Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2020-8349

Quick assessment

Affected
Lenovo Cloud Networking Operating System (CNOS)
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

CNOS是中国的一个基于SAI的网络操作系统。CNOS网络操作系统具有全局状态实时采集、业务按需服务、资源智能调度三大功能,具有全维度场景、强兼容、高性能的特点,可实现基于微服务的功能动态扩展,分钟级链路开通,毫秒级故障倒换,端到端逐跳可控等能力,支持兼容厂商设备和白盒化设备。 CNOS 存在代码注入漏洞,该漏洞源于内部安全审查已经在中发现了一个未经身份验证的远程代码执行漏洞。默认情况下此接口是禁用的,除非启用,否则不会受到攻击。当启用时,它只在连接到VRF和定义的acl允许的地方容易受到攻击。

CVSS 9.8 · Critical EPSS 2.25% · P82
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-8349

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is only vulnerable where attached to a VRF and as allowed by defined ACLs. Lenovo strongly recommends upgrading to a non-vulnerable CNOS release. Where not possible, Lenovo recommends disabling the REST API management interface or restricting access to the management VRF and further limiting access to authorized management stations via ACL.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
CNOS 代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
CNOS是中国的一个基于SAI的网络操作系统。CNOS网络操作系统具有全局状态实时采集、业务按需服务、资源智能调度三大功能,具有全维度场景、强兼容、高性能的特点,可实现基于微服务的功能动态扩展,分钟级链路开通,毫秒级故障倒换,端到端逐跳可控等能力,支持兼容厂商设备和白盒化设备。 CNOS 存在代码注入漏洞,该漏洞源于内部安全审查已经在中发现了一个未经身份验证的远程代码执行漏洞。默认情况下此接口是禁用的,除非启用,否则不会受到攻击。当启用时,它只在连接到VRF和定义的acl允许的地方容易受到攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Lenovo Cloud Networking Operating System (CNOS) unspecified ~ 10.10.6.0 -

II. Public POCs for CVE-2020-8349

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-8349

请登录查看更多情报信息。

Vendor Advisories for CVE-2020-8349 (1)

Same Patch Batch · Lenovo · 2020-10-14 · 5 CVEs total

CVE-2020-8350 8.8 HIGH Lenovo ThinkPad Stack Wireless Router 授权问题漏洞
CVE-2020-8338 7.8 HIGH Lenovo Diagnostics 代码问题漏洞
CVE-2020-8345 7.3 HIGH Lenovo Vantage 代码问题漏洞
CVE-2020-8332 6.4 MEDIUM IBM System x servers 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2020-8349

No comments yet


Leave a comment