Acronis | ¶à¸ö±¾µØÌáȨ·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-10-130x00 ·ì϶¸ÅÊö
AcronisÊÇרΪÏû·ÑÕß¡¢ÖÐÓׯóÒµ¼°´óÐÍÆóÒµÌṩ±¸·Ý¡¢¿àÄѸ´Ô¼°°²È«Êý¾Ý½Ó¼û¹æ»®È·µ±Ïȹ©¸øÉÌ¡£AcronisµÄ½â¾ö¹æ»®Ô̺¬ÎïÀí¡¢Ðé¹¹ºÍÔÆ·þÎñÆ÷±¸·ÝÈí¼þ¡¢´æ´¢ÖÎÀí¡¢°²È«Îļþ·ÖÏíºÍϵͳ²¿Êð¡£Acronis²úÆ·ÓÉ Acronis AnyData Engine Ìṩ¼¼ÊõÖ§³Ö£¬Îª±¾µØ¡¢Ô¶³Ì¡¢ÔƺÍÒÆ¶¯ÖеÄÊý¾ÝÌṩµ¥Ò»¡¢È«Ãæ¡¢°²È«µÄ½â¾ö¹æ»®¡£
2020Äê10Ô£¬Acronis°ä²¼Acronis True Image¡¢Cyber BackupºÍCyber ProtectionÖдæÔÚ¶à¸ö±¾µØÌáȨ·ì϶£¬²¢°ä²¼Á˰²È«¸üС£
0x01 ·ì϶ÏêÇé

Õâ´ÎÉæ¼°µÄ°²È«·ì϶ÈçÏ£º
·ì϶±àºÅ | ·ì϶ÀàÐÍ | Ó°ÏìÁìÓò |
CVE-2020-10138 | ±¾µØÌáȨ | Acronis Cyber Backup 12.5ºÍCyber Protect 15 |
CVE-2020-10139 | ±¾µØÌáȨ | Acronis True Image 2021 |
CVE-2020-10140 | ±¾µØÌáȨ | Acronis True Image 2021 |
Acronis Cyber BackupºÍCyber Protect±¾µØÌáȨ·ì϶£¨CVE-2020-10138£©
¸Ã·ì϶ÊÇÓÉÓÚAcronis Cyber Backup 12.5ºÍCyber Protect 15Ô̺¬Ò»¸öOpenSSL×é¼þ£¬¸Ã×é¼þÖ¸¶¨OPENSSLDIR±äÁ¿×÷ΪC:\jenkins_agent\ÖеÄ×ÓĿ¼¡£
Acronis Cyber BackupºÍCyber Protect¶¼Ê¹ÓÃOpenSSL×é¼þµÄȨÏÞ·þÎñ¡£¹¥»÷ÕßÄܹ»ÔÚϵͳ¸ùĿ¼Ï´´½¨×ÓĿ¼£¬ºÃ±ÈÄܹ»´´½¨openssl.cnfÎļþÒÔʹÓÃSYSTEMȨÏÞʵÏÖËÁÒâ´úÂëÖ´ÐС£
²Î¿¼Á´½Ó£º
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10138
Acronis True Image±¾µØÌáȨ·ì϶£¨CVE-2020-10139£©
¸Ã·ì϶ÊÇÓÉÓÚAcronis True Image 2021Ô̺¬Ò»¸öOpenSSL×é¼þ£¬¸Ã×é¼þ½«OPENSSLDIR±äÁ¿Ö¸¶¨ÎªC:\jenkins_agent\ÖеÄ×ÓĿ¼¡£
²Î¿¼Á´½Ó£º
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10139
Acronis True Image±¾µØÌáȨ·ì϶£¨CVE-2020-10140£©
¸Ã·ì϶ÊÇÓÉÓÚAcronis True Image 2021ÎÞ·¨ÕýÈ·ÉèÖÃC:\ProgramData\AcronisĿ¼µÄACL¡£
ÓÉÓÚijЩ¹ý³ÌÊÇÔÚC:\ProgramData\AcronisĿ¼ÏÂÖ´Ðе쬹¥»÷ÕßÄܹ»Í¨¹ýÔÚC:\ProgramData\AcronisĿ¼µÄõè¾¶ÖиéÖÃÒ»¸öDLLÀ´ÊµÏÖËÁÒâ´úÂëÖ´ÐС£
²Î¿¼Á´½Ó£º
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10140
0x02 ´ëÖý¨Òé
½¨ÒéÉý¼¶ÖÁ×îа汾¡£
Acronis True Image 2021£ºÄÚ²¿°æ±¾32010£º
https://www.acronis.com/en-us/support/updates/changes.html?p=42226
Acronis Cyber Backup 12.5£ºÄÚ²¿°æ±¾16363£º
https://dl.managed-protection.com/u/backup/rn/12.5/user/en-US/AcronisBackup12.5_relnotes.htm
Acronis Cyber Protect 15£ºÄÚ²¿°æ±¾24600£º
https://dl.managed-protection.com/u/cyberprotect/rn/15/user/en-US/AcronisCyberProtect15_relnotes.htm
ÏÂÔØµØÖ·£º
https://www.acronis.com/en-us/support/updates/index.html
0x03 ²Î¿¼Á´½Ó
https://kb.cert.org/vuls/id/114757
https://www.acronis.com/en-us/support/updates/index.html
0x04 ¹¦·òÏß
2020-10-07 Acronis°ä²¼°²È«¸üÐÂ
2020-10-13 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ