Cisco IMC SupervisorºÍUCS Director¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-08-22? Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1935£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1974£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
? Ó°Ïì°æ±¾
UCS Director releases 6.7.0.0 and 6.7.1.0
UCS Director Express for Big Data releases 3.7.0.0 and 3.7.1.0
CVE-2019-1935
Cisco IMC Supervisor releases:2.1
2.2.0.0 through 2.2.0.6
Cisco UCS Director releases:
6.0
6.5
6.6.0.0 and 6.6.1.0
6.7.0.0 and 6.7.1.0
Cisco UCS Director Express for Big Data releases:
3.0
3.5
3.6
3.7.0.0 and 3.7.1.0
CVE-2019-1974
Cisco IMC Supervisor releases:2.1
2.2.0.0 through 2.2.0.6
Cisco UCS Director releases:
5.5.0.0 through 5.5.0.2
6.0.0.0 through 6.0.1.3
6.5.0.0 through 6.5.0.3
6.6.0.0 and 6.6.1.0
6.7.0.0 through 6.7.2.0
Cisco UCS Director Express for Big Data releases:
2.1.0.0 through 2.1.0.2
3.0.0.0 through 3.0.1.3
3.5.0.0 through 3.5.0.3
3.6.0.0 and 3.6.1.0
3.7.0.0 through 3.7.2.0
? Îó²î¸ÅÊö
Cisco Integrated Management Controller£¨IMC£©Supervisor SoftwareºÍUCS Director Software¶¼ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄ²úÆ·¡£
Cisco Integrated Management Controller£¨IMC£©SupervisorÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ÓÃÓÚ¶ÔUCS£¨Í³Ò»ÅÌËãϵͳ£©¾ÙÐÐÖÎÀíµÄ¹¤¾ß£¬ËüÖ§³ÖHTTP¡¢SSH»á¼ûµÈ£¬²¢¿É¶Ô·þÎñÆ÷¾ÙÐпª»ú¡¢¹Ø»úºÍÖØÆôµÈ²Ù×÷¡£
Cisco UCS DirectorÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Èںϻù´¡ÉèÊ©ÖÎÃ÷È·¾ö¼Æ»®¡£¸Ã¼Æ»®Ö§³ÖÓû§´Ó¼òµ¥ÖÎÀí¿ØÖÆÌ¨ÖÎÀíÅÌËãÄÜÁ¦¡¢ÍøÂç·þÎñ¡¢´æ´¢ºÍÐéÄâ»ú£¬ÒÔ¸ü¿ìËٺ͵ͳÉÍâµØ°²ÅźÍÐû²¼IT·þÎñ¡£
Cisco UCS DirectorºÍCisco UCS Director Express for Big DataµÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤²¢Ê¹ÓÃÊÜÓ°ÏìϵͳÉϵÄÖÎÀíԱȨÏÞÖ´ÐÐí§Òâ²Ù×÷¡£
¸ÃÎó²îÊÇÓÉÓÚ²»×¼È·µÄÉí·ÝÑéÖ¤ÇëÇó´¦Öóͷ£Ôì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍÈ«ÐÄÉè¼ÆµÄHTTPÇëÇóÀ´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓÿÉÒÔÔÊÐí·ÇÌØÈ¨¹¥»÷Õßͨ¹ýijЩAPI»á¼ûºÍÖ´ÐÐí§Òâ²Ù×÷¡£
˼¿Æ¼¯³ÉÖÎÀí¿ØÖÆÆ÷£¨IMC£©Supervisor£¬Cisco UCS DirectorºÍCisco UCS Director Express for Big DataÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃSCPÓû§ÕÊ»§£¨scpuser£©µÇ¼ÊÜÓ°ÏìϵͳµÄCLI £¬¾ßÓÐĬÈÏÓû§Æ¾Ö¤¡£
¸ÃÎó²îÊÇÓÉÓÚ±£´æÒѼͼµÄĬÈÏÕÊ»§£¬ÆäÖаüÀ¨Î´¼Í¼µÄĬÈÏÃÜÂëºÍ¸ÃÕÊ»§µÄ¹ýʧȨÏÞÉèÖᣠÔÚ×°ÖòúƷʱ´ú£¬²»»áÇ¿ÖÆ¸ü¸Ä´ËÕÊ»§µÄĬÈÏÃÜÂë¡£ ¹¥»÷Õß¿ÉÒÔʹÓøÃÕÊ»§µÇ¼ÊÜÓ°ÏìµÄϵͳÀ´Ê¹ÓôËÎó²î¡£ ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÓÃscpuserÕÊ»§µÄȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£ Õâ°üÀ¨¶ÔϵͳÊý¾Ý¿âµÄÍêÈ«¶Áд»á¼ûȨÏÞ¡£
˼¿Æ¼¯³ÉÖÎÀí¿ØÖÆÆ÷£¨IMC£©Ö÷¹Ü£¬Cisco UCS DirectorºÍCisco UCS Director Express for Big DataµÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÓû§Éí·ÝÑéÖ¤²¢»ñµÃÖÎÀíÓû§µÄ»á¼ûȨÏÞ¡£
¸ÃÎó²îÊÇÓÉÓÚÉí·ÝÑéÖ¤Àú³ÌÖÐÇëÇó±êÍ·Ñé֤ȱ·¦Ôì³ÉµÄ¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍһϵÁжñÒâÇëÇóÀ´Ê¹ÓôËÎó²î¡£ ʹÓÃÎó²î¿ÉÒÔÈù¥»÷Õß»ñµÃ¶ÔÊÜÓ°Ïì×°±¸µÄÍêÈ«ÖÎÆÊÎö¼ûȨÏÞ¡£
? Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£
? ÐÞ¸´½¨Òé
˼¿ÆÒѾÐû²¼ÁË×îеĹ̼þ°æ±¾£¬ÊÜÓ°ÏìµÄÓû§Ó¦ÊµÊ±Éý¼¶¾ÙÐзÀ»¤£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-usercred
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-ucs-authbypass
? ²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ