¡¾Â©¶´Í¨¸æ¡¿Ivanti¶à¿î²úÎﻺ³åÇøÒç³ö©¶´(CVE-2025-0282)
Ðû²¼Ê±¼ä 2025-01-14Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Ivanti¶à¿î²úÎﻺ³åÇøÒç³ö©¶´ | ||
CVE ID | CVE-2025-0282 | ||
©¶´ÀàÐÍ | »º³åÇøÒç³ö | ·¢ÏÖʱ¼ä | 2025-01-14 |
©¶´ÆÀ·Ö | 9.0 | ©¶´Æ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ÒÑ·¢ÏÖ |
Ivanti Connect Secure£¨Ç°³Æ Pulse Connect Secure£©ÊÇ Ivanti ÌṩµÄÆóÒµ¼¶ SSL VPN ½â¾ö·½°¸£¬Ö¼ÔÚΪԶ³ÌÓû§ÌṩÄþ¾²µÄÍøÂç·ÃÎÊ¡£Í¨¹ý¼ÓÃÜͨµÀ±£ÕÏÊý¾ÝÄþ¾²£¬Ö§³ÖÉí·ÝÑéÖ¤ºÍ·ÃÎÊ¿ØÖÆ£¬ÊÊÓÃÓÚÔ¶³Ì°ì¹«¡¢ºÏ×÷»ï°é·ÃÎʺͷÖÖ§»ú¹¹Á¬½ÓµÈ¸ßÄþ¾²ÐÔ³¡¾°¡£
2025Äê1ÔÂ14ÈÕ£¬¶«Éƽ̨¼¯ÍÅVSRC¼à²âµ½Ivanti¹Ù·½Ðû²¼Á˸üУ¬ÐÞ¸´ÁËIvanti Connect Secure¡¢Policy SecureºÍZTA GatewaysÖеÄÁ½¸ö»º³åÇøÒç³ö©¶´£ºCVE-2025-0282ºÍCVE-2025-0283¡£ÆäÖУ¬CVE-2025-0282©¶´±»ÆÀ¶¨ÎªÑÏÖØ£¬CVSSÆÀ·ÖΪ9.0·Ö£»CVE-2025-0283©¶´Ôò±»ÆÀ¶¨Îª¸ßΣ£¬CVSSÆÀ·ÖΪ7.0·Ö¡£
CVE-2025-0282£ºÔ¶³Ìδ¾ÈÏÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý´Ë©¶´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐУ¬CVE-2025-0283£ºµ±µØÒÑÈÏÖ¤¹¥»÷Õß¿ÉÀûÓôË©¶´ÌáÉýȨÏÞ¡£
¶þ¡¢Ó°Ï췶Χ
22.7R2 <= Ivanti Neurons for ZTA <= 22.7R2.3
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 ÁÙʱ´ëÊ©
3.3 ͨÓý¨Òé
? ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
? ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
? ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£