Database/Control plane, storage & DevOps
Ceph CephX authentication protocol: CephX does not correctly bind client identity, so an attacker who can capture
Impact
CephX does not correctly bind client identity, so an attacker who can capture cluster traffic can replay an authentication exchange and act as that client. On a flat storage fabric this lets one tenant impersonate another tenant's OSD/MDS session and reach their data.
Who can reach it
An attacker on the Ceph public or cluster network able to observe and re-send traffic - an adjacent compute node on the same storage VLAN is sufficient.
What to do
Upgrade to Ceph 14.2.14 / 15.2.6 or later and restart mons, OSDs and MDSes. Enable msgr2 secure mode (ms_cluster_mode=secure, ms_service_mode=secure) so cluster traffic is encrypted and authenticated end to end, and put tenant traffic on a separate L2 domain from the storage fabric.
References
Related entries
- Ceph CephX authentication protocol: An attacker who sniffs the storage network can replay a CephX authenticationCVE-2018-1128 · Ceph CephX authentication protocolHigh
- Ceph CephX authentication protocol: The CephX signature calculation can be bypassed, so an on-path attacker can alterCVE-2018-1129 · Ceph CephX authentication protocolMedium
- APC PowerChute Business Edition (v9.0.x and earlier): PowerChute runs the shutdown script that fires when a UPS reportsCVE-2020-7526 · APC PowerChute Business Edition (v9.0.x and earlier)High
- Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1: Authenticated file uploadCVE-2020-7569 · Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1High
- Nagios XI: OS command injection in the windowswmi config wizard (authenticated)CVE-2021-25296 · Nagios XIHigh
- Nagios XI: OS command injection in the switch config wizardCVE-2021-25297 · Nagios XIHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.