˼¿Æ½¨¸´DCNM¶à¸ö·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-06-28·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1619£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1621£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.5
CVE±àºÅ£ºCVE-2019-1622£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º5.3
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾
·ì϶¸ÅÊö
Cisco Data Center Network ManagerÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Êý¾ÝÖÐÐÄÖÎÀíϵͳ¡£¸ÃϵͳºÏÓÃÓÚCisco NexusºÍMDSϵÁл¥»»»ú£¬Ìṩ´æ´¢¿ÉÊÓ»¯¡¢ÅäÖú͹ÊÕÏÅųýµÈÖ°ÄÜ¡£Ë¼¿Æ°ä²¼DCNMµÄ°²È«¸üУ¬½¨¸´¶à¸ö·ì϶£º
Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖеĻùÓÚWebµÄÖÎÀí½çÃæ´æÔÚȨÏÞÐí¿ÉºÍ½Ó¼û½ÚÔìÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓÚ²»ÕýÈ·µÄȨÏÞÉèÖ᣹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÔìµÄÊý¾ÝÀûÓø÷ì϶дÈëËÁÒâÎļþ²¢rootȨÏÞÖ´ÐдúÂë¡£
Cisco Data Center Network Manager (DCNM)11.1(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÖÎÀí²Ç»°¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄHTTPÒªÇóÀûÓø÷ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤²¢ÒÔÖÎÀíȨÏÞÖ´ÐÐËÁÒâ²Ù×÷¡£
Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚȨÏÞÐí¿ÉºÍ½Ó¼û½ÚÔìÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓÚ²»ÕýÈ·µÄȨÏÞÉèÖá£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý½«¸Ã½çÃæÏνӵ½ÊÜÓ°ÏìÉ豸²¢ÒªÇóURLsÀûÓø÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢µÄ½Ó¼ûȨÏÞ¡£
Cisco Data Center Network Manager (DCNM)ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏνӵ½»ùÓÚWebµÄÖÎÀí½çÃæ²¢ÒªÇóURLsÀûÓø÷ì϶¼ìË÷Ãô¸ÐÐÅÏ¢¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó¼û²Î¿¼Á´½Ó¡£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-file-dwnld
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-infodiscl


¾©¹«Íø°²±¸11010802024551ºÅ