¡¾Â©¶´Í¨¸æ¡¿Ivanti CSA¹ÜÀí¿ØÖÆÌ¨ÃüÁî×¢Èë©¶´(CVE-2024-47908)

Ðû²¼Ê±¼ä 2025-02-13

Ò»¡¢Â©¶´¸ÅÊö


©¶´Ãû³Æ

Ivanti CSA¹ÜÀí¿ØÖÆÌ¨ÃüÁî×¢Èë©¶´

CVE   ID

CVE-2024-47908

©¶´ÀàÐÍ

ÃüÁî×¢Èë

·¢ÏÖʱ¼ä

2025-02-13

©¶´ÆÀ·Ö

9.1

©¶´Æ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


Ivanti CSA£¨Cloud Security Automation£©ÊÇÒ»¿îÔÆÄþ¾²×Ô¶¯»¯½â¾ö·½°¸£¬Ö¼ÔÚ×ÊÖúÆóҵʵÏÖ¶ÔÔÆ»ù´¡ÉèÊ©µÄÄþ¾²¼à¿ØºÍ×Ô¶¯»¯¹ÜÀí¡£ËüÌṩ©¶´¹ÜÀí¡¢ºÏ¹æÐÔ¼ì²éºÍ·çÏÕÆÀ¹ÀµÈ¹¦Ð§£¬×ÊÖú×é֯ʶ±ðºÍÐÞ¸´ÔÆ»·¾³ÖеÄÄþ¾²ÎÊÌ⣬´Ó¶øÌáÉýÔÆÄþ¾²ÐÔ£¬È·±£ÆóÒµÇкÏÐÐÒµ³ß¶ÈºÍ¹æÔòÒªÇó¡£


2025Äê2ÔÂ13ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½IvantiÐû²¼Á˹ØÓÚIvanti CSAµÄÁ½¸öÄþ¾²Í¨¸æ£¬·Ö±ðÉæ¼°ÃüÁî×¢Èë©¶´£¨CVE-2024-47908£©ºÍ·¾¶±éÀú©¶´£¨CVE-2024-11771£©¡£Í¨¸æÖÐÖ¸³ö£¬Ivanti CSA 5.0.5֮ǰ°æ±¾µÄ¹ÜÀíÔ±¿ØÖÆÌ¨´æÔÚOSÃüÁî×¢Èë©¶´£¬¹¥»÷ÕßÔÚ»ñµÃ¹ÜÀíԱȨÏ޺󣬿ÉÔ¶³ÌÖ´ÐжñÒâ´úÂ룬CVE±àºÅΪCVE-2024-47908£¬CVSSÆÀ·Ö9.1£¬Â©¶´Æ·¼¶ÎªÑÏÖØ¡£Í¬Ê±£¬5.0.5֮ǰµÄ°æ±¾»¹´æÔÚ·¾¶±éÀú©¶´£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß·ÃÎÊÊÜÏÞ¹¦Ð§£¬CVE±àºÅΪCVE-2024-11771£¬CVSSÆÀ·Ö5.3£¬Â©¶´Æ·¼¶ÎªÖÐΣ¡£


¶þ¡¢Ó°Ï췶Χ


Ivanti CSA < 5.0.5


Èý¡¢Äþ¾²´ëÊ©


3.1 Éý¼¶°æ±¾


Éý¼¶ÖÁIvanti CSA 5.0.5°æ±¾


ÏÂÔØÁ´½Ó£º
https://forums.ivanti.com/s/article/CSA-5-0-Download


3.2 ÁÙʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-47908-CVE-2024-11771?language=en_US

https://nvd.nist.gov/vuln/detail/CVE-2024-47908
https://nvd.nist.gov/vuln/detail/CVE-2024-11771