CVE-2020-7197 | HPE SSMCÔ¶³ÌÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-10-26

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-7197

ʱ   ¼ä

2020-10-26

Àà   ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

3.7.0.0֮ǰµÄHP 3PAR   StoreServ Management and Core Software Media

 

 

HPE SSMCÊǺÏÓÃÓÚHPE Primera´æ´¢Æ½Ì¨ºÍHPE 3PAR StoreServÈ«ÉÁ´æÕóÁÐϵͳµÄÊý¾ÝÖÐÐÄÕóÁÐÖÎÀíºÍ»ã±¨½ÚÔį̀¡£Æäͨ¹ýHPE OneViewµÈHPEÖÎÀí¹¤¾ßÌṩÁËÏÖ´ú»¯µÄ±í¹ÛÒÔ¼°Í¨ÓõĽçÃæºÍ˵»°£¬²¢Ê¹ÓÃ×îеÄAPIºÍUI¼¼Êõ£¬¿É½«ËùÓÐHP 3PAR StoreServÖÎÀí¼¯ÖÐÔÚÒ»¸öµ¥Ò»µÄ´°¸ñÖУ¬ÌṩÎļþºÍ¿éµÄÈÚºÏÖÎÀíºÍ»ã±¨Ö°ÄÜ¡£

 

0x01 ·ì϶ÏêÇé

image.png

 

2020Äê10ÔÂ23ÈÕ£¬HPE°ä²¼°²È«¹«¸æ£¬ÆäÒѾ­½¨¸´ÁËHPE StoreServÖÎÀí½ÚÔį̀£¨SSMC£©ÖеÄÒ»¸öÔ¶³ÌÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶(CVE-2020-9197)£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ10.0¡£

ÓÉÓÚHPE StoreServÖÎÀí½ÚÔį̀£¨SSMC£©3.7.0.0ÊÇÒ»¸ö·Ç½Úµã¶àÕóÁÐÖÎÀíÆ÷WebÀûÓ÷¨Ê½£¬²¢ÇÒÓëÍйÜÕóÁÐÉϵÄÊý¾Ý¸ôÀ룬ÕâʹµÃSSMCºÜÈÝÒ×±»Ô¶³ÌÉí·ÝÑéÖ¤ÈÆ¹ý¡£

 

0x02 ´ëÖý¨Òé

ĿǰHPEÒѸüÐÂÁËHPE StoreServ Management Console (SSMC)3.7.0.0£¬½¨ÒéÉý¼¶µ½HPE 3PAR StoreServ Management Console 3.7.1.1»ò¸ü¸ß°æ±¾¡£

ÏÂÔØµØÖ·£º

https://myenterpriselicense.hpe.com/cwp-ui/free-software/SSMC_CONSOLE

 

0x03 ²Î¿¼Á´½Ó

https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbst04045en_us

https://securityaffairs.co/wordpress/109962/security/ssmc-critical-auth-bypass-issue.html?

0x04 ¹¦·òÏß

2020-10-23  HPE³õ´Î°ä²¼°²È«²¼¸æ

2020-10-24  HPE¸üа²È«²¼¸æ

2020-10-26  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

 

image.png