NAKIVO Backup & Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)À´Ï®£¬×ðÁú¿­Ê±Ìṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2025-02-28

NAKIVO Backup & Replication ÊÇÒ»¿îרעÓÚÐéÄ⻯¡¢Ôƶ˼°»ìÏýÇéÐεı¸·ÝÓëÔÖÄѻָ´µÄ½â¾ö¼Æ»®£¬ÊÊÓÃÓÚ VMware vSphere¡¢Microsoft Hyper-V¡¢Nutanix AHV¡¢Amazon EC2¡¢Windows/Linux ºÍ Microsoft 365 ÇéÐΡ£±¸·Ý·þÎñÆ÷¿ÉÒÔ×°ÖÃÔÚ Windows¡¢Linux ºÍ NAS ²Ù×÷ϵͳÉÏ£¬ÓÈÆäÊʺÏÖÐСÆóÒµÊг¡¡£


2025Äê2Ô£¬×ðÁú¿­Ê±¼à¿Øµ½µ½¹Ù·½ÐÞ¸´NAKIVO Backup & Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)£¬¹¥»÷Õß¿ÉʹÓÃSTPreLoadManagement ÀàÖÐµÄ getImageByPathÒªÁ죬Èƹý·¾¶ÑéÖ¤²¢¶ÁȡĿµÄ·þÎñÆ÷ÉϵÄí§ÒâÎļþ£¨°üÀ¨Ãô¸ÐÉèÖÃÎļþ¡¢Êý¾Ý¿â¡¢±¸·ÝÈÕÖ¾µÈ£©


1.png

¡¾Îó²î¸´ÏÖ½ØÍ¼¡¿

 

 

2.png

3.png

¡¾Ó°Ïì°æ±¾¡¿


NAKIVO Backup & Replication < v11.0.0.88174


¡¾ÐÞ¸´½¨Òé¡¿


Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®£º

ÏÖÔÚ¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁ×îа汾£º

https://www.nakivo.com/resources/download/trial-download/download/


¶þ¡¢×ðÁú¿­Ê±¼Æ»®£º


1¡¢×ðÁú¿­Ê±¼ì²âÀà²úÆ·¼Æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©£¬Éý¼¶µ½×îа汾

ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©£¬Éý¼¶µ½×îа汾

ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©£¬Éý¼¶µ½×îа汾

ÌìÇåWEBÇå¾²Ó¦ÓÃÍø¹Ø£¨WAF£©£¬Éý¼¶µ½×îа汾

ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬Éý¼¶µ½×îа汾


¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦£¬ÊÂÎñ¿âÏÂÔØµØµã£º

ÊÂÎñ¿âÏÂÔØµØµã£ºhttps://venustech.download.venuscloud.cn/


2¡¢×ðÁú¿­Ê±Â©É¨²úÆ·¼Æ»®


£¨1£©¡°×ðÁú¿­Ê±Îó²îɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè

 4.png


£¨2£©×ðÁú¿­Ê±Îó²îɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè

 5.png


3¡¢×ðÁú¿­Ê±×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¼Æ»®


×ðÁú¿­Ê±×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬¶ÔÈë¿â×ʲúNAKIVO Backup & Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¾ÙÐÐÖÎÀí¡£

6.png 


4¡¢×ðÁú¿­Ê±Çå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬¾ÙÐйØÁªÕ½ÂÔÉèÖã¬ÍŽáÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬´Ó¶ø·¢Ã÷¡°NAKIVO Backup & Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£


1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°NAKIVO Backup & Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¡±Îó²îɨÃèʹÃü£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú £»

7.png 


2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä £¿éÖУ¬Ìí¼Ó¡°L2_NAKIVO_Backup_Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¡±£¬Í¨¹ý×ðÁú¿­Ê±¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£º

8.png 


̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_NAKIVO_Backup_Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓà £»


3£©Ìí¼Ó¡°L3_NAKIVO_Backup_Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¡±£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_NAKIVO_Backup_Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¡±£¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£

9.png