【缝隙公告】Trend Micro ServerProtect 身份验证绕过缝隙 (CVE-2021-36745)

颁布功夫 2021-09-28


0x00 缝隙概述

CVE     ID

CVE-2021-36745

时      间

2021-09-24

类      型

身份验证绕过

等      级

严重

远程利用

影响领域


攻击复杂度

可用性

用户交互

所需权限

PoC/EXP


在野利用

 

0x01 缝隙详情

image.png

Trend Micro? ServerProtect是趋向科技的一款企业级反病毒法式。

2021年9月24日, 趋向科技颁布安全布告,修复了ServerProtect(防毒墙服务器版)中的一个身份验证绕过缝隙(CVE-2021-36745),其CVSSv3评分为9.8。

该缝隙存在于ServerProtect节制台中,由于不足适当的验证,远程攻击者能够利用它绕过受影响的 Trend Micro ServerProtect 装置的身份验证。

影响领域

ServerProtect for Storage (SPFS) 6.0

ServerProtect for EMC Celerra (SPEMC) 5.8

ServerProtect for Network Appliance Filers (SPNAF) 5.8

ServerProtect for Microsoft Windows / Novell Netware (SPNT) 5.8

 

0x02 措置建议

目前此缝隙已经修复,建议受影响的用户实时升级更新到以下版本:::

ServerProtect for Storage (SPFS) 6.0 CP1284

ServerProtect for EMC Celerra (SPEMC) 5.8 CP1577

ServerProtect for Network Appliance Filers (SPNAF) 5.8 CP1299

ServerProtect for Microsoft Windows / Novell Netware (SPNT) 5.8 CP1575

下载链接:::

https://success.trendmicro.com/solution/000289038

 

0x03 参考链接

https://success.trendmicro.com/solution/000289038

https://www.zerodayinitiative.com/advisories/ZDI-21-1115/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-CVE-2021-36745

 

0x04 更新版本

版本

日期

批改内容

V1.0

2021-09-28

初次颁布

 

0x05 文档附录

CNVD:::www.cnvd.org.cn

CNNVD:::www.cnnvd.org.cn

CVE:::cve.mitre.org

CVSS:::www.first.org

NVD:::nvd.nist.gov

 

0x06 关于OG东方厅

关注以下公家号,获取更多资讯:::

image.png