˼¿Æ½¨¸´DCNM¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-28

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-1620£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1619£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1621£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º7.5

CVE±àºÅ£ºCVE-2019-1622£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º5.3 



Ó°Ïì°æ±¾



ÊÜÓ°ÏìµÄ°æ±¾


Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾



·ì϶¸ÅÊö



Cisco Data Center Network ManagerÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×Êý¾ÝÖÐÐÄÖÎÀíϵͳ¡£¡£¡£ ¡£¡£¡£¡£¸ÃϵͳºÏÓÃÓÚCisco NexusºÍMDSϵÁл¥»»»ú£¬£¬£¬ £¬£¬£¬Ìṩ´æ´¢¿ÉÊÓ»¯¡¢ÅäÖú͹ÊÕÏÅųýµÈÖ°ÄÜ¡£¡£¡£ ¡£¡£¡£¡£Ë¼¿Æ°ä²¼DCNMµÄ°²È«¸üУ¬£¬£¬ £¬£¬£¬½¨¸´¶à¸ö·ì϶£º


CVE-2019-1620

Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖеĻùÓÚWebµÄÖÎÀí½çÃæ´æÔÚȨÏÞÐí¿ÉºÍ½Ó¼û½ÚÔìÎÊÌâ·ì϶£¬£¬£¬ £¬£¬£¬¸Ã·ì϶ԴÓÚ²»ÕýÈ·µÄȨÏÞÉèÖᣡ£¡£ ¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÔìµÄÊý¾ÝÀûÓø÷ì϶дÈëËÁÒâÎļþ²¢rootȨÏÞÖ´ÐдúÂë¡£¡£¡£ ¡£¡£¡£¡£


CVE-2019-1619

Cisco Data Center Network Manager (DCNM)11.1(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶£¬£¬£¬ £¬£¬£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÖÎÀí²Ç»°¡£¡£¡£ ¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄHTTPÒªÇóÀûÓø÷ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤²¢ÒÔÖÎÀíȨÏÞÖ´ÐÐËÁÒâ²Ù×÷¡£¡£¡£ ¡£¡£¡£¡£


CVE-2019-1621

Cisco Data Center Network Manager (DCNM) 11.2(1)֮ǰ°æ±¾ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚȨÏÞÐí¿ÉºÍ½Ó¼û½ÚÔìÎÊÌâ·ì϶£¬£¬£¬ £¬£¬£¬¸Ã·ì϶ԴÓÚ²»ÕýÈ·µÄȨÏÞÉèÖᣡ£¡£ ¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý½«¸Ã½çÃæÏνӵ½ÊÜÓ°ÏìÉ豸²¢ÒªÇóURLsÀûÓø÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢µÄ½Ó¼ûȨÏÞ¡£¡£¡£ ¡£¡£¡£¡£


CVE-2019-1622

Cisco Data Center Network Manager (DCNM)ÖлùÓÚWebµÄÖÎÀí½çÃæ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶¡£¡£¡£ ¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏνӵ½»ùÓÚWebµÄÖÎÀí½çÃæ²¢ÒªÇóURLsÀûÓø÷ì϶¼ìË÷Ãô¸ÐÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£



·ì϶ÑéÖ¤



ÔÝÎÞPOC/EXP¡£¡£¡£ ¡£¡£¡£¡£



½¨¸´½¨Òé



Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬ £¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó¼û²Î¿¼Á´½Ó¡£¡£¡£ ¡£¡£¡£¡£



²Î¿¼Á´½Ó



https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-codex
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-file-dwnld
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-infodiscl