˼¿ÆElastic Services Controller REST APIÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶

°ä²¼¹¦·ò 2019-05-09


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


1.²¼¾°ÃèÊö


5ÔÂ7ÈÕ˼¿Æ°ä²¼²¼¸æ½¨¸´Elastic Services Controller£¨ESC£©ÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2019-1867£©¡£¸Ã·ì϶¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýREST APIÖеÄÉí·ÝÑéÖ¤¡£


2.Ó°ÏìÁìÓò


CVE ID  £º   CVE-2019-1867    
·ì϶µÈ¼¶£º   ÑϳÁ
Ó°ÏìÁìÓò£º   Elastic Services Controller  4.1¡¢4.2¡¢4.3¡¢4.4 

CVSSÆÀ·Ö£º   10.0


3.·ì϶ÏêÇé


¸Ã·ì϶ÊÇÓÉÓÚREST APIÒªÇóµÄ²»ÕýÈ·ÑéÖ¤Ôì³ÉµÄ¡£¹¥»÷Õß¿Éͨ¹ýÏòREST API·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓÿÉÔÊÐí¹¥»÷Õßͨ¹ýREST APIÖ´ÐÐËÁÒâ²Ù×÷ £¬²¢»ñµÃÖÎÀíȨÏÞ¡£


ÓÉÓÚESCĬÈÏδÆôÓÃREST API £¬ÖÎÀíÔ±¿Éͨ¹ýÔËÐкÅÁîsudo netstat -tlnup | grep '8443|8080'²é¿´µ±Ç°ÊÇ·ñÆôÓÃÁËREST API¡£ÒÔÏÂʾÀýΪÔÚ¶Ë¿Ú8443ÉÏÆôÓÃÁËREST API·þÎñµÄÊä³öÁ˾֣º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

4.½¨¸´½¨Òé


´Ë·ì϶ÒÑÔÚCisco Elastic Services Controller°æ±¾4.5Öн¨¸´¡£ÆäËü²¹¶¡¿ÉÓõİ汾¼ûÏÂ±í£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

5.²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190507-esc-authbypass