Cisco IMC SupervisorºÍUCS Director¶à¸ö°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-22

? ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1938 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1935 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-1974 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬¹Ù·½Î´ÆÀ¶¨ 


Ó°Ïì°æ±¾


CVE-2019-1938
UCS Director releases 6.7.0.0 and 6.7.1.0
UCS Director Express for Big Data releases 3.7.0.0 and 3.7.1.0


CVE-2019-1935

Cisco IMC Supervisor releases:
2.1
2.2.0.0 through 2.2.0.6
Cisco UCS Director releases:
6.0
6.5
6.6.0.0 and 6.6.1.0
6.7.0.0 and 6.7.1.0
Cisco UCS Director Express for Big Data releases:
3.0
3.5
3.6
3.7.0.0 and 3.7.1.0


CVE-2019-1974

Cisco IMC Supervisor releases:
2.1
2.2.0.0 through 2.2.0.6
Cisco UCS Director releases:
5.5.0.0 through 5.5.0.2
6.0.0.0 through 6.0.1.3
6.5.0.0 through 6.5.0.3
6.6.0.0 and 6.6.1.0
6.7.0.0 through 6.7.2.0
Cisco UCS Director Express for Big Data releases:
2.1.0.0 through 2.1.0.2
3.0.0.0 through 3.0.1.3
3.5.0.0 through 3.5.0.3
3.6.0.0 and 3.6.1.0
3.7.0.0 through 3.7.2.0


·ì϶¸ÅÊö


Cisco Integrated Management Controller£¨IMC£©Supervisor SoftwareºÍUCS Director Software¶¼ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄ²úÆ·¡£


Cisco Integrated Management Controller£¨IMC£©SupervisorÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ÓÃÓÚ¶ÔUCS£¨Í³Ò»ÍÆËãϵͳ£©½øÐÐÖÎÀíµÄ¹¤¾ß £¬ËüÖ§³ÖHTTP¡¢SSH½Ó¼ûµÈ £¬²¢¿É¶Ô·þÎñÆ÷½øÐпª»ú¡¢¹Ø»úºÍ³ÁÆôµÈ²Ù×÷¡£


Cisco UCS DirectorÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Èںϻù´¡ÉèÊ©ÖÎÀí½â¾ö¹æ»®¡£¸Ã¹æ»®Ö§³ÖÓû§´Óµ¥Ò»ÖÎÀí½ÚÔį̀ÖÎÀíÍÆËãÄÜÁ¦¡¢ÍøÂç·þÎñ¡¢´æ´¢ºÍÐé¹¹»ú £¬ÒÔ¸ü¼±¾çºÍµÍ³É±¾µØ²¿ÊðºÍ°ä²¼IT·þÎñ¡£


CVE-2019-1938

Cisco UCS DirectorºÍCisco UCS Director Express for Big DataµÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤²¢Ê¹ÓÃÊÜÓ°ÏìϵͳÉϵÄÖÎÀíԱȨÏÞÖ´ÐÐËÁÒâ²Ù×÷¡£


¸Ã·ì϶ÊÇÓÉÓÚ²»ÕýÈ·µÄÉí·ÝÑéÖ¤ÒªÇó´¦ÖÃÔì³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢Ë;«ÐÄÉè¼ÆµÄHTTPÒªÇóÀ´ÀûÓô˷ì϶¡£ ³É¹¦ÀûÓÃÄܹ»ÔÊÐí·ÇÌØÈ¨¹¥»÷Õßͨ¹ýijЩAPI½Ó¼ûºÍÖ´ÐÐËÁÒâ²Ù×÷¡£


CVE-2019-1935

˼¿Æ¼¯³ÉÖÎÀí½ÚÔìÆ÷£¨IMC£©Supervisor £¬Cisco UCS DirectorºÍCisco UCS Director Express for Big DataÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃSCPÓû§ÕÊ»§£¨scpuser£©µÇ¼ÊÜÓ°ÏìϵͳµÄCLI  £¬ÓµÓÐĬÈÏÓû§Í´´¦¡£


¸Ã·ì϶ÊÇÓÉÓÚ´æÔÚÒѼͼµÄĬÈÏÕÊ»§ £¬ÆäÖÐÔ̺¬Î´¼Í¼µÄĬÈÏÃÜÂëºÍ¸ÃÕÊ»§µÄÃýÎóȨÏÞÉèÖᣠÔÚ×°ÖòúÆ·ÆÚ¼ä £¬²»»áÇ¿Ôì¸ü¸Ä´ËÕÊ»§µÄĬÈÏÃÜÂë¡£ ¹¥»÷ÕßÄܹ»Ê¹ÓøÃÕÊ»§µÇ¼ÊÜÓ°ÏìµÄϵͳÀ´ÀûÓô˷ì϶¡£ ³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÓÃscpuserÕÊ»§µÄȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£ ÕâÔ̺¬¶ÔϵͳÊý¾Ý¿âµÄÆëÈ«¶Áд½Ó¼ûȨÏÞ¡£


CVE-2019-1974

˼¿Æ¼¯³ÉÖÎÀí½ÚÔìÆ÷£¨IMC£©Ö÷¹Ü £¬Cisco UCS DirectorºÍCisco UCS Director Express for Big DataµÄ»ùÓÚWebµÄÖÎÀí½çÃæÖеķì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÓû§Éí·ÝÑéÖ¤²¢»ñµÃÖÎÀíÓû§µÄ½Ó¼ûȨÏÞ¡£


¸Ã·ì϶ÊÇÓÉÓÚÉí·ÝÑéÖ¤¹ý³ÌÖÐÒªÇó±êÍ·ÑéÖ¤²»¼°Ôì³ÉµÄ¡£ ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËÍһϵÁжñÒâÒªÇóÀ´ÀûÓô˷ì϶¡£ ÀûÓ÷ì϶Äܹ»Èù¥»÷Õß»ñµÃ¶ÔÊÜÓ°ÏìÉ豸µÄÆëÈ«ÖÎÀí½Ó¼ûȨÏÞ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


˼¿ÆÒѾ­°ä²¼ÁË×îеĹ̼þ°æ±¾ £¬ÊÜÓ°ÏìµÄÓû§Ó¦ÊµÊ±Éý¼¶½øÐзÀ»¤£º


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-ucsd-authbypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-usercred
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-ucs-authbypass


²Î¿¼Á´½Ó


https://threatpost.com/cisco-patches-six-critical-bugs/147585/