¡¾·ì϶¹«¸æ¡¿CVE-2020-7200 HPE SIMÔ¶³Ì´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2020-12-17

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-7200

ʱ   ¼ä

2020-12-17

Àà   ÐÍ

RCE

µÈ   ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

HPE SIM 7.6.X

 

0x01 ·ì϶ÏêÇé


 

image.png

HPE Systems Insight Manager£¨SIM£©ÊÇÓÃÓÚ¶à¸öHPE·þÎñÆ÷¡¢´æ´¢ºÍÍøÂç²úÆ·µÄÖÎÀíºÍÔ¶³ÌÖ§³Ö×Ô¶¯»¯½â¾ö¹æ»®¡£¡£¡£¡£¡£¡£¡£¡£

2020Äê12ÔÂ15ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬HPE°ä²¼°²È«²¼¸æ£¬£¬£¬ £¬£¬£¬£¬£¬°ä²¼ÁËSIMÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-7200£©£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£¡£¡£

¸Ã·ì϶ÊÇδ¶ÔÓû§Ìá½»µÄÊý¾Ý½øÐÐÕýÈ·ÑéÖ¤Ôì³ÉµÄ£¬£¬£¬ £¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö²»³ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐдúÂ룬£¬£¬ £¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥ÇÒÀûÓø´ÔӶȵ͡£¡£¡£¡£¡£¡£¡£¡£

0x02 ´ëÖý¨Òé

HPE SIMÖ§³ÖLinuxºÍWindowsϵͳ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬£¬£¬£¬£¬HPE½ö°ä²¼ÁËÕë¶ÔWindowsϵͳµÄһʱ´ëÊ©£¬£¬£¬ £¬£¬£¬£¬£¬HPE½«ÔÚ½«À´µÄ°æ±¾ÖÐÌṩ¸Ã·ì϶µÄÆëÈ«½¨¸´·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£

һʱ´ëÊ©£¨½öºÏÓÃÓÚwindowsϵͳ£©£º

½ûÓá°½áºÏËÑË÷¡±ºÍ¡°½áºÏCMSÅäÖá±Ö°ÄÜ£¬£¬£¬ £¬£¬£¬£¬£¬²½ÖèÈçÏ£º

1.ÖÕ³¡HPE SIM·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£

2.´ÓSIMµÄ×°ÖÃõè¾¶ÖÐɾ³ýÎļþ¡£¡£¡£¡£¡£¡£¡£¡£

3.³ÁÆôHPE SIM·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£

4. ÆÚ´ýHPE SIMÍøÒ³¡° https£º// SIM_IP£º50000¡±¿É½Ó¼ûºó£¬£¬£¬ £¬£¬£¬£¬£¬ÔÚºÅÁîÌáÐÑ·ûÖÐÖ´ÐиúÅÁmxtool -r -f tools\multi-cms-search.xml 1>nul 2>nul¡£¡£¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04068en_us

https://www.bleepingcomputer.com/news/security/hpe-discloses-critical-zero-day-in-server-management-software/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7200

 

0x04 ¹¦·òÏß

2020-12-15  HPE°ä²¼°²È«²¼¸æ

2020-12-16  HPE¸üа²È«²¼¸æ

2020-12-17  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png