¡¾·ì϶¹«¸æ¡¿NAKIVO Backup & Replication ËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)
°ä²¼¹¦·ò 2025-02-27Ò»¡¢¡¢¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | NAKIVO Backup & Replication δ¾Éí·ÝÑéÖ¤µÄËÁÒâÎļþ¶ÁÈ¡·ì϶ | ||
CVE ID | CVE-2024-48248 | ||
·ì϶ÀàÐÍ | ËÁÒâÎļþ¶ÁÈ¡ | ·¢ÏÖ¹¦·ò | 2025-02-27 |
·ì϶ÆÀ·Ö | 7.5 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
NAKIVO Backup & ReplicationÊÇÒ»¿î¸ßЧµÄÊý¾Ý±£»¤½â¾ö¹æ»®£¬£¬×¨ÎªÐé¹¹»¯¡¢¡¢¡¢ÔƺÍÎïÀí»·¾³Éè¼Æ¡£¡£¡£ËüÖ§³Ö VMware¡¢¡¢¡¢Hyper-V¡¢¡¢¡¢AWS¡¢¡¢¡¢AzureµÈƽ̨µÄ±¸·Ý¡¢¡¢¡¢¸´Ô¡¢¡¢¡¢¸´Öƺ͹鵵ְÄÜ¡£¡£¡£¸ÃÈí¼þÌṩ¼±¾ç¡¢¡¢¡¢¿¿µÃסµÄ±¸·ÝÓ븴ԣ¬£¬Ö§³ÖÔöÁ¿±¸·ÝºÍÈ¥ÖØ¼¼Êõ£¬£¬ÒÔ½Ú¼ó´æ´¢¿Õ¼ä²¢Ìá¸ß»úÄÜ¡£¡£¡£NAKIVO Backup & Replication»¹Ö§³Ö¿àÄѸ´Ô¡¢¡¢¡¢ÔƱ¸·ÝºÍ¿çƽ̨Êý¾ÝǨá㣬£¬È·±£ÆóÒµ¹Ø¼üÊý¾ÝµÄ°²È«¡£¡£¡£ÆäÇá±ãµÄ½çÃæºÍ×Ô¶¯»¯Á÷³ÌÔ®ÊÖÓû§Ìá¸ßÖÎÀíЧÄÜ£¬£¬½µµÍÔËά³É±¾¡£¡£¡£
2025Äê2ÔÂ27ÈÕ£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½watchTowr Labs°ä²¼Á˹ØÓÚNAKIVO Backup & Replication²úÆ·µÄδ¾Éí·ÝÑéÖ¤µÄËÁÒâÎļþ¶ÁÈ¡·ì϶µÄ°²È«·ÖÎöÎÄÕ¡£¡£¡£ÎÄÕ½Òʾ£¬£¬¹¥»÷Õß¿Éͨ¹ý¸Ã·ì϶½Ó¼û·þÎñÆ÷ÉϵÄËÁÒâÎļþ£¬£¬Ô̺¬´æ´¢ÔÚÊý¾Ý¿âÖÐµÄÆ¾Ö¤ºÍ±¸·ÝÎļþ£¨Èç.rawÌåʽµÄ±¸·ÝÎļþºÍproduct01.h2.dbÊý¾Ý¿âÎļþ£©£¬£¬½ø¶øÌáȡδ¼ÓÃÜ´æ´¢µÄÃô¸Ðƾ֤ÐÅÏ¢¡£¡£¡£´ËÍ⣬£¬¹¥»÷Õß»¹ÄÜͨ¹ýµ÷ÊÔJava¹ý³Ì£¬£¬ÌáÈ¡ÄÚ´æÖд洢µÄÇ峺Îı¾Æ¾Ö¤¡£¡£¡£ÕâʹµÃ¹¥»÷Õß¿ÉÄÜ»ñÈ¡ÓëÆäËûϵͳ¼¯³ÉËùÐèµÄSSHÃÜÂë¡¢¡¢¡¢AWSÃÜÔ¿µÈÃô¸ÐÊý¾Ý£¬£¬´Ó¶ø½øÒ»²½½ÚÖÆÊÜÓ°ÏìµÄ±¸·Ý»·¾³¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼Ö¹¥»÷ÕßÇÔȡϵͳÖÐËùÓд洢µÄƾ֤£¬£¬Ôì³ÉÑÏÖØµÄ°²È«·çÏÕ¡£¡£¡£
¶þ¡¢¡¢¡¢Ó°ÏìÁìÓò
NAKIVO Backup & Replication <= 10.11.3.86570
Èý¡¢¡¢¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Á¢¼´½«NAKIVO Backup & Replication¸üе½v11.0.0.88174»ò¸ü¸ß°æ±¾£¬£¬ÒÔÐÞ¸´¸Ã·ì϶¡£¡£¡£¿£¿£¿ª·¢ÕßÒѾÔڸð汾ÖÐÒýÈëÁËÎļþõè¾¶´¦Öõݲȫ¸Ä½ø£¬£¬Ô¤·ÀÁËĿ¼±éÀú¹¥»÷¡£¡£¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ