¡¾Îó²îͨ¸æ¡¿Aviatrix ControllerÏÂÁî×¢ÈëÎó²î£¨CVE-2024-50603£©
Ðû²¼Ê±¼ä 2025-01-08Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Aviatrix ControllerÏÂÁî×¢ÈëÎó²î | ||
CVE ID | CVE-2024-50603 | ||
Îó²îÀàÐÍ | ÏÂÁî×¢Èë | ·¢Ã÷ʱ¼ä | 2025-01-08 |
Îó²îÆÀ·Ö | 10.0 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Aviatrix ControllerÊÇÒ»¿îǿʢµÄÔÆÍøÂçÖÎÀíÆ½Ì¨£¬£¬£¬£¬£¬Ìṩ¼ò»¯µÄ¿çÔÆÍøÂçÖÎÀí¡¢×Ô¶¯»¯ÉèÖá¢Çå¾²Õ½ÂÔ¡¢Á÷Á¿¼à¿ØµÈ¹¦Ð§£¬£¬£¬£¬£¬×ÊÖúÆóҵʵÏÖÔ½·¢ÎÞа¡¢Çå¾²ºÍ¸ßЧµÄÔÆÍøÂç¼Ü¹¹£¬£¬£¬£¬£¬ÌØÊâÊÊÓÃÓÚ¶àÔÆºÍ»ìÏýÔÆÇéÐΡ£¡£¡£¡£¡£¡£
2025Äê1ÔÂ8ÈÕ£¬£¬£¬£¬£¬¿Ê±K66¼¯ÍÅVSRC¼à²âµ½Aviatrix ControllerÖб»Åû¶±£´æÒ»¸öÏÂÁî×¢ÈëÎó²î£¨CVE-2024-50603£©£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ10.0£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îµÄÊÖÒÕϸ½Ú¼°PoCÒѹûÕæ¡£¡£¡£¡£¡£¡£
Aviatrix ControllerÊÜÓ°Ïì°æ±¾ÖУ¬£¬£¬£¬£¬ÓÉÓÚ¶Ô /v1/api Ï list_flightpath_destination_instances ²Ù×÷ÖÐµÄ cloud_type ²ÎÊý»ò flightpath_connection_test ²Ù×÷ÖÐµÄ src_cloud_type ²ÎÊýȱ·¦Êʵ±µÄÊäÈëÕûÀí£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇ󣬣¬£¬£¬£¬Ê¹ÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Aviatrix Controller < 7.1.4191
Aviatrix Controller 7.2.x < 7.2.4996
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º
Aviatrix Controller >= 7.1.4191
Aviatrix Controller 7.2.x >= 7.2.4996
ÏÂÔØÁ´½Ó£º
https://aviatrix.com/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£
? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£
? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£
? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/
https://nvd.nist.gov/vuln/detail/CVE-2024-50603
https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aviatrix-systems.aviatrix-controller?tab=overview
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2025-01-08 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¿Ê±K66¼ò½é
¿Ê±K66½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¿Ê±K66´óÏ㬣¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬¿Ê±K66ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£
5.2 ¹ØÓڿʱK66
¿Ê±K66Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ