¡¾Îó²îͨ¸æ¡¿NAKIVO Backup & Replication í§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)
Ðû²¼Ê±¼ä 2025-02-27Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | NAKIVO Backup & Replication δ¾Éí·ÝÑéÖ¤µÄí§ÒâÎļþ¶ÁÈ¡Îó²î | ||
CVE ID | CVE-2024-48248 | ||
Îó²îÀàÐÍ | í§ÒâÎļþ¶ÁÈ¡ | ·¢Ã÷ʱ¼ä | 2025-02-27 |
Îó²îÆÀ·Ö | 7.5 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
NAKIVO Backup & ReplicationÊÇÒ»¿î¸ßЧµÄÊý¾Ý±£»£»£»¤½â¾ö¼Æ»®£¬£¬£¬£¬£¬×¨ÎªÐéÄ⻯¡¢ÔƺÍÎïÀíÇéÐÎÉè¼Æ¡£¡£¡£ËüÖ§³Ö VMware¡¢Hyper-V¡¢AWS¡¢AzureµÈƽ̨µÄ±¸·Ý¡¢»Ö¸´¡¢¸´Öƺ͹鵵¹¦Ð§¡£¡£¡£¸ÃÈí¼þÌṩ¿ìËÙ¡¢¿É¿¿µÄ±¸·ÝÓë»Ö¸´£¬£¬£¬£¬£¬Ö§³ÖÔöÁ¿±¸·ÝºÍÈ¥ÖØÊÖÒÕ£¬£¬£¬£¬£¬ÒÔ½ÚÔ¼´æ´¢¿Õ¼ä²¢Ìá¸ßÐÔÄÜ¡£¡£¡£NAKIVO Backup & Replication»¹Ö§³ÖÔÖÄѻָ´¡¢ÔƱ¸·ÝºÍ¿çƽ̨Êý¾ÝǨá㣬£¬£¬£¬£¬È·±£ÆóÒµÒªº¦Êý¾ÝµÄÇå¾²¡£¡£¡£ÆäÇáÓ¯µÄ½çÃæºÍ×Ô¶¯»¯Á÷³Ì×ÊÖúÓû§Ìá¸ßÖÎÀíЧÂÊ£¬£¬£¬£¬£¬½µµÍÔËά±¾Ç®¡£¡£¡£
2025Äê2ÔÂ27ÈÕ£¬£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨¼¯ÍÅVSRC¼à²âµ½watchTowr LabsÐû²¼Á˹ØÓÚNAKIVO Backup & Replication²úÆ·µÄδ¾Éí·ÝÑéÖ¤µÄí§ÒâÎļþ¶ÁÈ¡Îó²îµÄÇå¾²ÆÊÎöÎÄÕ¡£¡£¡£ÎÄÕÂÕ¹ÏÖ£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¸ÃÎó²î»á¼ûЧÀÍÆ÷ÉϵÄí§ÒâÎļþ£¬£¬£¬£¬£¬°üÀ¨´æ´¢ÔÚÊý¾Ý¿âÖÐµÄÆ¾Ö¤ºÍ±¸·ÝÎļþ£¨Èç.rawÃûÌõı¸·ÝÎļþºÍproduct01.h2.dbÊý¾Ý¿âÎļþ£©£¬£¬£¬£¬£¬½ø¶øÌáȡδ¼ÓÃÜ´æ´¢µÄÃô¸Ðƾ֤ÐÅÏ¢¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¹¥»÷Õß»¹ÄÜͨ¹ýµ÷ÊÔJavaÀú³Ì£¬£¬£¬£¬£¬ÌáÈ¡ÄÚ´æÖд洢µÄÇåÎúÎı¾Æ¾Ö¤¡£¡£¡£ÕâʹµÃ¹¥»÷ÕßÄܹ»»ñÈ¡ÓëÆäËûϵͳ¼¯³ÉËùÐèµÄSSHÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬´Ó¶ø½øÒ»²½¿ØÖÆÊÜÓ°ÏìµÄ±¸·ÝÇéÐΡ£¡£¡£¸ÃÎó²î¿ÉÄܵ¼Ö¹¥»÷ÕßÇÔȡϵͳÖÐËùÓд洢µÄƾ֤£¬£¬£¬£¬£¬Ôì³ÉÑÏÖØµÄÇ徲Σº¦¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
NAKIVO Backup & Replication <= 10.11.3.86570
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
Á¬Ã¦½«NAKIVO Backup & Replication¸üе½v11.0.0.88174»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¿£¿£¿£¿£¿ª·¢ÕßÒѾÔڸð汾ÖÐÒýÈëÁËÎļþ·¾¶´¦Öóͷ£µÄÇ徲ˢУ¬£¬£¬£¬£¬×èÖ¹ÁËĿ¼±éÀú¹¥»÷¡£¡£¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ