¡¾Â©¶´Í¨¸æ¡¿Cisco IMCÃüÁî×¢Èë©¶´£¨CVE-2024-20356£©

Ðû²¼Ê±¼ä 2024-04-23

Ò»¡¢Â©¶´¸ÅÊö

©¶´Ãû³Æ

   Cisco IMCÃüÁî×¢Èë©¶´

CVE   ID

CVE-2024-20356

©¶´ÀàÐÍ

ÃüÁî×¢Èë

·¢ÏÖʱ¼ä

2024-04-22

©¶´ÆÀ·Ö

8.7

©¶´Æ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ

δ֪

 

Cisco Integrated Management Controller£¨¼ò³ÆIMC£©ÊÇÒ»ÖÖµ×°å¹ÜÀí¿ØÖÆÆ÷£¬ÓÃÓÚͨ¹ý¶à¸ö½Ó¿Ú¹ÜÀí UCS CϵÁлú¼ÜºÍUCS SϵÁд洢·þÎñÆ÷£¬°üÂÞ XML API¡¢Web (WebUI) ºÍÃüÁîÐÐ (CLI) ½Ó¿Ú¡£

2024Äê4ÔÂ22ÈÕ£¬¶«É­Æ½Ì¨VSRC¼à²âµ½Cisco IMCÃüÁî×¢Èë©¶´£¨CVE-2024-20356£¬CVSSÆÀ·Ö8.7£©µÄPoC/EXPÔÚ»¥ÁªÍøÉϹûÈ»¡£

ÓÉÓÚ¶ÔÓû§ÌṩµÄÊäÈëÑéÖ¤²»×㣬˼¿Æ¼¯³É¹ÜÀí¿ØÖÆÆ÷ (IMC) »ùÓÚWebµÄ¹ÜÀí½çÃæÖдæÔÚÃüÁî×¢Èë©¶´£¬¾­¹ýÉí·ÝÑéÖ¤ÇÒ¾ßÓйÜÀíÔ±¼¶±ðȨÏÞµÄÔ¶³ÌÍþвÕß¿Éͨ¹ýÏòÊÜÓ°ÏìÈí¼þµÄ»ùÓÚWebµÄ¹ÜÀí½çÃæ·¢ËͶñÒâÉè¼ÆµÄÃüÁîÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼Ö½«È¨ÏÞÌáÉýÖÁroot¡£

 

¶þ¡¢Ó°Ï췶Χ

Èç¹ûÒÔÏÂCisco²úÎïÔÚĬÈÏÅäÖÃÖÐÔËÐÐÒ×Êܹ¥»÷µÄ Cisco IMC °æ±¾£¬Ôò´Ë©¶´»áÓ°ÏìÕâЩ²úÎ

5000ϵÁÐÆóÒµÍøÂç¼ÆËãϵͳ (ENCS)

Catalyst 8300ϵÁÐEdge uCPE

¶ÀÁ¢Ä£Ê½ÏµÄUCS CϵÁÐ M5¡¢M6 ºÍM7»ú¼Ü·þÎñÆ÷

UCS EϵÁзþÎñÆ÷

¶ÀÁ¢Ä£Ê½Ï嵀 UCS SϵÁд洢·þÎñÆ÷

×¢£º¸Ã©¶´²îÒìÓÚCisco IMC CLIÃüÁî×¢Èë©¶´£¨CVE-2024-20295£©¡£

»ùÓÚÉÏÊöCisco UCS CϵÁзþÎñÆ÷Ö®Ò»µÄÔ¤ÅäÖð汾µÄ˼¿ÆÉ豸Èç¹û¹ûÈ»¶Ô Cisco IMC UI µÄ·ÃÎÊ£¬Ò²»áÊܵ½¸Ã©¶´µÄÓ°Ï죬ÊÜÓ°Ïì²úÎïÁÐ±í¼°ÆäÐÞ¸´°æ±¾¿É²Î¿¼¹Ù·½Í¨¸æ£º

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-bLuPcb

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ¸Ã©¶´ÒѾ­ÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£¨²¿ÃÅ£©£º

ÊÜÓ°Ïì²úÎï/É豸

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

Cisco 5000 Series ENCS ºÍCatalyst 8300 Series Edge uCPE

˼¿Æ NFVIS °æ±¾<=3.12

Ç¨ÒÆµ½Àι̰汾¡£

˼¿Æ NFVIS °æ±¾<=4.13

4.14.1

Cisco UCS C-Series M5 Rack   Server

˼¿Æ IMC °æ±¾4.0

Ç¨ÒÆµ½Àι̰汾¡£

˼¿Æ IMC °æ±¾4.1

4.1(3n)

˼¿Æ IMC °æ±¾4.2

4.2(3j)

˼¿Æ IMC °æ±¾4.3

4.3(2.240009)

Cisco UCS C-Series M6 Rack   Server

˼¿Æ IMC °æ±¾4.2

4.2(3j)

˼¿Æ IMC °æ±¾4.3

4.3(2.240009)

4.3(3.240022)

Cisco UCS C-Series M7 Rack   Server

˼¿Æ IMC °æ±¾4.3

4.3(3.240022)

Cisco UCS E-Series M2 ºÍM3 Server

˼¿Æ IMC °æ±¾<= 3.1

Ç¨ÒÆµ½Àι̰汾¡£

˼¿Æ IMC °æ±¾3.2

3.2.15.3

Cisco UCS E-Series M6 Server

˼¿Æ IMC °æ±¾<= 4.12

4.12.2

Cisco UCS S-Series Storage   Server

˼¿Æ IMC °æ±¾4.0

Ç¨ÒÆµ½Àι̰汾¡£

˼¿Æ IMC °æ±¾4.1

4.1(3n)

˼¿Æ IMC °æ±¾4.2

4.2(3k)

˼¿Æ IMC °æ±¾4.3

4.3(2.240009)

4.3(3.240041)

 

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 Í¨Óý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  Ê¹ÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-bLuPcb

https://github.com/nettitude/CVE-2024-20356


 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-04-23

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

19184841hpzh.png