Cisco ACI MSO APIÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-1388£©

°ä²¼¹¦·ò 2021-02-25

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-1388

ʱ   ¼ä

2021-02-25

Àà   ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ   ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Cisco ACI MSO 3.0

 

0x01 ·ì϶ÏêÇé

image.png

 

Cisco Multi-Site Orchestrator£¨MSO£©¿Éͨ¹ýÔËÓªÉÌÄܹ»ÊµÏÖ»ìºÏÔÆ¹æ»®£¬ÔÚDCNM¡¢ACI¡¢ÔƺͿçÓòµÄ±ßÔµÁìÓòÄÚ½ç˵ºÍЭµ÷ÍøÂçÕ½Êõ¡£

2021Äê02ÔÂ24ÈÕ£¬Cisco°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËCisco ACI MSO API½Ó¿ÚÉϵÄÒ»¸öÑϳÁµÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-1388£©£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ10.0¡£

¸Ã·ì϶ÊÇÌØ¶¨API½Ó¿ÚÉϵÄtokenÑéÖ¤²»ÕýÈ·Ôì³ÉµÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄAPI·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»ñµÃÓµÓÐÖÎÀíԱȨÏÞµÄtoken£¬×îÖÕÈÆ¹ýÊÜÓ°ÏìÉ豸ÉϵÄÉí·ÝÑéÖ¤¡£

¸Ã·ì϶½öÓ°ÏìCisco ACI MSO 3.0°æ±¾£¨Cisco ACI MSO 3.0(1i)°æ±¾²»ÊÜÓ°Ï죩£¬²¢ÇÒ½öÔÚ²¿ÊðÓÚCisco Application Services EngineͳһÀûÓÃÍÐ¹ÜÆ½Ì¨ÉÏʱ²ÅÊÜÓ°Ïì¡£

´Ë±í£¬Cisco»¹½¨¸´ÁËCisco Application Services Engine£¨CisocÀûÓ÷þÎñÒýÇæ£©ÖеÄÒ»¸öÑϳÁµÄδÊÚȨ½Ó¼û·ì϶£¨CVE-2021-1393£©ºÍCisco NX-OSÖеÄÒ»¸öËÁÒâÎļþ²Ù×÷·ì϶£¨CVE-2021-1361£©£¬Õâ2¸ö·ì϶µÄCVSSÆÀ·Ö¾ùΪ9.8¡£¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃÕâЩ·ì϶δÊÚȨ½Ó¼ûÉ豸¡¢¸ü¸ÄÅäÖᢴ´½¨¡¢É¾³ý»òÒÔrootȨÏÞ¸²¸ÇËÁÒâÎļþ¡£ 

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶Òѱ»½¨¸´£¬½¨ÒéʵʱÉý¼¶µ½Cisco ACI MSO 3.0£¨3m£©°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/home

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mso-authbyp-bb5GmBQv?

https://www.bleepingcomputer.com/news/security/cisco-fixes-maximum-severity-mso-auth-bypass-vulnerability/

 

0x04 ¹¦·òÏß

2021-02-24  Cisco°ä²¼°²È«²¼¸æ

2021-02-25  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png