¡¾Â©¶´Í¨¸æ¡¿VMware vCenter Server ÎļþÉÏ´«Â©¶´£¨CVE-2021-22005£©
Ðû²¼Ê±¼ä 2021-09-230x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-22005 | ʱ ¼ä | 2021-09-21 |
Àà ÐÍ | ÎļþÉÏ´« | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà |
0x01 ©¶´ÏêÇé
2021Äê9ÔÂ21ÈÕ£¬VMwareÐû²¼Äþ¾²Í¨¸æ£¬¹ûÈ»Åû¶ÁËvCenter ServerÖеÄ19¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´µÄCVSSv3ÆÀ·Ö·¶Î§Îª4.3-9.8¡£
ÆäÖУ¬×îΪÑÏÖØµÄ©¶´ÎªvCenter Server ÖеÄÈÎÒâÎļþÉÏ´«Â©¶´(CVE-2021-22005)£¬¸Ã©¶´´æÔÚÓÚvCenter ServerµÄ·ÖÎö·þÎñÖУ¬ÆäCVSSv3ÆÀ·ÖΪ 9.8¡£Äܹ»ÍøÂç·ÃÎÊvCenter Server É쵀 443 ¶Ë¿ÚµÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÉÏ´«¶ñÒâÎļþÔÚ vCenter Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¸Ã©¶´ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓ㬹¥»÷ÅÓ´ó¶ÈµÍ£¬ÇÒÎÞÐèÓû§½»»¥¡£
ƾ¾ÝShodanµÄËÑË÷½á¹û£¬ÊýÒÔǧ¼ÆµÄvCenter Server¿Éͨ¹ý»¥ÁªÍø·ÃÎʲ¢Êܵ½¹¥»÷ ¡£Ä¿Ç°ÒѾ¼ì²âµ½¹¥»÷ÕßÕýÔÚɨÃèºÍ¹¥»÷´æÔÚ©¶´µÄVMware vCenter ·þÎñÆ÷¡£
³ýCVE-2021-22005Ö®Í⣬VMware»¹ÐÞ¸´ÁËvCenter ServerÖÐµÄÆäËü18¸öÄþ¾²Â©¶´£º
l CVE-2021-21991£ºvCenter Server µ±µØÌáȨ©¶´£¨CVSSv3ÆÀ·Ö8.8£©
l CVE-2021-22006£ºvCenter Server ·´ÏòÊðÀíÈÆ¹ý©¶´£¨CVSSv3ÆÀ·Ö8.3£©
l CVE-2021-22011£ºvCenter Serverδ¾Éí·ÝÑéÖ¤µÄ API ¶Ëµã©¶´£¨CVSSv3ÆÀ·Ö8.1£©
l CVE-2021-22015£ºvCenter Server µ±µØÌáȨ©¶´£¨CVSSv3ÆÀ·Ö7.8£©
l CVE-2021-22012£ºvCenter Server δ¾Éí·ÝÑéÖ¤µÄ API ÐÅϢй¶©¶´£¨CVSSv3ÆÀ·Ö7.5£©
l CVE-2021-22013£ºvCenter Server ·¾¶±éÀú©¶´£¨CVSSv3ÆÀ·Ö7.5£©
l CVE-2021-22016£ºvCenter Server ·´ÉäÐÍ XSS ©¶´£¨CVSSv3ÆÀ·Ö7.5£©
l CVE-2021-22017£ºvCenter Server rhttpproxy ÈÆ¹ý©¶´£¨CVSSv3ÆÀ·Ö7.3£©
l CVE-2021-22014£ºvCenter Server Éí·ÝÑéÖ¤´úÂëÖ´ÐЩ¶´£¨CVSSv3ÆÀ·Ö7.2£©
l CVE-2021-22018£ºvCenter Server Îļþɾ³ý©¶´£¨CVSSv3ÆÀ·Ö6.5£©
l CVE-2021-21992£ºvCenter Server XML ½âÎö¾Ü¾ø·þÎñ©¶´£¨CVSSv3ÆÀ·Ö6.5£©
l CVE-2021-22007£ºvCenter Server µ±µØÐÅϢй¶©¶´£¨CVSSv3ÆÀ·Ö5.5£©
l CVE-2021-22019£ºvCenter Server ¾Ü¾ø·þÎñ©¶´£¨CVSSv3ÆÀ·Ö5.3£©
l CVE-2021-22009£ºvCenter Server VAPI ¾Ü¾ø·þÎñ©¶´£¨CVSSv3ÆÀ·Ö5.3£©
l CVE-2021-22010£ºvCenter Server VPXD ¾Ü¾ø·þÎñ©¶´£¨CVSSv3ÆÀ·Ö5.3£©
l CVE-2021-22008£ºvCenter Server ÐÅϢй¶©¶´£¨CVSSv3ÆÀ·Ö5.3£©
l CVE-2021-22020£ºvCenter Server Analytics ·þÎñ¾Ü¾ø·þÎñ©¶´£¨CVSSv3ÆÀ·Ö5.0£©
l CVE-2021-21993£ºvCenter Server SSRF ©¶´£¨CVSSv3ÆÀ·Ö4.3£©
Ó°Ï췶Χ
CVE-2021-22005£º
VMware vCenter Server 7.0
VMware vCenter Server 6.7
×¢£ºCVE-2021-22005»áÓ°ÏìËùÓÐĬÈÏÅäÖÃµÄ vCenter Server 6.7 ºÍ 7.0 ²¿Ê𣬲»»áÓ°Ïì vCenter Server 6.5¡£ÆäËü18¸ö©¶´µÄÓ°Ï췶ΧÇë²Î¼ûVMware¹Ù·½Í¨¸æ¡£
0x02 ´¦Öý¨Òé
ĿǰVMwareÒѾÐû²¼ÁËÏà¹ØÂ©¶´µÄ²¹¶¡£¬½¨ÒéÊÜÓ°ÏìµÄÓû§²Î¿¼VMware¹Ù·½Í¨¸æ¼°Ê±Éý¼¶¸üС£
ÏÂÔØÁ´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
https://www.bleepingcomputer.com/news/security/hackers-are-scanning-for-vmware-cve-2021-22005-targets-patch-now/
https://threatpost.com/vmware-ransomware-bug-vcenter-server/174901/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-09-23 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º