思科ESC REST API身份验证绕过误差清静通告

宣布时间 2019-05-09

误差编号和级别


CVE编号:CVE-2019-1867,危险级别:严重,CVSS分值:厂商自评:10.0,官方未评定


影响版本及版本


Cisco Elastic Services Controller Release 4.1、4.2、4.3、4.4,且启用了REST API。

默认情形下REST API 是禁用的。


不受影响的版本


Cisco Elastic Services Controller Release < 4.1

Cisco Elastic Services Controller Release 4.5


误差概述


5月7日思科宣布通告修复Elastic Services Controller(ESC)中的身份验证绕过误差(CVE-2019-1867)。该误差可允许未经身份验证的远程攻击者绕过REST API中的身份验证。


该误差是由于REST API请求的不准确验证造成的。攻击者可通过向REST API发送恶意请求来使用此误差。乐成使用可允许攻击者通过REST API执行恣意操作,并获得管理权限。


由于ESC默认未启用REST API,管理员可通过运行下令sudo netstat -tlnup | grep '8443|8080'审查目今是否启用了REST API。以下示例为在端口8443上启用了REST API服务的输出效果:

 

尊龙凯时 - 人生就是搏!


误差验证


暂无POC/EXP。


修复建议


此误差已在Cisco Elastic Services Controller版本4.5中修复。其它补丁可用的版本见下表:


尊龙凯时 - 人生就是搏!


参考链接


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190507-esc-authbypass