¡¾Îó²îͨ¸æ¡¿Ivanti CSAÖÎÀí¿ØÖÆÌ¨ÏÂÁî×¢ÈëÎó²î(CVE-2024-47908)

Ðû²¼Ê±¼ä 2025-02-13

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Ivanti CSAÖÎÀí¿ØÖÆÌ¨ÏÂÁî×¢ÈëÎó²î

CVE   ID

CVE-2024-47908

Îó²îÀàÐÍ

ÏÂÁî×¢Èë

·¢Ã÷ʱ¼ä

2025-02-13

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Ivanti CSA£¨Cloud Security Automation£©ÊÇÒ»¿îÔÆÇå¾²×Ô¶¯»¯½â¾ö¼Æ»®£¬£¬£¬Ö¼ÔÚ×ÊÖúÆóҵʵÏÖ¶ÔÔÆ»ù´¡ÉèÊ©µÄÇå¾²¼à¿ØºÍ×Ô¶¯»¯ÖÎÀí¡£¡£ ¡£¡£¡£¡£ËüÌṩÎó²îÖÎÀí¡¢ºÏ¹æÐÔ¼ì²éºÍΣº¦ÆÀ¹ÀµÈ¹¦Ð§£¬£¬£¬×ÊÖú×é֯ʶ±ðºÍÐÞ¸´ÔÆÇéÐÎÖеÄÇå¾²ÎÊÌ⣬£¬£¬´Ó¶øÌáÉýÔÆÇå¾²ÐÔ£¬£¬£¬È·±£ÆóÒµÇкÏÐÐÒµ±ê×¼ºÍ¹æÔòÒªÇ󡣡£ ¡£¡£¡£¡£


2025Äê2ÔÂ13ÈÕ£¬£¬£¬¿­Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅVSRC¼à²âµ½IvantiÐû²¼Á˹ØÓÚIvanti CSAµÄÁ½¸öÇ徲ͨ¸æ£¬£¬£¬»®·ÖÉæ¼°ÏÂÁî×¢ÈëÎó²î£¨CVE-2024-47908£©ºÍ·¾¶±éÀúÎó²î£¨CVE-2024-11771£©¡£¡£ ¡£¡£¡£¡£Í¨¸æÖÐÖ¸³ö£¬£¬£¬Ivanti CSA 5.0.5֮ǰ°æ±¾µÄÖÎÀíÔ±¿ØÖÆÌ¨±£´æOSÏÂÁî×¢ÈëÎó²î£¬£¬£¬¹¥»÷ÕßÔÚ»ñµÃÖÎÀíԱȨÏ޺󣬣¬£¬¿ÉÔ¶³ÌÖ´ÐжñÒâ´úÂ룬£¬£¬CVE±àºÅΪCVE-2024-47908£¬£¬£¬CVSSÆÀ·Ö9.1£¬£¬£¬Îó²îÆ·¼¶ÎªÑÏÖØ¡£¡£ ¡£¡£¡£¡£Í¬Ê±£¬£¬£¬5.0.5֮ǰµÄ°æ±¾»¹±£´æÂ·¾¶±éÀúÎó²î£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»á¼ûÊÜÏÞ¹¦Ð§£¬£¬£¬CVE±àºÅΪCVE-2024-11771£¬£¬£¬CVSSÆÀ·Ö5.3£¬£¬£¬Îó²îÆ·¼¶ÎªÖÐΣ¡£¡£ ¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Ivanti CSA < 5.0.5


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Éý¼¶ÖÁIvanti CSA 5.0.5°æ±¾


ÏÂÔØÁ´½Ó£º
https://forums.ivanti.com/s/article/CSA-5-0-Download


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£ ¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£ ¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£ ¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£ ¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£ ¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£ ¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-47908-CVE-2024-11771?language=en_US

https://nvd.nist.gov/vuln/detail/CVE-2024-47908
https://nvd.nist.gov/vuln/detail/CVE-2024-11771