¡¾·ì϶¹«¸æ¡¿CVE-2020-7200 HPE SIMÔ¶³Ì´úÂëÖ´Ðзì϶
°ä²¼¹¦·ò 2020-12-170x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-7200 | ʱ ¼ä | 2020-12-17 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | HPE SIM 7.6.X |
0x01 ·ì϶ÏêÇé

HPE Systems Insight Manager£¨SIM£©ÊÇÓÃÓÚ¶à¸öHPE·þÎñÆ÷¡¢´æ´¢ºÍÍøÂç²úÆ·µÄÖÎÀíºÍÔ¶³ÌÖ§³Ö×Ô¶¯»¯½â¾ö¹æ»®¡£
2020Äê12ÔÂ15ÈÕ£¬HPE°ä²¼°²È«²¼¸æ£¬°ä²¼ÁËSIMÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-7200£©£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8¡£
¸Ã·ì϶ÊÇδ¶ÔÓû§Ìá½»µÄÊý¾Ý½øÐÐÕýÈ·ÑéÖ¤Ôì³ÉµÄ£¬Õâ¿ÉÄܵ¼Ö²»³ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐдúÂ룬ÎÞÐèÓû§½»»¥ÇÒÀûÓø´ÔӶȵ͡£
0x02 ´ëÖý¨Òé
HPE SIMÖ§³ÖLinuxºÍWindowsϵͳ¡£Ä¿Ç°£¬HPE½ö°ä²¼ÁËÕë¶ÔWindowsϵͳµÄһʱ´ëÊ©£¬HPE½«ÔÚ½«À´µÄ°æ±¾ÖÐÌṩ¸Ã·ì϶µÄÆëÈ«½¨¸´·¨Ê½¡£
һʱ´ëÊ©£¨½öºÏÓÃÓÚwindowsϵͳ£©£º
½ûÓá°½áºÏËÑË÷¡±ºÍ¡°½áºÏCMSÅäÖá±Ö°ÄÜ£¬²½ÖèÈçÏ£º
1.ÖÕ³¡HPE SIM·þÎñ¡£
2.´ÓSIMµÄ×°ÖÃõè¾¶ÖÐɾ³ý
3.³ÁÆôHPE SIM·þÎñ¡£
4. ÆÚ´ýHPE SIMÍøÒ³¡° https£º// SIM_IP£º50000¡±¿É½Ó¼ûºó£¬ÔÚºÅÁîÌáÐÑ·ûÖÐÖ´ÐиúÅÁmxtool -r -f tools\multi-cms-search.xml 1>nul 2>nul¡£
0x03 ²Î¿¼Á´½Ó
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04068en_us
https://www.bleepingcomputer.com/news/security/hpe-discloses-critical-zero-day-in-server-management-software/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7200
0x04 ¹¦·òÏß
2020-12-15 HPE°ä²¼°²È«²¼¸æ
2020-12-16 HPE¸üа²È«²¼¸æ
2020-12-17 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ