¡¾Îó²îͨ¸æ¡¿Ivanti CSAÖÎÀí¿ØÖÆÌ¨ÏÂÁî×¢ÈëÎó²î(CVE-2024-47908)

Ðû²¼Ê±¼ä 2025-02-13

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Ivanti CSAÖÎÀí¿ØÖÆÌ¨ÏÂÁî×¢ÈëÎó²î

CVE   ID

CVE-2024-47908

Îó²îÀàÐÍ

ÏÂÁî×¢Èë

·¢Ã÷ʱ¼ä

2025-02-13

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Ivanti CSA£¨Cloud Security Automation£©ÊÇÒ»¿îÔÆÇå¾²×Ô¶¯»¯½â¾ö¼Æ»®£¬ £¬£¬£¬£¬£¬£¬Ö¼ÔÚ×ÊÖúÆóҵʵÏÖ¶ÔÔÆ»ù´¡ÉèÊ©µÄÇå¾²¼à¿ØºÍ×Ô¶¯»¯ÖÎÀí¡£¡£¡£¡£¡£ËüÌṩÎó²îÖÎÀí¡¢ºÏ¹æÐÔ¼ì²éºÍΣº¦ÆÀ¹ÀµÈ¹¦Ð§£¬ £¬£¬£¬£¬£¬£¬×ÊÖú×é֯ʶ±ðºÍÐÞ¸´ÔÆÇéÐÎÖеÄÇå¾²ÎÊÌ⣬ £¬£¬£¬£¬£¬£¬´Ó¶øÌáÉýÔÆÇå¾²ÐÔ£¬ £¬£¬£¬£¬£¬£¬È·±£ÆóÒµÇкÏÐÐÒµ±ê×¼ºÍ¹æÔòÒªÇ󡣡£¡£¡£¡£


2025Äê2ÔÂ13ÈÕ£¬ £¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½IvantiÐû²¼Á˹ØÓÚIvanti CSAµÄÁ½¸öÇ徲ͨ¸æ£¬ £¬£¬£¬£¬£¬£¬»®·ÖÉæ¼°ÏÂÁî×¢ÈëÎó²î£¨CVE-2024-47908£©ºÍ·¾¶±éÀúÎó²î£¨CVE-2024-11771£©¡£¡£¡£¡£¡£Í¨¸æÖÐÖ¸³ö£¬ £¬£¬£¬£¬£¬£¬Ivanti CSA 5.0.5֮ǰ°æ±¾µÄÖÎÀíÔ±¿ØÖÆÌ¨±£´æOSÏÂÁî×¢ÈëÎó²î£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ»ñµÃÖÎÀíԱȨÏÞºó£¬ £¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐжñÒâ´úÂ룬 £¬£¬£¬£¬£¬£¬CVE±àºÅΪCVE-2024-47908£¬ £¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.1£¬ £¬£¬£¬£¬£¬£¬Îó²îÆ·¼¶ÎªÑÏÖØ¡£¡£¡£¡£¡£Í¬Ê±£¬ £¬£¬£¬£¬£¬£¬5.0.5֮ǰµÄ°æ±¾»¹±£´æÂ·¾¶±éÀúÎó²î£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»á¼ûÊÜÏÞ¹¦Ð§£¬ £¬£¬£¬£¬£¬£¬CVE±àºÅΪCVE-2024-11771£¬ £¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö5.3£¬ £¬£¬£¬£¬£¬£¬Îó²îÆ·¼¶ÎªÖÐΣ¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Ivanti CSA < 5.0.5


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Éý¼¶ÖÁIvanti CSA 5.0.5°æ±¾


ÏÂÔØÁ´½Ó£º
https://forums.ivanti.com/s/article/CSA-5-0-Download


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ £¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬ £¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬ £¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬ £¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬ £¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ £¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ £¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ £¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬ £¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-47908-CVE-2024-11771?language=en_US

https://nvd.nist.gov/vuln/detail/CVE-2024-47908
https://nvd.nist.gov/vuln/detail/CVE-2024-11771