¡¾·ì϶¹«¸æ¡¿NAKIVO Backup & Replication ËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)
°ä²¼¹¦·ò 2025-02-27Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | NAKIVO Backup & Replication δ¾Éí·ÝÑéÖ¤µÄËÁÒâÎļþ¶ÁÈ¡·ì϶ | ||
CVE ID | CVE-2024-48248 | ||
·ì϶ÀàÐÍ | ËÁÒâÎļþ¶ÁÈ¡ | ·¢ÏÖ¹¦·ò | 2025-02-27 |
·ì϶ÆÀ·Ö | 7.5 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
NAKIVO Backup & ReplicationÊÇÒ»¿î¸ßЧµÄÊý¾Ý±£»¤½â¾ö¹æ»®£¬×¨ÎªÐé¹¹»¯¡¢ÔƺÍÎïÀí»·¾³Éè¼Æ¡£ËüÖ§³Ö VMware¡¢Hyper-V¡¢AWS¡¢AzureµÈƽ̨µÄ±¸·Ý¡¢¸´Ô¡¢¸´ÔìºÍ¹éµµÖ°ÄÜ¡£¸ÃÈí¼þÌṩ¼±¾ç¡¢¿¿µÃסµÄ±¸·ÝÓ븴ԣ¬Ö§³ÖÔöÁ¿±¸·ÝºÍÈ¥³Á¼¼Êõ£¬ÒÔ½Ú¼ó´æ´¢¿Õ¼ä²¢Ìá¸ß»úÄÜ¡£NAKIVO Backup & Replication»¹Ö§³Ö¿àÄѸ´Ô¡¢ÔƱ¸·ÝºÍ¿çƽ̨Êý¾ÝǨá㣬ȷ±£ÆóÒµ¹Ø¼üÊý¾ÝµÄ°²È«¡£ÆäÇá±ãµÄ½çÃæºÍ×Ô¶¯»¯Á÷³ÌÔ®ÊÖÓû§Ìá¸ßÖÎÀíЧÄÜ£¬½µµÍÔËά³É±¾¡£
2025Äê2ÔÂ27ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½watchTowr Labs°ä²¼Á˹ØÓÚNAKIVO Backup & Replication²úÆ·µÄδ¾Éí·ÝÑéÖ¤µÄËÁÒâÎļþ¶ÁÈ¡·ì϶µÄ°²È«·ÖÎöÎÄÕ¡£ÎÄÕ½Òʾ£¬¹¥»÷Õß¿Éͨ¹ý¸Ã·ì϶½Ó¼û·þÎñÆ÷ÉϵÄËÁÒâÎļþ£¬Ô̺¬´æ´¢ÔÚÊý¾Ý¿âÖÐµÄÆ¾Ö¤ºÍ±¸·ÝÎļþ£¨Èç.rawÌåʽµÄ±¸·ÝÎļþºÍproduct01.h2.dbÊý¾Ý¿âÎļþ£©£¬½ø¶øÌáȡδ¼ÓÃÜ´æ´¢µÄÃô¸Ðƾ֤ÐÅÏ¢¡£´Ë±í£¬¹¥»÷Õß»¹ÄÜͨ¹ýµ÷ÊÔJava¹ý³Ì£¬ÌáÈ¡ÄÚ´æÖд洢µÄÇ峺Îı¾Æ¾Ö¤¡£ÕâʹµÃ¹¥»÷Õß¿ÉÄÜ»ñÈ¡ÓëÆäËûϵͳ¼¯³ÉËùÐèµÄSSHÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÊý¾Ý£¬´Ó¶ø½øÒ»²½½ÚÔìÊÜÓ°ÏìµÄ±¸·Ý»·¾³¡£¸Ã·ì϶¿ÉÄܵ¼Ö¹¥»÷ÕßÇÔȡϵͳÖÐËùÓд洢µÄƾ֤£¬Ôì³ÉÑϳÁµÄ°²È«·çÏÕ¡£
¶þ¡¢Ó°ÏìÁìÓò
NAKIVO Backup & Replication <= 10.11.3.86570
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
µ±¼´½«NAKIVO Backup & Replication¸üе½v11.0.0.88174»ò¸ü¸ß°æ±¾£¬ÒÔ½¨¸´¸Ã·ì϶¡£¿ª·¢ÕßÒѾÔڸð汾ÖÐÒýÈëÁËÎļþõè¾¶´¦Öõݲȫ¸Ä½ø£¬Ô¤·ÀÁËĿ¼±éÀú¹¥»÷¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ