþ²Ù×÷Îó²î£¨CVE-2021-1361£©£¬£¬£¬£¬Õâ2¸öÎó²îµÄCVSSÆÀ·Ö¾ùΪ9.8¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÕâЩÎó²îδÊÚȨ»á¼û×°±¸¡¢¸ü¸ÄÉèÖᢽ¨É衢ɾ³ý»òÒÔrootȨÏÞÁýÕÖí§ÒâÎļþ¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¸ÃÎó²îÒѱ»ÐÞ¸´£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶µ½Cisco ACI MSO 3.0£¨3m£©°æ±¾¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/home
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mso-authbyp-bb5GmBQv?
https://www.bleepingcomputer.com/news/security/cisco-fixes-maximum-severity-mso-auth-bypass-vulnerability/
0x04 ʱ¼äÏß
2021-02-24 CiscoÐû²¼Ç徲ͨ¸æ
2021-02-25 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/