Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Ivanti CSA¹ÜÀí¿ØÖÆÌ¨ÃüÁî×¢Èë©¶´ |
CVE ID | CVE-2024-47908 |
©¶´ÀàÐÍ | ÃüÁî×¢Èë | ·¢ÏÖʱ¼ä | 2025-02-13 |
©¶´ÆÀ·Ö | 9.1 | ©¶´Æ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ¸ß |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Ivanti CSA£¨Cloud Security Automation£©ÊÇÒ»¿îÔÆÄþ¾²×Ô¶¯»¯½â¾ö·½°¸£¬Ö¼ÔÚ×ÊÖúÆóҵʵÏÖ¶ÔÔÆ»ù´¡ÉèÊ©µÄÄþ¾²¼à¿ØºÍ×Ô¶¯»¯¹ÜÀí¡£ËüÌṩ©¶´¹ÜÀí¡¢ºÏ¹æÐÔ¼ì²éºÍ·çÏÕÆÀ¹ÀµÈ¹¦Ð§£¬×ÊÖú×é֯ʶ±ðºÍÐÞ¸´ÔÆ»·¾³ÖеÄÄþ¾²ÎÊÌ⣬´Ó¶øÌáÉýÔÆÄþ¾²ÐÔ£¬È·±£ÆóÒµÇкÏÐÐÒµ³ß¶ÈºÍ¹æÔòÒªÇó¡£
2025Äê2ÔÂ13ÈÕ£¬¶«Éƽ̨¼¯ÍÅVSRC¼à²âµ½IvantiÐû²¼Á˹ØÓÚIvanti CSAµÄÁ½¸öÄþ¾²Í¨¸æ£¬·Ö±ðÉæ¼°ÃüÁî×¢Èë©¶´£¨CVE-2024-47908£©ºÍ·¾¶±éÀú©¶´£¨CVE-2024-11771£©¡£Í¨¸æÖÐÖ¸³ö£¬Ivanti CSA 5.0.5֮ǰ°æ±¾µÄ¹ÜÀíÔ±¿ØÖÆÌ¨´æÔÚOSÃüÁî×¢Èë©¶´£¬¹¥»÷ÕßÔÚ»ñµÃ¹ÜÀíԱȨÏ޺󣬿ÉÔ¶³ÌÖ´ÐжñÒâ´úÂ룬CVE±àºÅΪCVE-2024-47908£¬CVSSÆÀ·Ö9.1£¬Â©¶´Æ·¼¶ÎªÑÏÖØ¡£Í¬Ê±£¬5.0.5֮ǰµÄ°æ±¾»¹´æÔÚ·¾¶±éÀú©¶´£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß·ÃÎÊÊÜÏÞ¹¦Ð§£¬CVE±àºÅΪCVE-2024-11771£¬CVSSÆÀ·Ö5.3£¬Â©¶´Æ·¼¶ÎªÖÐΣ¡£
¶þ¡¢Ó°Ï췶Χ
Ivanti CSA < 5.0.5
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Éý¼¶ÖÁIvanti CSA 5.0.5°æ±¾
https://forums.ivanti.com/s/article/CSA-5-0-Download
3.2 ÁÙʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£? ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£? ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£? ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£? ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-47908-CVE-2024-11771?language=en_US
https://nvd.nist.gov/vuln/detail/CVE-2024-47908https://nvd.nist.gov/vuln/detail/CVE-2024-11771