內容說明:
Cisco Data Center Network Manager存在多個安全性漏洞,攻擊者可利用漏洞繞過身分驗證的安全機制,導致攻擊者可取得管理權限執行任意行為
影響平台:
Cisco Data Center Network Manager 11.2(1)(含)以前版本
處置建議:
目前Cisco官方已針對此弱點釋出修復版本,請各機關聯絡設備維護廠商或將軟體版本更新至11.3(1)(含)以上版本
CVE編號:
CVE-2019-15975
CVE-2019-15976
CVE-2019-15977
CVE-2019-15978
CVE-2019-15979
CVE-2019-15980
CVE-2019-15981
CVE-2019-15982
CVE-2019-15983
CVE-2019-15984
CVE-2019-15985
CVE-2019-15999
參考資料:
1. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-auth-bypass
2. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-sql-inject
3. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-path-trav
4. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject
5. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-xml-ext-entity
6. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-unauth-access
7. https://www.tenable.com/blog/cve-2019-15975-cve-2019-15976-cve-2019-15977-critical-authentication-bypass-vulnerabilities-in
8. https://www.ithome.com.tw/news/135203