¡¾Îó²îͨ¸æ¡¿Ivanti¶à¿î²úÆ·»º³åÇøÒç³öÎó²î(CVE-2025-0282)
Ðû²¼Ê±¼ä 2025-01-14Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Ivanti¶à¿î²úÆ·»º³åÇøÒç³öÎó²î | ||
CVE ID | CVE-2025-0282 | ||
Îó²îÀàÐÍ | »º³åÇøÒç³ö | ·¢Ã÷ʱ¼ä | 2025-01-14 |
Îó²îÆÀ·Ö | 9.0 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ÒÑ·¢Ã÷ |
Ivanti Connect Secure£¨Ç°³Æ Pulse Connect Secure£©ÊÇ Ivanti ÌṩµÄÆóÒµ¼¶ SSL VPN ½â¾ö¼Æ»®£¬£¬£¬£¬Ö¼ÔÚΪԶ³ÌÓû§ÌṩÇå¾²µÄÍøÂç»á¼û¡£¡£¡£¡£Í¨¹ý¼ÓÃÜͨµÀ°ü¹ÜÊý¾ÝÇå¾²£¬£¬£¬£¬Ö§³ÖÉí·ÝÑéÖ¤ºÍ»á¼û¿ØÖÆ£¬£¬£¬£¬ÊÊÓÃÓÚÔ¶³Ì°ì¹«¡¢ÏàÖúͬ°é»á¼ûºÍ·ÖÖ§»ú¹¹ÅþÁ¬µÈ¸ßÇå¾²ÐÔ³¡¾°¡£¡£¡£¡£
2025Äê1ÔÂ14ÈÕ£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Ivanti¹Ù·½Ðû²¼Á˸üУ¬£¬£¬£¬ÐÞ¸´ÁËIvanti Connect Secure¡¢Policy SecureºÍZTA GatewaysÖеÄÁ½¸ö»º³åÇøÒç³öÎó²î£ºCVE-2025-0282ºÍCVE-2025-0283¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬CVE-2025-0282Îó²î±»ÆÀ¶¨ÎªÑÏÖØ£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.0·Ö£»£»£»£»£»£»CVE-2025-0283Îó²îÔò±»ÆÀ¶¨Îª¸ßΣ£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.0·Ö¡£¡£¡£¡£
CVE-2025-0282£ºÔ¶³Ìδ¾ÈÏÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý´ËÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬CVE-2025-0283£ºÍâµØÒÑÈÏÖ¤¹¥»÷Õß¿ÉʹÓôËÎó²îÌáÉýȨÏÞ¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
22.7R2 <= Ivanti Neurons for ZTA <= 22.7R2.3
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 ÔÝʱ²½·¥
3.3 ͨÓý¨Òé
? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£
? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£
? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£