NAKIVO Backup & ReplicationËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)À´Ï®£¬GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®

°ä²¼¹¦·ò 2025-02-28

NAKIVO Backup & Replication ÊÇÒ»¿îרһÓÚÐé¹¹»¯¡¢Ôƶ˼°»ìºÏ»·¾³µÄ±¸·ÝÓë¿àÄѸ´Ô­µÄ½â¾ö¹æ»®£¬ºÏÓÃÓÚ VMware vSphere¡¢Microsoft Hyper-V¡¢Nutanix AHV¡¢Amazon EC2¡¢Windows/Linux ºÍ Microsoft 365 »·¾³¡£±¸·Ý·þÎñÆ÷Äܹ»×°ÖÃÔÚ Windows¡¢Linux ºÍ NAS ²Ù×÷ϵͳÉÏ£¬ÓÈÆäÊʺÏÖÐÓׯóÒµÊг¡¡£


2025Äê2Ô£¬GA»Æ½ð¼×¼à¿Øµ½µ½¹Ù·½½¨¸´NAKIVO Backup & ReplicationËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)£¬¹¥»÷Õß¿ÉÀûÓÃSTPreLoadManagement ÀàÖÐµÄ getImageByPath²½Ö裬Èƹýõè¾¶ÑéÖ¤²¢¶Áȡָ±ê·þÎñÆ÷ÉϵÄËÁÒâÎļþ£¨Ô̺¬Ãô¸ÐÅäÖÃÎļþ¡¢Êý¾Ý¿â¡¢±¸·ÝÈÕÖ¾µÈ£©


1.png

¡¾·ì϶¸´ÏÖ½ØÍ¼¡¿

 

 

2.png

3.png

¡¾Ó°Ïì°æ±¾¡¿


NAKIVO Backup & Replication < v11.0.0.88174


¡¾½¨¸´½¨Òé¡¿


Ò»¡¢¹Ù·½½¨¸´¹æ»®£º

Ŀǰ¹Ù·½ÒѰ䲼°²È«¸üУ¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁ×îа汾£º

https://www.nakivo.com/resources/download/trial-download/download/


¶þ¡¢GA»Æ½ð¼×¹æ»®£º


1¡¢GA»Æ½ð¼×¼ì²âÀà²úÆ·¹æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©£¬Éý¼¶µ½×îа汾

ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©£¬Éý¼¶µ½×îа汾

ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©£¬Éý¼¶µ½×îа汾

ÌìÇåWEB°²È«ÀûÓÃÍø¹Ø£¨WAF£©£¬Éý¼¶µ½×îа汾

ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬Éý¼¶µ½×îа汾


¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ£¬ÊÂÎñ¿âÏÂÔØµØÖ·£º

ÊÂÎñ¿âÏÂÔØµØÖ·£ºhttps://venustech.download.venuscloud.cn/


2¡¢GA»Æ½ð¼×©ɨ²úÆ·¹æ»®


£¨1£©¡°GA»Æ½ð¼×·ì϶ɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè

 4.png


£¨2£©GA»Æ½ð¼×·ì϶ɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè

 5.png


3¡¢GA»Æ½ð¼××ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®


GA»Æ½ð¼××ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬¶ÔÈë¿â×ʲúNAKIVO Backup & ReplicationËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)½øÐÐÖÎÀí¡£

6.png 


4¡¢GA»Æ½ð¼×°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®


Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬½øÐйØÁªÕ½ÊõÅäÖ㬽áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬´Ó¶ø·¢ÏÖ¡°NAKIVO Backup & ReplicationËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£


1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°NAKIVO Backup & ReplicationËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)¡±·ì϶ɨÃ蹤×÷£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄ³ÁÒª×ʲú £»

7.png 


2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä £¿éÖУ¬Ôö³¤¡°L2_NAKIVO_Backup_ReplicationËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)¡±£¬Í¨¹ýGA»Æ½ð¼×¼ì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬·¢ÏÖ±í²¿¹¥»÷ÐÐΪ£º

8.png 


ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_NAKIVO_Backup_ReplicationËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓà £»


3£©Ôö³¤¡°L3_NAKIVO_Backup_ReplicationËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)¡±£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÅ×Ú»òÔ̺¬¡°L2_NAKIVO_Backup_ReplicationËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)¡±£¬¹¥»÷Á˾ֵÅ×Ú¡°¹¥»÷³É¹¦¡±£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶÈ¡£

9.png