˼¿ÆÐÞ¸´DCNM¶à¸öÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-06-28Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1619£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1621£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.5
CVE±àºÅ£ºCVE-2019-1622£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º5.3
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾
Îó²î¸ÅÊö
Cisco Data Center Network ManagerÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Êý¾ÝÖÐÐÄÖÎÀíϵͳ¡£¸ÃϵͳÊÊÓÃÓÚCisco NexusºÍMDSϵÁн»Á÷»ú£¬Ìṩ´æ´¢¿ÉÊÓ»¯¡¢ÉèÖú͹ÊÕÏɨ³ýµÈ¹¦Ð§¡£Ë¼¿ÆÐû²¼DCNMµÄÇå¾²¸üУ¬ÐÞ¸´¶à¸öÎó²î£º
Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖеĻùÓÚWebµÄÖÎÀí½çÃæ±£´æÈ¨ÏÞÔÊÐíºÍ»á¼û¿ØÖÆÎÊÌâÎó²î£¬¸ÃÎó²îÔ´ÓÚ²»×¼È·µÄȨÏÞÉèÖ᣹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÖƵÄÊý¾ÝʹÓøÃÎó²îдÈëí§ÒâÎļþ²¢rootȨÏÞÖ´ÐдúÂë¡£
Cisco Data Center Network Manager (DCNM)11.1(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ±£´æ»á¼û¿ØÖƹýʧÎó²î£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷÖÎÆÊÎö»°¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄHTTPÇëÇóʹÓøÃÎó²îÈÆ¹ýÉí·ÝÑéÖ¤²¢ÒÔÖÎÀíȨÏÞÖ´ÐÐí§Òâ²Ù×÷¡£
Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ±£´æÈ¨ÏÞÔÊÐíºÍ»á¼û¿ØÖÆÎÊÌâÎó²î£¬¸ÃÎó²îÔ´ÓÚ²»×¼È·µÄȨÏÞÉèÖá£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý½«¸Ã½çÃæÅþÁ¬µ½ÊÜÓ°Ïì×°±¸²¢ÇëÇóURLsʹÓøÃÎó²î»ñÈ¡Ãô¸ÐÐÅÏ¢µÄ»á¼ûȨÏÞ¡£
Cisco Data Center Network Manager (DCNM)ÖлùÓÚWebµÄÖÎÀí½çÃæ±£´æ»á¼û¿ØÖƹýʧÎó²î¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÅþÁ¬µ½»ùÓÚWebµÄÖÎÀí½çÃæ²¢ÇëÇóURLsʹÓøÃÎó²î¼ìË÷Ãô¸ÐÐÅÏ¢¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬²¹¶¡»ñÈ¡Á´½Ó¼û²Î¿¼Á´½Ó¡£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-file-dwnld
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-infodiscl


¾©¹«Íø°²±¸11010802024551ºÅ