Cisco ACI MSO APIÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-1388£©
°ä²¼¹¦·ò 2021-02-250x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-1388 | ʱ ¼ä | 2021-02-25 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Cisco ACI MSO 3.0 |
0x01 ·ì϶ÏêÇé

Cisco Multi-Site Orchestrator£¨MSO£©¿Éͨ¹ýÔËÓªÉÌÄܹ»ÊµÏÖ»ìºÏÔÆ¹æ»®£¬ÔÚDCNM¡¢ACI¡¢ÔƺͿçÓòµÄ±ßÔµÁìÓòÄÚ½ç˵ºÍе÷ÍøÂçÕ½Êõ¡£
2021Äê02ÔÂ24ÈÕ£¬Cisco°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËCisco ACI MSO API½Ó¿ÚÉϵÄÒ»¸öÑϳÁµÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-1388£©£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ10.0¡£
¸Ã·ì϶ÊÇÌØ¶¨API½Ó¿ÚÉϵÄtokenÑéÖ¤²»ÕýÈ·Ôì³ÉµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄAPI·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»ñµÃÓµÓÐÖÎÀíԱȨÏÞµÄtoken£¬×îÖÕÈÆ¹ýÊÜÓ°ÏìÉ豸ÉϵÄÉí·ÝÑéÖ¤¡£
¸Ã·ì϶½öÓ°ÏìCisco ACI MSO 3.0°æ±¾£¨Cisco ACI MSO 3.0(1i)°æ±¾²»ÊÜÓ°Ï죩£¬²¢ÇÒ½öÔÚ²¿ÊðÓÚCisco Application Services EngineͳһÀûÓÃÍÐ¹ÜÆ½Ì¨ÉÏʱ²ÅÊÜÓ°Ïì¡£
´Ë±í£¬Cisco»¹½¨¸´ÁËCisco Application Services Engine£¨CisocÀûÓ÷þÎñÒýÇæ£©ÖеÄÒ»¸öÑϳÁµÄδÊÚȨ½Ó¼û·ì϶£¨CVE-2021-1393£©ºÍCisco NX-OSÖеÄÒ»¸öËÁÒâÎļþ²Ù×÷·ì϶£¨CVE-2021-1361£©£¬Õâ2¸ö·ì϶µÄCVSSÆÀ·Ö¾ùΪ9.8¡£¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃÕâЩ·ì϶δÊÚȨ½Ó¼ûÉ豸¡¢¸ü¸ÄÅäÖᢴ´½¨¡¢É¾³ý»òÒÔrootȨÏÞ¸²¸ÇËÁÒâÎļþ¡£
0x02 ´ëÖý¨Òé
Ŀǰ¸Ã·ì϶Òѱ»½¨¸´£¬½¨ÒéʵʱÉý¼¶µ½Cisco ACI MSO 3.0£¨3m£©°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/home
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mso-authbyp-bb5GmBQv?
https://www.bleepingcomputer.com/news/security/cisco-fixes-maximum-severity-mso-auth-bypass-vulnerability/
0x04 ¹¦·òÏß
2021-02-24 Cisco°ä²¼°²È«²¼¸æ
2021-02-25 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ