¡¾Îó²îͨ¸æ¡¿NAKIVO Backup & Replication í§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)

Ðû²¼Ê±¼ä 2025-02-27

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

NAKIVO Backup & Replication δ¾­Éí·ÝÑéÖ¤µÄí§ÒâÎļþ¶ÁÈ¡Îó²î

CVE   ID

CVE-2024-48248

Îó²îÀàÐÍ

í§ÒâÎļþ¶ÁÈ¡

·¢Ã÷ʱ¼ä

2025-02-27

Îó²îÆÀ·Ö

7.5

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


NAKIVO Backup & ReplicationÊÇÒ»¿î¸ßЧµÄÊý¾Ý±£»£»£» £»£»£»¤½â¾ö¼Æ»®£¬£¬£¬ £¬£¬×¨ÎªÐéÄ⻯¡¢ÔƺÍÎïÀíÇéÐÎÉè¼Æ¡£¡£¡£¡£¡£¡£ËüÖ§³Ö VMware¡¢Hyper-V¡¢AWS¡¢AzureµÈƽ̨µÄ±¸·Ý¡¢»Ö¸´¡¢¸´Öƺ͹鵵¹¦Ð§¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÌṩ¿ìËÙ¡¢¿É¿¿µÄ±¸·ÝÓë»Ö¸´£¬£¬£¬ £¬£¬Ö§³ÖÔöÁ¿±¸·ÝºÍÈ¥ÖØÊÖÒÕ£¬£¬£¬ £¬£¬ÒÔ½ÚÔ¼´æ´¢¿Õ¼ä²¢Ìá¸ßÐÔÄÜ¡£¡£¡£¡£¡£¡£NAKIVO Backup & Replication»¹Ö§³ÖÔÖÄѻָ´¡¢ÔƱ¸·ÝºÍ¿çƽ̨Êý¾ÝǨá㣬£¬£¬ £¬£¬È·±£ÆóÒµÒªº¦Êý¾ÝµÄÇå¾²¡£¡£¡£¡£¡£¡£ÆäÇáÓ¯µÄ½çÃæºÍ×Ô¶¯»¯Á÷³Ì×ÊÖúÓû§Ìá¸ßÖÎÀíЧÂÊ£¬£¬£¬ £¬£¬½µµÍÔËά±¾Ç®¡£¡£¡£¡£¡£¡£


2025Äê2ÔÂ27ÈÕ£¬£¬£¬ £¬£¬ÍòÀû¹ú¼Ê¹ÙÍø¼¯ÍÅVSRC¼à²âµ½watchTowr LabsÐû²¼Á˹ØÓÚNAKIVO Backup & Replication²úÆ·µÄδ¾­Éí·ÝÑéÖ¤µÄí§ÒâÎļþ¶ÁÈ¡Îó²îµÄÇå¾²ÆÊÎöÎÄÕ¡£¡£¡£¡£¡£¡£ÎÄÕÂÕ¹ÏÖ£¬£¬£¬ £¬£¬¹¥»÷Õß¿Éͨ¹ý¸ÃÎó²î»á¼ûЧÀÍÆ÷ÉϵÄí§ÒâÎļþ£¬£¬£¬ £¬£¬°üÀ¨´æ´¢ÔÚÊý¾Ý¿âÖÐµÄÆ¾Ö¤ºÍ±¸·ÝÎļþ£¨Èç.rawÃûÌõı¸·ÝÎļþºÍproduct01.h2.dbÊý¾Ý¿âÎļþ£©£¬£¬£¬ £¬£¬½ø¶øÌáȡδ¼ÓÃÜ´æ´¢µÄÃô¸Ðƾ֤ÐÅÏ¢¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬¹¥»÷Õß»¹ÄÜͨ¹ýµ÷ÊÔJavaÀú³Ì£¬£¬£¬ £¬£¬ÌáÈ¡ÄÚ´æÖд洢µÄÇåÎúÎı¾Æ¾Ö¤¡£¡£¡£¡£¡£¡£ÕâʹµÃ¹¥»÷ÕßÄܹ»»ñÈ¡ÓëÆäËûϵͳ¼¯³ÉËùÐèµÄSSHÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÊý¾Ý£¬£¬£¬ £¬£¬´Ó¶ø½øÒ»²½¿ØÖÆÊÜÓ°ÏìµÄ±¸·ÝÇéÐΡ£¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼Ö¹¥»÷ÕßÇÔȡϵͳÖÐËùÓд洢µÄƾ֤£¬£¬£¬ £¬£¬Ôì³ÉÑÏÖØµÄÇ徲Σº¦¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


NAKIVO Backup & Replication <= 10.11.3.86570


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Á¬Ã¦½«NAKIVO Backup & Replication¸üе½v11.0.0.88174»ò¸ü¸ß°æ±¾£¬£¬£¬ £¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡ £¿£¿£¿ £¿£¿£¿£¿£¿ª·¢ÕßÒѾ­Ôڸð汾ÖÐÒýÈëÁËÎļþ·¾¶´¦Öóͷ£µÄÇ徲ˢУ¬£¬£¬ £¬£¬×èÖ¹ÁËĿ¼±éÀú¹¥»÷¡£¡£¡£¡£¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://www.nakivo.com/resources/download/trial-download/download/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ £¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬ £¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬ £¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬ £¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ £¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ £¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ £¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ £¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬ £¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/