Aruba Mobility Controller Çå¾²Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-17

¡ñÎó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-7081£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬ £¬£¬£¬¹Ù·½£º9.8


¡ñÓ°Ïì°æ±¾


Aruba Networks ArubaOS£º


6.4.4.21֮ǰµÄ6.x°æ±¾

6.5.4.13֮ǰµÄ6.5.x°æ±¾

8.2.2.6֮ǰµÄ8.x°æ±¾

8.3.0.7֮ǰµÄ8.3.0.x°æ±¾

8.4.0.3֮ǰµÄ8.4.0.x°æ±¾


¡ñÎó²î¸ÅÊö


Aruba Networks ArubaOSÊÇÃÀ¹ú°²ÒÆÍ¨ÍøÂ磨Aruba Networks£©¹«Ë¾µÄÒ»Ì×ÃæÏòAruba Mobility-Defined Networks£¨°üÀ¨Òƶ¯¿ØÖÆÆ÷ºÍÒÆ¶¯½ÓÈë½»Á÷»ú£©µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£


Aruba Networks ArubaOSÖеÄÍøÂç¼àÌýÄ £¿£¿ £¿é±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýת´ïÌØÖÆµÄIPÁ÷Á¿Ê¹ÓøÃÎó²îÔì³ÉÀú³ÌÍ߽⻣» £»£»òÒÔϵͳȨÏÞÔڵײã²Ù×÷ϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


¡ñÎó²îÑéÖ¤


EXP£ºhttps://x-c3ll.github.io/posts/CVE-2018-7081-RCE-ArubaOS/¡£¡£¡£¡£¡£


¡ñÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬ £¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º


https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-004.txt


¡ñ²Î¿¼Á´½Ó


https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-004.txt