Database/Control plane, storage & DevOps
Ceph CephX authentication protocol: An attacker who sniffs the storage network can replay a CephX authentication
Impact
An attacker who sniffs the storage network can replay a CephX authentication exchange and obtain a session as the client it copied, gaining that client's read and write rights against RADOS pools. The victim's identity is fully assumed - there is no distinct attacker identity to audit.
Who can reach it
Passive-then-active attacker on the Ceph public/cluster network. Any tenant node sharing the storage L2 domain qualifies.
What to do
Upgrade to a Ceph release carrying the cephx replay fix (12.2.6+/13.2.x) and restart all daemons. Move to msgr2 secure mode and isolate the storage fabric from tenant-controlled interfaces.
References
Related entries
- Ceph CephX authentication protocol: The CephX signature calculation can be bypassed, so an on-path attacker can alterCVE-2018-1129 · Ceph CephX authentication protocolMedium
- Ceph CephX authentication protocol: CephX does not correctly bind client identity, so an attacker who can captureCVE-2020-25660 · Ceph CephX authentication protocolHigh
- Emerson/Vertiv Liebert IntelliSlot Web Card (config/configUser.htm, config/configTelnet.htm): The IntelliSlot cardCVE-2018-12922 · Emerson/Vertiv Liebert IntelliSlot Web Card (config/configUser.htm, config/configTelnet.htm)High
- ntpd (protocol engine, zero-origin timestamp): Continually sending packets with a zero-origin timestamp lets a remoteCVE-2018-7185 · ntpd (protocol engine, zero-origin timestamp)High
- Ceph RADOS Gateway (RGW, Beast frontend): An unauthenticated client can crash radosgw by sending valid headers followedCVE-2019-10222 · Ceph RADOS Gateway (RGW, Beast frontend)High
- Slurm (srun --uid): Srun --uid drops privileges in the wrong order, so a step launched through it can end up runningCVE-2019-19728 · Slurm (srun --uid)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.