¡¾Îó²îͨ¸æ¡¿NAKIVO Backup & Replication í§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)

Ðû²¼Ê±¼ä 2025-02-27

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

NAKIVO Backup & Replication δ¾­Éí·ÝÑéÖ¤µÄí§ÒâÎļþ¶ÁÈ¡Îó²î

CVE   ID

CVE-2024-48248

Îó²îÀàÐÍ

í§ÒâÎļþ¶ÁÈ¡

·¢Ã÷ʱ¼ä

2025-02-27

Îó²îÆÀ·Ö

7.5

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


NAKIVO Backup & ReplicationÊÇÒ»¿î¸ßЧµÄÊý¾Ý±£»£» £»£» £»£»¤½â¾ö¼Æ»® £¬£¬£¬ £¬£¬£¬£¬×¨ÎªÐéÄ⻯¡¢ÔƺÍÎïÀíÇéÐÎÉè¼Æ¡£¡£ ¡£¡£ËüÖ§³Ö VMware¡¢Hyper-V¡¢AWS¡¢AzureµÈƽ̨µÄ±¸·Ý¡¢»Ö¸´¡¢¸´Öƺ͹鵵¹¦Ð§¡£¡£ ¡£¡£¸ÃÈí¼þÌṩ¿ìËÙ¡¢¿É¿¿µÄ±¸·ÝÓë»Ö¸´ £¬£¬£¬ £¬£¬£¬£¬Ö§³ÖÔöÁ¿±¸·ÝºÍÈ¥ÖØÊÖÒÕ £¬£¬£¬ £¬£¬£¬£¬ÒÔ½ÚÔ¼´æ´¢¿Õ¼ä²¢Ìá¸ßÐÔÄÜ¡£¡£ ¡£¡£NAKIVO Backup & Replication»¹Ö§³ÖÔÖÄѻָ´¡¢ÔƱ¸·ÝºÍ¿çƽ̨Êý¾ÝǨáã £¬£¬£¬ £¬£¬£¬£¬È·±£ÆóÒµÒªº¦Êý¾ÝµÄÇå¾²¡£¡£ ¡£¡£ÆäÇáÓ¯µÄ½çÃæºÍ×Ô¶¯»¯Á÷³Ì×ÊÖúÓû§Ìá¸ßÖÎÀíЧÂÊ £¬£¬£¬ £¬£¬£¬£¬½µµÍÔËά±¾Ç®¡£¡£ ¡£¡£


2025Äê2ÔÂ27ÈÕ £¬£¬£¬ £¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½watchTowr LabsÐû²¼Á˹ØÓÚNAKIVO Backup & Replication²úÆ·µÄδ¾­Éí·ÝÑéÖ¤µÄí§ÒâÎļþ¶ÁÈ¡Îó²îµÄÇå¾²ÆÊÎöÎÄÕ¡£¡£ ¡£¡£ÎÄÕÂÕ¹ÏÖ £¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¸ÃÎó²î»á¼ûЧÀÍÆ÷ÉϵÄí§ÒâÎļþ £¬£¬£¬ £¬£¬£¬£¬°üÀ¨´æ´¢ÔÚÊý¾Ý¿âÖÐµÄÆ¾Ö¤ºÍ±¸·ÝÎļþ£¨Èç.rawÃûÌõı¸·ÝÎļþºÍproduct01.h2.dbÊý¾Ý¿âÎļþ£© £¬£¬£¬ £¬£¬£¬£¬½ø¶øÌáȡδ¼ÓÃÜ´æ´¢µÄÃô¸Ðƾ֤ÐÅÏ¢¡£¡£ ¡£¡£±ðµÄ £¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß»¹ÄÜͨ¹ýµ÷ÊÔJavaÀú³Ì £¬£¬£¬ £¬£¬£¬£¬ÌáÈ¡ÄÚ´æÖд洢µÄÇåÎúÎı¾Æ¾Ö¤¡£¡£ ¡£¡£ÕâʹµÃ¹¥»÷ÕßÄܹ»»ñÈ¡ÓëÆäËûϵͳ¼¯³ÉËùÐèµÄSSHÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÊý¾Ý £¬£¬£¬ £¬£¬£¬£¬´Ó¶ø½øÒ»²½¿ØÖÆÊÜÓ°ÏìµÄ±¸·ÝÇéÐΡ£¡£ ¡£¡£¸ÃÎó²î¿ÉÄܵ¼Ö¹¥»÷ÕßÇÔȡϵͳÖÐËùÓд洢µÄƾ֤ £¬£¬£¬ £¬£¬£¬£¬Ôì³ÉÑÏÖØµÄÇ徲Σº¦¡£¡£ ¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


NAKIVO Backup & Replication <= 10.11.3.86570


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Á¬Ã¦½«NAKIVO Backup & Replication¸üе½v11.0.0.88174»ò¸ü¸ß°æ±¾ £¬£¬£¬ £¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£ ¡£¡£¿£¿ £¿£¿£¿£¿£¿ª·¢ÕßÒѾ­Ôڸð汾ÖÐÒýÈëÁËÎļþ·¾¶´¦Öóͷ£µÄÇ徲ˢР£¬£¬£¬ £¬£¬£¬£¬×èÖ¹ÁËĿ¼±éÀú¹¥»÷¡£¡£ ¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://www.nakivo.com/resources/download/trial-download/download/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£ ¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬£¬£¬ £¬£¬£¬£¬ïÔ̭ϵͳÎó²î £¬£¬£¬ £¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£ ¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬£¬£¬ £¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ £¬£¬£¬ £¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ £¬£¬£¬ £¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬£¬£¬ £¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£ ¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬£¬£¬ £¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£ ¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬£¬£¬ £¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬£¬£¬ £¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£ ¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£ ¡£¡£


3.4 ²Î¿¼Á´½Ó


https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/