Cisco Data Center Network Manager²Ù×÷ϵͳºÅÁî×¢Èë·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-01-06·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-15978£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.2£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-15979£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.2£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Cisco Data Center Network Manager 11.3(1)֮ǰ°æ±¾
·ì϶¸ÅÊö
Cisco Data Center Network ManagerÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Êý¾ÝÖÐÐÄÖÎÀíϵͳ¡£¸ÃϵͳºÏÓÃÓÚCisco NexusºÍMDSϵÁл¥»»»ú£¬Ìṩ´æ´¢¿ÉÊÓ»¯¡¢ÅäÖú͹ÊÕÏÅųýµÈÖ°ÄÜ¡£
CVE-2019-15978
Cisco Data Center Network Manager 11.3(1)֮ǰ°æ±¾ÖеÄREST API´æÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»Óгä·ÖÑéÖ¤Ìá½»µ½¸ÃAPIµÄÓû§ÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄÒªÇóÀûÓø÷ì϶ÒÔÖÎÀíȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£
CVE-2019-15979
Cisco Data Center Network Manager 11.3(1)֮ǰ°æ±¾ÖеÄSOAP API´æÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»Óгä·ÖÑéÖ¤Ìá½»µ½¸ÃAPIµÄÓû§ÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄÒªÇóÀûÓø÷ì϶ÒÔÖÎÀíȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject¡£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject


¾©¹«Íø°²±¸11010802024551ºÅ