¡¾Îó²îͨ¸æ¡¿NAKIVO Backup & Replication í§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)
Ðû²¼Ê±¼ä 2025-02-27Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | NAKIVO Backup & Replication δ¾Éí·ÝÑéÖ¤µÄí§ÒâÎļþ¶ÁÈ¡Îó²î | ||
CVE ID | CVE-2024-48248 | ||
Îó²îÀàÐÍ | í§ÒâÎļþ¶ÁÈ¡ | ·¢Ã÷ʱ¼ä | 2025-02-27 |
Îó²îÆÀ·Ö | 7.5 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
NAKIVO Backup & ReplicationÊÇÒ»¿î¸ßЧµÄÊý¾Ý±£»£»£»£»£»¤½â¾ö¼Æ»®£¬£¬£¬×¨ÎªÐéÄ⻯¡¢ÔƺÍÎïÀíÇéÐÎÉè¼Æ¡£¡£¡£¡£¡£¡£ËüÖ§³Ö VMware¡¢Hyper-V¡¢AWS¡¢AzureµÈƽ̨µÄ±¸·Ý¡¢»Ö¸´¡¢¸´Öƺ͹鵵¹¦Ð§¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÌṩ¿ìËÙ¡¢¿É¿¿µÄ±¸·ÝÓë»Ö¸´£¬£¬£¬Ö§³ÖÔöÁ¿±¸·ÝºÍÈ¥ÖØÊÖÒÕ£¬£¬£¬ÒÔ½ÚÔ¼´æ´¢¿Õ¼ä²¢Ìá¸ßÐÔÄÜ¡£¡£¡£¡£¡£¡£NAKIVO Backup & Replication»¹Ö§³ÖÔÖÄѻָ´¡¢ÔƱ¸·ÝºÍ¿çƽ̨Êý¾ÝǨá㣬£¬£¬È·±£ÆóÒµÒªº¦Êý¾ÝµÄÇå¾²¡£¡£¡£¡£¡£¡£ÆäÇáÓ¯µÄ½çÃæºÍ×Ô¶¯»¯Á÷³Ì×ÊÖúÓû§Ìá¸ßÖÎÀíЧÂÊ£¬£¬£¬½µµÍÔËά±¾Ç®¡£¡£¡£¡£¡£¡£
2025Äê2ÔÂ27ÈÕ£¬£¬£¬Z6×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½watchTowr LabsÐû²¼Á˹ØÓÚNAKIVO Backup & Replication²úÆ·µÄδ¾Éí·ÝÑéÖ¤µÄí§ÒâÎļþ¶ÁÈ¡Îó²îµÄÇå¾²ÆÊÎöÎÄÕ¡£¡£¡£¡£¡£¡£ÎÄÕÂÕ¹ÏÖ£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¸ÃÎó²î»á¼ûЧÀÍÆ÷ÉϵÄí§ÒâÎļþ£¬£¬£¬°üÀ¨´æ´¢ÔÚÊý¾Ý¿âÖÐµÄÆ¾Ö¤ºÍ±¸·ÝÎļþ£¨Èç.rawÃûÌõı¸·ÝÎļþºÍproduct01.h2.dbÊý¾Ý¿âÎļþ£©£¬£¬£¬½ø¶øÌáȡδ¼ÓÃÜ´æ´¢µÄÃô¸Ðƾ֤ÐÅÏ¢¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬¹¥»÷Õß»¹ÄÜͨ¹ýµ÷ÊÔJavaÀú³Ì£¬£¬£¬ÌáÈ¡ÄÚ´æÖд洢µÄÇåÎúÎı¾Æ¾Ö¤¡£¡£¡£¡£¡£¡£ÕâʹµÃ¹¥»÷ÕßÄܹ»»ñÈ¡ÓëÆäËûϵͳ¼¯³ÉËùÐèµÄSSHÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÊý¾Ý£¬£¬£¬´Ó¶ø½øÒ»²½¿ØÖÆÊÜÓ°ÏìµÄ±¸·ÝÇéÐΡ£¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼Ö¹¥»÷ÕßÇÔȡϵͳÖÐËùÓд洢µÄƾ֤£¬£¬£¬Ôì³ÉÑÏÖØµÄÇ徲Σº¦¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
NAKIVO Backup & Replication <= 10.11.3.86570
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
Á¬Ã¦½«NAKIVO Backup & Replication¸üе½v11.0.0.88174»ò¸ü¸ß°æ±¾£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ª·¢ÕßÒѾÔڸð汾ÖÐÒýÈëÁËÎļþ·¾¶´¦Öóͷ£µÄÇ徲ˢУ¬£¬£¬×èÖ¹ÁËĿ¼±éÀú¹¥»÷¡£¡£¡£¡£¡£¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ