¡¾Îó²îͨ¸æ¡¿Ivanti CSAÖÎÀí¿ØÖÆÌ¨ÏÂÁî×¢ÈëÎó²î(CVE-2024-47908)

Ðû²¼Ê±¼ä 2025-02-13

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Ivanti CSAÖÎÀí¿ØÖÆÌ¨ÏÂÁî×¢ÈëÎó²î

CVE   ID

CVE-2024-47908

Îó²îÀàÐÍ

ÏÂÁî×¢Èë

·¢Ã÷ʱ¼ä

2025-02-13

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Ivanti CSA£¨Cloud Security Automation£©ÊÇÒ»¿îÔÆÇå¾²×Ô¶¯»¯½â¾ö¼Æ»®£¬Ö¼ÔÚ×ÊÖúÆóҵʵÏÖ¶ÔÔÆ»ù´¡ÉèÊ©µÄÇå¾²¼à¿ØºÍ×Ô¶¯»¯ÖÎÀí¡£ËüÌṩÎó²îÖÎÀí¡¢ºÏ¹æÐÔ¼ì²éºÍΣº¦ÆÀ¹ÀµÈ¹¦Ð§£¬×ÊÖú×é֯ʶ±ðºÍÐÞ¸´ÔÆÇéÐÎÖеÄÇå¾²ÎÊÌ⣬´Ó¶øÌáÉýÔÆÇå¾²ÐÔ£¬È·±£ÆóÒµÇкÏÐÐÒµ±ê×¼ºÍ¹æÔòÒªÇó¡£


2025Äê2ÔÂ13ÈÕ£¬×ðÁú¿­Ê±¼¯ÍÅVSRC¼à²âµ½IvantiÐû²¼Á˹ØÓÚIvanti CSAµÄÁ½¸öÇ徲ͨ¸æ£¬»®·ÖÉæ¼°ÏÂÁî×¢ÈëÎó²î£¨CVE-2024-47908£©ºÍ·¾¶±éÀúÎó²î£¨CVE-2024-11771£©¡£Í¨¸æÖÐÖ¸³ö£¬Ivanti CSA 5.0.5֮ǰ°æ±¾µÄÖÎÀíÔ±¿ØÖÆÌ¨±£´æOSÏÂÁî×¢ÈëÎó²î£¬¹¥»÷ÕßÔÚ»ñµÃÖÎÀíԱȨÏ޺󣬿ÉÔ¶³ÌÖ´ÐжñÒâ´úÂ룬CVE±àºÅΪCVE-2024-47908£¬CVSSÆÀ·Ö9.1£¬Îó²îÆ·¼¶ÎªÑÏÖØ¡£Í¬Ê±£¬5.0.5֮ǰµÄ°æ±¾»¹±£´æÂ·¾¶±éÀúÎó²î£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»á¼ûÊÜÏÞ¹¦Ð§£¬CVE±àºÅΪCVE-2024-11771£¬CVSSÆÀ·Ö5.3£¬Îó²îÆ·¼¶ÎªÖÐΣ¡£


¶þ¡¢Ó°Ïì¹æÄ£


Ivanti CSA < 5.0.5


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Éý¼¶ÖÁIvanti CSA 5.0.5°æ±¾


ÏÂÔØÁ´½Ó£º
https://forums.ivanti.com/s/article/CSA-5-0-Download


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-47908-CVE-2024-11771?language=en_US

https://nvd.nist.gov/vuln/detail/CVE-2024-47908
https://nvd.nist.gov/vuln/detail/CVE-2024-11771