˼¿Æ½¨¸´DCNM¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-28

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-1620 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1619 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1621 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º7.5

CVE±àºÅ£ºCVE-2019-1622 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º5.3 



Ó°Ïì°æ±¾



ÊÜÓ°ÏìµÄ°æ±¾


Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾



·ì϶¸ÅÊö



Cisco Data Center Network ManagerÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Êý¾ÝÖÐÐÄÖÎÀíϵͳ¡£¸ÃϵͳºÏÓÃÓÚCisco NexusºÍMDSϵÁл¥»»»ú £¬Ìṩ´æ´¢¿ÉÊÓ»¯¡¢ÅäÖú͹ÊÕÏÅųýµÈÖ°ÄÜ¡£Ë¼¿Æ°ä²¼DCNMµÄ°²È«¸üР£¬½¨¸´¶à¸ö·ì϶£º


CVE-2019-1620

Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖеĻùÓÚWebµÄÖÎÀí½çÃæ´æÔÚȨÏÞÐí¿ÉºÍ½Ó¼û½ÚÔìÎÊÌâ·ì϶ £¬¸Ã·ì϶ԴÓÚ²»ÕýÈ·µÄȨÏÞÉèÖ᣹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÔìµÄÊý¾ÝÀûÓø÷ì϶дÈëËÁÒâÎļþ²¢rootȨÏÞÖ´ÐдúÂë¡£


CVE-2019-1619

Cisco Data Center Network Manager (DCNM)11.1(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶ £¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÖÎÀí²Ç»°¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄHTTPÒªÇóÀûÓø÷ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤²¢ÒÔÖÎÀíȨÏÞÖ´ÐÐËÁÒâ²Ù×÷¡£


CVE-2019-1621

Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚȨÏÞÐí¿ÉºÍ½Ó¼û½ÚÔìÎÊÌâ·ì϶ £¬¸Ã·ì϶ԴÓÚ²»ÕýÈ·µÄȨÏÞÉèÖá£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý½«¸Ã½çÃæÏνӵ½ÊÜÓ°ÏìÉ豸²¢ÒªÇóURLsÀûÓø÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢µÄ½Ó¼ûȨÏÞ¡£


CVE-2019-1622

Cisco Data Center Network Manager (DCNM)ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏνӵ½»ùÓÚWebµÄÖÎÀí½çÃæ²¢ÒªÇóURLsÀûÓø÷ì϶¼ìË÷Ãô¸ÐÐÅÏ¢¡£



·ì϶ÑéÖ¤



ÔÝÎÞPOC/EXP¡£



½¨¸´½¨Òé



Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬²¹¶¡»ñÈ¡Á´½Ó¼û²Î¿¼Á´½Ó¡£



²Î¿¼Á´½Ó



https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-codex
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-file-dwnld
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-infodiscl