˼¿ÆElastic Services Controller REST APIÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î

Ðû²¼Ê±¼ä 2019-05-09


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


1.Åä¾°ÐÎò


5ÔÂ7ÈÕ˼¿ÆÐû²¼Í¨¸æÐÞ¸´Elastic Services Controller£¨ESC£©ÖеÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2019-1867£© ¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýREST APIÖеÄÉí·ÝÑéÖ¤ ¡£¡£¡£¡£¡£


2.Ó°Ïì¹æÄ£


CVE ID  £º   CVE-2019-1867    
Îó²îÆ·¼¶£º   ÑÏÖØ
Ó°Ïì¹æÄ££º   Elastic Services Controller  4.1¡¢4.2¡¢4.3¡¢4.4 

CVSSÆÀ·Ö£º   10.0


3.Îó²îÏêÇé


¸ÃÎó²îÊÇÓÉÓÚREST APIÇëÇóµÄ²»×¼È·ÑéÖ¤Ôì³ÉµÄ ¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÏòREST API·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î ¡£¡£¡£¡£¡£ÀÖ³ÉʹÓÿÉÔÊÐí¹¥»÷Õßͨ¹ýREST APIÖ´ÐÐí§Òâ²Ù×÷£¬£¬£¬£¬²¢»ñµÃÖÎÀíȨÏÞ ¡£¡£¡£¡£¡£


ÓÉÓÚESCĬÈÏδÆôÓÃREST API£¬£¬£¬£¬ÖÎÀíÔ±¿Éͨ¹ýÔËÐÐÏÂÁîsudo netstat -tlnup | grep '8443|8080'Éó²éÄ¿½ñÊÇ·ñÆôÓÃÁËREST API ¡£¡£¡£¡£¡£ÒÔÏÂʾÀýΪÔÚ¶Ë¿Ú8443ÉÏÆôÓÃÁËREST APIЧÀ͵ÄÊä³öЧ¹û£º

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

4.ÐÞ¸´½¨Òé


´ËÎó²îÒÑÔÚCisco Elastic Services Controller°æ±¾4.5ÖÐÐÞ¸´ ¡£¡£¡£¡£¡£ÆäËü²¹¶¡¿ÉÓõİ汾¼ûÏÂ±í£º

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

5.²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190507-esc-authbypass