¡¾·ì϶¹«¸æ¡¿NAKIVO Backup & Replication ËÁÒâÎļþ¶ÁÈ¡·ì϶(CVE-2024-48248)

°ä²¼¹¦·ò 2025-02-27

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

NAKIVO Backup & Replication δ¾­Éí·ÝÑéÖ¤µÄËÁÒâÎļþ¶ÁÈ¡·ì϶

CVE   ID

CVE-2024-48248

·ì϶ÀàÐÍ

ËÁÒâÎļþ¶ÁÈ¡

·¢ÏÖ¹¦·ò

2025-02-27

·ì϶ÆÀ·Ö

7.5

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


NAKIVO Backup & ReplicationÊÇÒ»¿î¸ßЧµÄÊý¾Ý±£»¤½â¾ö¹æ»®£¬×¨ÎªÐé¹¹»¯¡¢ÔƺÍÎïÀí»·¾³Éè¼Æ¡£ËüÖ§³Ö VMware¡¢Hyper-V¡¢AWS¡¢AzureµÈƽ̨µÄ±¸·Ý¡¢¸´Ô­¡¢¸´ÔìºÍ¹éµµÖ°ÄÜ¡£¸ÃÈí¼þÌṩ¼±¾ç¡¢¿¿µÃסµÄ±¸·ÝÓ븴ԭ£¬Ö§³ÖÔöÁ¿±¸·ÝºÍÈ¥³Á¼¼Êõ£¬ÒÔ½Ú¼ó´æ´¢¿Õ¼ä²¢Ìá¸ß»úÄÜ¡£NAKIVO Backup & Replication»¹Ö§³Ö¿àÄѸ´Ô­¡¢ÔƱ¸·ÝºÍ¿çƽ̨Êý¾ÝǨá㣬ȷ±£ÆóÒµ¹Ø¼üÊý¾ÝµÄ°²È«¡£ÆäÇá±ãµÄ½çÃæºÍ×Ô¶¯»¯Á÷³ÌÔ®ÊÖÓû§Ìá¸ßÖÎÀíЧÄÜ£¬½µµÍÔËά³É±¾¡£


2025Äê2ÔÂ27ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½watchTowr Labs°ä²¼Á˹ØÓÚNAKIVO Backup & Replication²úÆ·µÄδ¾­Éí·ÝÑéÖ¤µÄËÁÒâÎļþ¶ÁÈ¡·ì϶µÄ°²È«·ÖÎöÎÄÕ¡£ÎÄÕ½Òʾ£¬¹¥»÷Õß¿Éͨ¹ý¸Ã·ì϶½Ó¼û·þÎñÆ÷ÉϵÄËÁÒâÎļþ£¬Ô̺¬´æ´¢ÔÚÊý¾Ý¿âÖÐµÄÆ¾Ö¤ºÍ±¸·ÝÎļþ£¨Èç.rawÌåʽµÄ±¸·ÝÎļþºÍproduct01.h2.dbÊý¾Ý¿âÎļþ£©£¬½ø¶øÌáȡδ¼ÓÃÜ´æ´¢µÄÃô¸Ðƾ֤ÐÅÏ¢¡£´Ë±í£¬¹¥»÷Õß»¹ÄÜͨ¹ýµ÷ÊÔJava¹ý³Ì£¬ÌáÈ¡ÄÚ´æÖд洢µÄÇ峺Îı¾Æ¾Ö¤¡£ÕâʹµÃ¹¥»÷Õß¿ÉÄÜ»ñÈ¡ÓëÆäËûϵͳ¼¯³ÉËùÐèµÄSSHÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÊý¾Ý£¬´Ó¶ø½øÒ»²½½ÚÔìÊÜÓ°ÏìµÄ±¸·Ý»·¾³¡£¸Ã·ì϶¿ÉÄܵ¼Ö¹¥»÷ÕßÇÔȡϵͳÖÐËùÓд洢µÄƾ֤£¬Ôì³ÉÑϳÁµÄ°²È«·çÏÕ¡£


¶þ¡¢Ó°ÏìÁìÓò


NAKIVO Backup & Replication <= 10.11.3.86570


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


µ±¼´½«NAKIVO Backup & Replication¸üе½v11.0.0.88174»ò¸ü¸ß°æ±¾£¬ÒÔ½¨¸´¸Ã·ì϶¡£¿ª·¢ÕßÒѾ­Ôڸð汾ÖÐÒýÈëÁËÎļþõè¾¶´¦Öõݲȫ¸Ä½ø£¬Ô¤·ÀÁËĿ¼±éÀú¹¥»÷¡£


ÏÂÔØÁ´½Ó£ºhttps://www.nakivo.com/resources/download/trial-download/download/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/