CVE-2020-7197 | HPE SSMCÔ¶³ÌÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-10-260x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-7197 | ʱ ¼ä | 2020-10-26 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | 3.7.0.0֮ǰµÄHP 3PAR StoreServ Management and Core Software Media |
HPE SSMCÊǺÏÓÃÓÚHPE Primera´æ´¢Æ½Ì¨ºÍHPE 3PAR StoreServÈ«ÉÁ´æÕóÁÐϵͳµÄÊý¾ÝÖÐÐÄÕóÁÐÖÎÀíºÍ»ã±¨½ÚÔį̀¡£Æäͨ¹ýHPE OneViewµÈHPEÖÎÀí¹¤¾ßÌṩÁËÏÖ´ú»¯µÄ±í¹ÛÒÔ¼°Í¨ÓõĽçÃæºÍ˵»°£¬²¢Ê¹ÓÃ×îеÄAPIºÍUI¼¼Êõ£¬¿É½«ËùÓÐHP 3PAR StoreServÖÎÀí¼¯ÖÐÔÚÒ»¸öµ¥Ò»µÄ´°¸ñÖУ¬ÌṩÎļþºÍ¿éµÄÈÚºÏÖÎÀíºÍ»ã±¨Ö°ÄÜ¡£
0x01 ·ì϶ÏêÇé

2020Äê10ÔÂ23ÈÕ£¬HPE°ä²¼°²È«¹«¸æ£¬ÆäÒѾ½¨¸´ÁËHPE StoreServÖÎÀí½ÚÔį̀£¨SSMC£©ÖеÄÒ»¸öÔ¶³ÌÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶(CVE-2020-9197)£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ10.0¡£
ÓÉÓÚHPE StoreServÖÎÀí½ÚÔį̀£¨SSMC£©3.7.0.0ÊÇÒ»¸ö·Ç½Úµã¶àÕóÁÐÖÎÀíÆ÷WebÀûÓ÷¨Ê½£¬²¢ÇÒÓëÍйÜÕóÁÐÉϵÄÊý¾Ý¸ôÀ룬ÕâʹµÃSSMCºÜÈÝÒ×±»Ô¶³ÌÉí·ÝÑéÖ¤ÈÆ¹ý¡£
0x02 ´ëÖý¨Òé
ĿǰHPEÒѸüÐÂÁËHPE StoreServ Management Console (SSMC)3.7.0.0£¬½¨ÒéÉý¼¶µ½HPE 3PAR StoreServ Management Console 3.7.1.1»ò¸ü¸ß°æ±¾¡£
ÏÂÔØµØÖ·£º
https://myenterpriselicense.hpe.com/cwp-ui/free-software/SSMC_CONSOLE
0x03 ²Î¿¼Á´½Ó
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbst04045en_us
https://securityaffairs.co/wordpress/109962/security/ssmc-critical-auth-bypass-issue.html?
0x04 ¹¦·òÏß
2020-10-23 HPE³õ´Î°ä²¼°²È«²¼¸æ
2020-10-24 HPE¸üа²È«²¼¸æ
2020-10-26 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/


¾©¹«Íø°²±¸11010802024551ºÅ