¡¾·ì϶¹«¸æ¡¿VMware vCenter Server ÎļþÉÏ´«·ì϶£¨CVE-2021-22005£©

°ä²¼¹¦·ò 2021-09-23

0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-22005

ʱ      ¼ä

2021-09-21

Àà      ÐÍ

ÎļþÉÏ´«

µÈ      ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

2021Äê9ÔÂ21ÈÕ£¬VMware°ä²¼°²È«²¼¸æ£¬¹«¿ªÅû¶ÁËvCenter ServerÖеÄ19¸ö°²È«·ì϶£¬ÕâЩ·ì϶µÄCVSSv3ÆÀ·ÖÁìÓòΪ4.3-9.8 ¡£

ÆäÖУ¬×îΪÑϳÁµÄ·ì϶ΪvCenter Server ÖеÄËÁÒâÎļþÉÏ´«·ì϶(CVE-2021-22005)£¬¸Ã·ì϶´æÔÚÓÚvCenter ServerµÄ·ÖÎö·þÎñÖУ¬ÆäCVSSv3ÆÀ·ÖΪ 9.8 ¡£¿ÉÄÜÍøÂç½Ó¼ûvCenter Server É쵀 443 ¶Ë¿ÚµÄ¹¥»÷ÕßÄܹ»Í¨¹ýÉÏ´«¶ñÒâÎļþÔÚ vCenter Server ÉÏÔ¶³ÌÖ´ÐдúÂë ¡£¸Ã·ì϶ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓ㬹¥»÷¸´ÔӶȵÍ£¬ÇÒÎÞÐèÓû§½»»¥ ¡£

ƾ¾ÝShodanµÄËÑË÷Á˾Ö£¬ÊýÒÔǧ¼ÆµÄvCenter Server¿Éͨ¹ý»¥ÁªÍø½Ó¼û²¢Êܵ½¹¥»÷  ¡£Ä¿Ç°ÒѾ­¼ì²âµ½¹¥»÷ÕßÔÚɨÃèºÍ¹¥»÷´æÔÚ·ì϶µÄVMware vCenter ·þÎñÆ÷ ¡£

³ýCVE-2021-22005Ö®±í£¬VMware»¹½¨¸´ÁËvCenter ServerÖÐµÄÆäËü18¸ö°²È«·ì϶£º

l  CVE-2021-21991£ºvCenter Server ±¾µØÌáȨ·ì϶£¨CVSSv3ÆÀ·Ö8.8£©

l  CVE-2021-22006£ºvCenter Server ·´Ïò´úÀíÈÆ¹ý·ì϶£¨CVSSv3ÆÀ·Ö8.3£©

l  CVE-2021-22011£ºvCenter Serverδ¾­Éí·ÝÑéÖ¤µÄ API ¶Ëµã·ì϶£¨CVSSv3ÆÀ·Ö8.1£©

l  CVE-2021-22015£ºvCenter Server ±¾µØÌáȨ·ì϶£¨CVSSv3ÆÀ·Ö7.8£©

l  CVE-2021-22012£ºvCenter Server δ¾­Éí·ÝÑéÖ¤µÄ API ÐÅϢй¶·ì϶£¨CVSSv3ÆÀ·Ö7.5£©

l  CVE-2021-22013£ºvCenter Server õè¾¶±éÀú·ì϶£¨CVSSv3ÆÀ·Ö7.5£©

l  CVE-2021-22016£ºvCenter Server ·´ÉäÐÍ XSS ·ì϶£¨CVSSv3ÆÀ·Ö7.5£©

l  CVE-2021-22017£ºvCenter Server rhttpproxy ÈÆ¹ý·ì϶£¨CVSSv3ÆÀ·Ö7.3£©

l  CVE-2021-22014£ºvCenter Server Éí·ÝÑéÖ¤´úÂëÖ´Ðзì϶£¨CVSSv3ÆÀ·Ö7.2£©

l  CVE-2021-22018£ºvCenter Server Îļþɾ³ý·ì϶£¨CVSSv3ÆÀ·Ö6.5£©

l  CVE-2021-21992£ºvCenter Server XML ½âÎö»Ø¾ø·þÎñ·ì϶£¨CVSSv3ÆÀ·Ö6.5£©

l  CVE-2021-22007£ºvCenter Server ±¾µØÐÅϢй¶·ì϶£¨CVSSv3ÆÀ·Ö5.5£©

l  CVE-2021-22019£ºvCenter Server »Ø¾ø·þÎñ·ì϶£¨CVSSv3ÆÀ·Ö5.3£©

l  CVE-2021-22009£ºvCenter Server VAPI »Ø¾ø·þÎñ·ì϶£¨CVSSv3ÆÀ·Ö5.3£©

l  CVE-2021-22010£ºvCenter Server VPXD »Ø¾ø·þÎñ·ì϶£¨CVSSv3ÆÀ·Ö5.3£©

l  CVE-2021-22008£ºvCenter Server ÐÅϢй¶·ì϶£¨CVSSv3ÆÀ·Ö5.3£©

l  CVE-2021-22020£ºvCenter Server Analytics ·þÎñ»Ø¾ø·þÎñ·ì϶£¨CVSSv3ÆÀ·Ö5.0£©

l  CVE-2021-21993£ºvCenter Server SSRF ·ì϶£¨CVSSv3ÆÀ·Ö4.3£©

 

Ó°ÏìÁìÓò

CVE-2021-22005£º

VMware vCenter Server 7.0

VMware vCenter Server 6.7

×¢£ºCVE-2021-22005»áÓ°ÏìËùÓÐĬÈÏÅäÖÃµÄ vCenter Server 6.7 ºÍ 7.0 ²¿Ê𣬲»»áÓ°Ïì vCenter Server 6.5 ¡£ÆäËü18¸ö·ì϶µÄÓ°ÏìÁìÓòÇë°Ý¼ûVMware¹Ù·½²¼¸æ ¡£

 

0x02 ´ëÖý¨Òé

ĿǰVMwareÒѾ­°ä²¼ÁËÓйطì϶µÄ²¹¶¡£¬½¨ÒéÊÜÓ°ÏìµÄÓû§²Î¿¼VMware¹Ù·½²¼¸æÊµÊ±Éý¼¶¸üР¡£

ÏÂÔØÁ´½Ó£º

https://www.vmware.com/security/advisories/VMSA-2021-0020.html

 

0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2021-0020.html

https://www.bleepingcomputer.com/news/security/hackers-are-scanning-for-vmware-cve-2021-22005-targets-patch-now/

https://threatpost.com/vmware-ransomware-bug-vcenter-server/174901/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-09-23

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png