¡¾Â©¶´Í¨¸æ¡¿Cisco IMC CLIÃüÁî×¢È멶´£¨CVE-2024-20295£©

Ðû²¼Ê±¼ä 2024-04-18


Ò»¡¢Â©¶´¸ÅÊö

©¶´Ãû³Æ

  Cisco   IMC CLIÃüÁî×¢È멶´

CVE   ID

CVE-2024-20295

©¶´ÀàÐÍ

ÃüÁî×¢Èë

·¢ÏÖʱ¼ä

2024-04-18

©¶´ÆÀ·Ö

8.8

©¶´Æ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

µ±µØ

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ

 

Cisco Integrated Management Controller£¨¼ò³ÆIMC£©ÊÇÒ»ÖÖµ×°å¹ÜÀí¿ØÖÆÆ÷£¬ÓÃÓÚͨ¹ý¶à¸ö½Ó¿Ú¹ÜÀí UCS CϵÁлú¼ÜºÍUCS SϵÁд洢·þÎñÆ÷£¬°üÂÞ XML API¡¢Web (WebUI) ºÍÃüÁîÐÐ (CLI) ½Ó¿Ú¡£

2024Äê4ÔÂ18ÈÕ£¬¶«É­Æ½Ì¨VSRC¼à²âµ½Cisco IMCÖÐÐÞ¸´ÁËÒ»¸öµ±µØȨÏÞÌáÉý©¶´£¨CVE-2024-20295£©£¬ÆäCVSSÆÀ·ÖΪ8.8£¬Ä¿Ç°¸Ã©¶´µÄPoC/EXPÒѹûÈ»¡£

ÓÉÓÚ¶ÔÓû§ÌṩµÄÊäÈëÑéÖ¤²»×㣬Cisco IMC CLIÖдæÔÚÃüÁî×¢È멶´£¬¾­¹ýÉí·ÝÑéÖ¤µÄµ±µØÍþвÕß¿ÉÒÔͨ¹ýÌá½»¶ñÒâÉè¼ÆµÄ CLI ÃüÁîÀ´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼Ö½«È¨ÏÞÌáÉýÖÁroot¡£

 


¶þ¡¢Ó°Ï췶Χ

Èç¹ûÒÔÏ Cisco ²úÎïÔÚĬÈÏÅäÖÃÖÐÔËÐÐÒ×Êܹ¥»÷µÄ Cisco IMC °æ±¾£¬Ôò´Ë©¶´»áÓ°ÏìÕâЩ²úÎ

5000 ϵÁÐÆóÒµÍøÂç¼ÆËãϵͳ (ENCS)

Catalyst 8300 ϵÁÐ Edge uCPE

¶ÀÁ¢Ä£Ê½Ï嵀 UCS C ϵÁлú¼Üʽ·þÎñÆ÷

UCS E ϵÁзþÎñÆ÷

»ùÓÚCisco UCS CϵÁзþÎñÆ÷Ô¤ÅäÖð汾µÄ˼¿ÆÉ豸Èç¹û¹ûÈ»¶ÔCisco IMC CLI µÄ·ÃÎÊ£¬Ò²»áÊܵ½Ó°Ï죬ĿǰÒÑÖª°üÂÞÒÔÏÂ˼¿Æ²úÎ

5520 ºÍ 8540 ÎÞÏß¿ØÖÆÆ÷

Ó¦Ó÷¨Ê½¼Æı»ù´¡ÉèÊ©¿ØÖÆÆ÷ (APIC) ·þÎñÆ÷

ÉÌÒµ°æ 6000 ºÍ 7000 É豸

Catalyst Center Appliances£¬ÒÔÇ°³ÆΪ DNA ÖÐÐÄ (DNAC)

ÔÆ·þÎñƽ̨ (CSP) 5000 ϵÁÐ

¹«¹²·þÎñƽ̨ÊÕ¼¯Æ÷ (CSPC) É豸

»¥ÁªÒƶ¯ÌåÑé (CMX) É豸

»¥ÁªÄþ¾² UCS ƽ̨ϵÁзþÎñÆ÷

Cyber Vision CenterÉ豸

ExpresswayϵÁÐÉ豸

HyperFlex Edge½Úµã

ÎÞ Fabric »¥Á¬£¨DC-NO-FI£©²¿Êðģʽ HyperFlex Êý¾ÝÖÐÐÄÖÐµÄ HyperFlex ½Úµã

IEC6400 Edge ComputeÉ豸

IOS XRv 9000 É豸

Meeting Server 1000 É豸

Nexus ÒDZí°åÉ豸

Prime InfrastructureÉ豸

Prime Network Registrar JumpstartÉ豸

Secure Email Gateways

Secure Email ºÍ Web Manager

Secure Endpoint Private CloudÉ豸

Secure Firewall Management CenterÉ豸£¬ÒÔÇ°³ÆΪ Firepower ¹ÜÀíÖÐÐÄ

Secure Malware Analytics É豸

Secure Network Analytics É豸

Secure Network Server É豸

Secure Web É豸

Secure Workload Servers

Telemetry Broker É豸

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ä¿Ç°¸Ã©¶´ÒѾ­ÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔÏ°汾£¨²¿ÃÅ£©£º

ÊÜÓ°Ïì²úÎï/É豸

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

Cisco 5000 Series ENCS ºÍCatalyst 8300 Series Edge uCPE

˼¿Æ NFVIS °æ±¾<=3.12

ǨÒƵ½Àι̰汾¡£

˼¿Æ NFVIS °æ±¾<=4.13

4.14.1

Cisco UCS C-Series M4 Rack   Server

˼¿Æ IMC °æ±¾<=4.0

ǨÒƵ½Àι̰汾¡£

4.1

4.1(2m)

Cisco UCS C-Series M5 Rack   Server

˼¿Æ IMC °æ±¾<=4.0

ǨÒƵ½Àι̰汾¡£

˼¿Æ IMC °æ±¾4.1

4.1(3m)

˼¿Æ IMC °æ±¾4.2

4.2(3j)

˼¿Æ IMC °æ±¾4.3

4.3(2.240002)

Cisco UCS C-Series M6 Rack   Server

˼¿Æ IMC °æ±¾4.2

4.2(3j)

˼¿Æ IMC °æ±¾4.3

4.3(2.240002)

Cisco UCS C-Series M7 Rack   Server

˼¿Æ IMC °æ±¾4.3

4.3(2.240002)

Cisco UCS E-Series M2 and M3

˼¿Æ IMC °æ±¾>= 3.2.6

3.2.15

Cisco UCS E-Series M6

˼¿Æ IMC °æ±¾<= 4.12

4.12.2

 

¾ßÌåÊÜÓ°Ïì°æ±¾¡¢ÐÞ¸´°æ±¾¼°¸ü¶àÏà¹ØÐÅÏ¢¿É²Î¿¼Cisoc¹Ù·½Í¨¸æ£º

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-mUx4c5AJ

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£

l  ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-mUx4c5AJ

https://www.bleepingcomputer.com/news/security/cisco-discloses-root-escalation-flaw-with-public-exploit-code/

 


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-04-18

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png