Supermicro·þÎñÆ÷UBAnywhere·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-05

?·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


?Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Supermicro X9¡¢X10ºÍ X11 ƽ̨µÄBMC×é¼þ


?·ì϶¸ÅÊö


Supermicro X9¡¢X10ºÍ X11 ƽ̨µÄBMC×é¼þÐ鹹ýÌåʵÏÖÖб»ÆØ¶à¸öÎÊÌâ £¬ËüÃDZ»Í³³ÆÎª USBAnywhere¡£


BMCÖ¼ÔÚÔÊÐíÖÎÀíÔ±¶Ô·þÎñÆ÷Ö´Ðдø±íÖÎÀí £¬Òò¶øÊǸßȨÏÞ×é¼þ¡£Ô¶³Ì½Ó¼ûʱ £¬Ð鹹ýÌå·þÎñÔÊÐíÃ÷ÎÄÉí·ÝÑéÖ¤ £¬·¢ËÍ´óÁ¿Î´¼ÓÃܵÄÁ÷Á¿ £¬ÆäÓಿÃÅʹÓÃÈõ¼ÓÃÜËã·¨ £¬²¢ÇÒºÜÈÝÒ×ÈÆ¹ýÉí·ÝÑéÖ¤¡£ÕâЩÎÊÌâÔÊÐí¹¥»÷ÕßÇáËÉ»ñÈ¡¶Ô·þÎñÆ÷µÄ½Ó¼ûȨÏÞ £¬²½ÖèÊDz¶»ñºÏ·¨Óû§µÄÉí·ÝÑéÖ¤Êý¾Ý°ü £¬Ê¹ÓÃĬÈÏÍ´´¦¡£ÔÚijЩÇé¿öÏ £¬µ××Ó²»±ØÒªÈκÎÍ´´¦¡£ÏνӺó £¬Ð鹹ýÌå·þÎñÔÊÐí¹¥»÷Õß×÷ΪԭʼUSBÉ豸ÓëÖ÷»úϵͳ½øÐн»»¥¡£ÕâÒâζ׏¥»÷ÕßÄܹ»Ïñ¹¥»÷USB¶Ë¿ÚÒ»Ñù¹¥»÷·þÎñÆ÷ £¬ÀýÈç¼ÓÔØÐµIJÙ×÷ϵͳӳÏñ»òʹÓüüÅ̺ÍÊó±êÅú¸Ä·þÎñÆ÷ £¬Ö²Èë¶ñÒâÈí¼þ £¬ÉõÖÁÆëÈ«½ûÓÃÉ豸¡£Ò×ÓÚ½Ó¼ûºÍÖ±½Ó¹¥»÷õè¾¶µÄ½áºÏÄܹ»Ê¹²»³ÉÊìµÄ¹¥»÷ÕßÔ¶³Ì¹¥»÷×éÖ¯ÖÐ×îÓмÛÖµµÄ×ʲú¡£


×êÑÐÈËÔ±ÔÚ×êÑÐÂÛÎÄÖÐÏêÊöÁËÕâЩ·ì϶ÒÔ¼°ÍþвÈËÔ±ÈôºÎÀûÓÃËüÃÇ¡£×êÑÐÔ±Ú¹ÊͳÆ £¬¿Éͨ¹ý°ä²¼ÓÚ SMC web ½Ó¿ÚµÄ Java ÀûÓ÷¨Ê½À´½Ó¼ûÐ鹹ýÌå·þÎñ¡£Õâ¿î app Ïνӵ½Ð鹹ýÌå·þÎñ²¢¼àÌý BMC É쵀 TCP ¶Ë¿Ú623¡£¸Ã·þÎñʹÓÃ×Ô½ç˵µÄ»ùÓÚÊý¾Ý°üµÄÌåʽÈÏÖ¤¿Í»§¶Ë²¢ÔÚ¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼äÒÆ¶¯ USB Êý¾Ý°ü¡£


¼´±ãÕâ¿î JavaÀûÓ÷¨Ê½ÒÀ¸½µÄÊÇΨһµÄ»á»° ID ½øÐÐÈÏÖ¤ £¬µ«×êÑÐÈËÔ±ÒÔΪ¸Ã·þÎñ¿ÉÔÊÐíÃ÷ÎÄ´ó¾ÖµÄƾ֤¡£Áí±í £¬½ö¶Ô³õʼµÄÈÏÖ¤Êý¾Ý°üÁ÷Á¿½øÐÐÁ˼ÓÃÜ¡£Èõµã»¹Ô̺¬Ê¹ÓÃÁËÒÀ¸½Ò×Êܹ¥»÷µÄ RC4Á÷ÃÜÂëºÍ³Ê´Ë¿Ì BMC ¹Ì¼þÖеÄÒ»¸öÃÜÔ¿µÄ²»Á¼¼ÓÃÜËã·¨¡£


Áí±íÒ»¸öÈõµãÊÇÓ°ÏìSupermicro X10 ºÍ X11 ƽ̨µÄÈÏÖ¤ÈÆ¹ýÈõµã¡£×êÑÐÈËÔ±°µÊ¾ £¬µ±¿Í»§¶ËÕýÈ·µØÑéÖ¤Ð鹹ýÌå·þÎñ²¢¶Ï¿ªÏνӺó £¬¸Ã¿Í»§¶ËµÄ·þÎñÄÚ²¿×´Ì¬ÒÀȻδŤת¡£


¹ÌÈ»ÌýÆðÀ´ºÜΣÏÕ £¬µ«ºÃÔÚÓÉÓÚ BMC ²Ù×÷ϵͳִÐи÷ÖÅä £¬Òò¶ø¹¥»÷Õß²»³ÉÄܽÚÔìËü¡£Ö»¹ÜÈç´Ë £¬ÈôÊǹ¥»÷ÕßÓµÓÐ×ã¹»µÄÓÆ¾ÃÐÔ £¬ÄÇô´ÓÀíÂÛÉÏÀ´½² £¬¾Í¿ÉÄܱ»·ÖÅ䏸´Ëǰ¾­ÈÏÖ¤µÄÓû§µÄÌ×½Ó×ÖÎļþÃèÊö·û±àºÅ¡£


¹ÌÈ»ÎÞÊýÊÜÓ°ÏìµÄ·þÎñÆ÷λÓÚÄÚ²¿ÍøÂç £¬µ«×êÑÐÈËÔ±°µÊ¾ÔÚ»¥ÁªÍøÉÏÕÒµ½ÁË4.7Íǫ̀Ò×Êܹ¥»÷µÄ·þÎñÆ÷¡£


?·ì϶ÑéÖ¤


POC£ºhttps://github.com/eclypsium/USBAnywhere¡£ 


?½¨¸´½¨Òé


ÆóÒµ¸Ãµ±ÀûÓÃSupermicro Òѽ¨¸´µÄ X9¡¢X10 ºÍ X11 ƽ̨×îй̼þ£ºhttps://www.supermicro.org.cn/support/security_center.cfm¡£


?²Î¿¼Á´½Ó


https://eclypsium.com/2019/09/03/usbanywhere-bmc-vulnerability-opens-servers-to-remote-attack/