VMware NSXºÅÁî×¢Èë·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-07-25

·ì϶±àºÅ
CVE-2018-6961


·ì϶¼¶±ð
³§ÉÌ×ÔÆÀ£º³ÁÒª  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ°æ±¾£º
SD-WAN Edge 3.x, 2.x


·ì϶¸ÅÊö
Critical Start·¢ÏÖÁËVMwareµÄNSX SD-WAN»·¾³ÖÐÒ»¸öδ¾­Éí·ÝÑéÖ¤µÄºÅÁî×¢Èë·ì϶²¢ÏòVMwareµÄ°²È«ÏìÓ¦ÖÐÐÄ·¢³öÖҸ档¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÔÚÔ¶³Ì·þÎñÆ÷ÉÏÔËÐÐËÁÒâºÅÁî¡£ÓÉÓÚºÅÁî×¢Èë·ì϶¿ÉÄܵ¼ÖÂÍйÜWebÀûÓ÷¨Ê½µÄ·þÎñÆ÷Êܵ½ÇÖº¦£¬Òò¶øÍ¨³£±»ÒÔΪÊÇÒ»¸ö¼«¶ÈÑϳÁµÄȱµã£¬¿ÉÄÜ»áÓ°Ïì¸÷ÀàÍøÂçÉ豸£¬Ô̺¬Â·ÓÉÆ÷£¬»¥»»»úºÍ·À»ðǽ£¬´Ó¶ø½«Ãô¸ÐµÄ¡¢»ùÓÚÍøÂçµÄÐÅϢ¶³ö¸øÎ´¾­ÊÚȨµÄ½Ó¼ûºÍʹÓá£VMwareÏàʶºóѸ¿ì°ä²¼ÁËÒ»¸ö²¹¶¡À´½â¾öÕâ¸ö·ì϶¡£


ÔÚLuaÖУ¬ÀýÈ磬µ±¿ª·¢ÈËԱʹÓÃδ¾­ÑéÖ¤µÄÓû§Êý¾Ýͨ¹ýos.execute£¨£©»òio.popen£¨£©Luaº¯ÊýÔËÐвÙ×÷ϵͳºÅÁîʱ£¬¾Í»á³öÏÖÕâÖÖ·ì϶¡£Ò×Êܹ¥»÷µÄ´úÂëʾÀý£º
 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ì϶ÀûÓÃ
´Ë·ì϶µÄPOCÁ´½Ó£ºhttps://github.com/Critical-Start/Section-8¡£


½¨¸´½¨Òé
Ŀǰ¹Ù·½Òѽ¨¸´¸Ã·ì϶£¬Éý¼¶ÖÁ3.1.2°æ±¾£ºhttps://www.vmware.com/security/advisories/VMSA-2018-0011.html¡£


²Î¿¼Á´½Ó
https://www.criticalstart.com/2018/06/cve-2018-6961-unauthenticated-command-injection-vulnerability-in-vmware-nsx-sd-wan-by-velocloud/
https://github.com/Critical-Start/Section-8
https://www.vmware.com/security/advisories/VMSA-2018-0011.html