¡¾Â©¶´Í¨¸æ¡¿NAKIVO Backup & Replication ÈÎÒâÎļþ¶Áȡ©¶´(CVE-2024-48248)

Ðû²¼Ê±¼ä 2025-02-27

Ò»¡¢Â©¶´¸ÅÊö


©¶´Ãû³Æ

NAKIVO Backup & Replication δ¾­Éí·ÝÑéÖ¤µÄÈÎÒâÎļþ¶Áȡ©¶´

CVE   ID

CVE-2024-48248

©¶´ÀàÐÍ

ÈÎÒâÎļþ¶ÁÈ¡

·¢ÏÖʱ¼ä

2025-02-27

©¶´ÆÀ·Ö

7.5

©¶´Æ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


NAKIVO Backup & ReplicationÊÇÒ»¿î¸ßЧµÄÊý¾Ý±£»¤½â¾ö·½°¸£¬×¨ÎªÐéÄ⻯¡¢ÔƺÍÎïÀí»·¾³Éè¼Æ¡£ËüÖ§³Ö VMware¡¢Hyper-V¡¢AWS¡¢AzureµÈƽ̨µÄ±¸·Ý¡¢»Ö¸´¡¢¸´Öƺ͹鵵¹¦Ð§¡£¸ÃÈí¼þÌṩ¿ìËÙ¡¢¿É¿¿µÄ±¸·ÝÓë»Ö¸´£¬Ö§³ÖÔöÁ¿±¸·ÝºÍÈ¥ÖØ¼¼Êõ£¬ÒÔ½ÚÊ¡´æ´¢¿Õ¼ä²¢Ìá¸ßÐÔÄÜ¡£NAKIVO Backup & Replication»¹Ö§³ÖÔÖÄѻָ´¡¢ÔƱ¸·ÝºÍ¿çƽ̨Êý¾ÝÇ¨ÒÆ£¬È·±£ÆóÒµÒªº¦Êý¾ÝµÄÄþ¾²¡£Æä¼ò±ãµÄ½çÃæºÍ×Ô¶¯»¯Á÷³Ì×ÊÖúÓû§Ìá¸ß¹ÜÀíЧÂÊ£¬½µµÍÔËά³É±¾¡£


2025Äê2ÔÂ27ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½watchTowr LabsÐû²¼Á˹ØÓÚNAKIVO Backup & Replication²úÎïµÄδ¾­Éí·ÝÑéÖ¤µÄÈÎÒâÎļþ¶Áȡ©¶´µÄÄþ¾²·ÖÎöÎÄÕ¡£ÎÄÕ½Òʾ£¬¹¥»÷Õß¿Éͨ¹ý¸Ã©¶´·ÃÎÊ·þÎñÆ÷ÉϵÄÈÎÒâÎļþ£¬°üÂÞ´æ´¢ÔÚÊý¾Ý¿âÖÐµÄÆ¾Ö¤ºÍ±¸·ÝÎļþ£¨Èç.raw¸ñʽµÄ±¸·ÝÎļþºÍproduct01.h2.dbÊý¾Ý¿âÎļþ£©£¬½ø¶øÌáȡδ¼ÓÃÜ´æ´¢µÄÃô¸Ðƾ֤ÐÅÏ¢¡£´ËÍ⣬¹¥»÷Õß»¹ÄÜͨ¹ýµ÷ÊÔJava½ø³Ì£¬ÌáÈ¡ÄÚ´æÖд洢µÄÇåÎúÎı¾Æ¾Ö¤¡£ÕâʹµÃ¹¥»÷ÕßÄܹ»»ñÈ¡ÓëÆäËûϵͳ¼¯³ÉËùÐèµÄSSHÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÊý¾Ý£¬´Ó¶ø½øÒ»²½¿ØÖÆÊÜÓ°ÏìµÄ±¸·Ý»·¾³¡£¸Ã©¶´¿ÉÄܵ¼Ö¹¥»÷ÕßÇÔȡϵͳÖÐËùÓд洢µÄƾ֤£¬Ôì³ÉÑÏÖØµÄÄþ¾²·çÏÕ¡£


¶þ¡¢Ó°Ï췶Χ


NAKIVO Backup & Replication <= 10.11.3.86570


Èý¡¢Äþ¾²´ëÊ©


3.1 Éý¼¶°æ±¾


Á¢¼´½«NAKIVO Backup & Replication¸üе½v11.0.0.88174»ò¸ü¸ß°æ±¾£¬ÒÔÐÞ¸´¸Ã©¶´¡£¿ª·¢ÕßÒѾ­Ôڸð汾ÖÐÒýÈëÁËÎļþ·¾¶´¦ÖõÄÄþ¾²¸ïУ¬ÖÆÖ¹ÁËĿ¼±éÀú¹¥»÷¡£


ÏÂÔØÁ´½Ó£ºhttps://www.nakivo.com/resources/download/trial-download/download/


3.2 ÁÙʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/