˼¿Æ½¨¸´DCNM¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-28

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-1620£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1619£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1621£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.5

CVE±àºÅ£ºCVE-2019-1622£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º5.3 



Ó°Ïì°æ±¾



ÊÜÓ°ÏìµÄ°æ±¾


Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾



·ì϶¸ÅÊö



Cisco Data Center Network ManagerÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Êý¾ÝÖÐÐÄÖÎÀíϵͳ ¡£¸ÃϵͳºÏÓÃÓÚCisco NexusºÍMDSϵÁл¥»»»ú£¬Ìṩ´æ´¢¿ÉÊÓ»¯¡¢ÅäÖú͹ÊÕÏÅųýµÈÖ°ÄÜ ¡£Ë¼¿Æ°ä²¼DCNMµÄ°²È«¸üУ¬½¨¸´¶à¸ö·ì϶£º


CVE-2019-1620

Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖеĻùÓÚWebµÄÖÎÀí½çÃæ´æÔÚȨÏÞÐí¿ÉºÍ½Ó¼û½ÚÔìÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓÚ²»ÕýÈ·µÄȨÏÞÉèÖà ¡£¹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÔìµÄÊý¾ÝÀûÓø÷ì϶дÈëËÁÒâÎļþ²¢rootȨÏÞÖ´ÐдúÂë ¡£


CVE-2019-1619

Cisco Data Center Network Manager (DCNM)11.1(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÖÎÀí²Ç»° ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄHTTPÒªÇóÀûÓø÷ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤²¢ÒÔÖÎÀíȨÏÞÖ´ÐÐËÁÒâ²Ù×÷ ¡£


CVE-2019-1621

Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚȨÏÞÐí¿ÉºÍ½Ó¼û½ÚÔìÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓÚ²»ÕýÈ·µÄȨÏÞÉèÖà ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý½«¸Ã½çÃæÏνӵ½ÊÜÓ°ÏìÉ豸²¢ÒªÇóURLsÀûÓø÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢µÄ½Ó¼ûȨÏÞ ¡£


CVE-2019-1622

Cisco Data Center Network Manager (DCNM)ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶ ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏνӵ½»ùÓÚWebµÄÖÎÀí½çÃæ²¢ÒªÇóURLsÀûÓø÷ì϶¼ìË÷Ãô¸ÐÐÅÏ¢ ¡£



·ì϶ÑéÖ¤



ÔÝÎÞPOC/EXP ¡£



½¨¸´½¨Òé



Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó¼û²Î¿¼Á´½Ó ¡£



²Î¿¼Á´½Ó



https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-codex
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-file-dwnld
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-infodiscl