¡¾Îó²îͨ¸æ¡¿Ivanti¶à¿î²úÆ·»º³åÇøÒç³öÎó²î(CVE-2025-0282)
Ðû²¼Ê±¼ä 2025-01-14Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Ivanti¶à¿î²úÆ·»º³åÇøÒç³öÎó²î | ||
CVE ID | CVE-2025-0282 | ||
Îó²îÀàÐÍ | »º³åÇøÒç³ö | ·¢Ã÷ʱ¼ä | 2025-01-14 |
Îó²îÆÀ·Ö | 9.0 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ÒÑ·¢Ã÷ |
Ivanti Connect Secure£¨Ç°³Æ Pulse Connect Secure£©ÊÇ Ivanti ÌṩµÄÆóÒµ¼¶ SSL VPN ½â¾ö¼Æ»®£¬Ö¼ÔÚΪԶ³ÌÓû§ÌṩÇå¾²µÄÍøÂç»á¼û¡£Í¨¹ý¼ÓÃÜͨµÀ°ü¹ÜÊý¾ÝÇå¾²£¬Ö§³ÖÉí·ÝÑéÖ¤ºÍ»á¼û¿ØÖÆ£¬ÊÊÓÃÓÚÔ¶³Ì°ì¹«¡¢ÏàÖúͬ°é»á¼ûºÍ·ÖÖ§»ú¹¹ÅþÁ¬µÈ¸ßÇå¾²ÐÔ³¡¾°¡£
2025Äê1ÔÂ14ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅVSRC¼à²âµ½Ivanti¹Ù·½Ðû²¼Á˸üУ¬ÐÞ¸´ÁËIvanti Connect Secure¡¢Policy SecureºÍZTA GatewaysÖеÄÁ½¸ö»º³åÇøÒç³öÎó²î£ºCVE-2025-0282ºÍCVE-2025-0283¡£ÆäÖУ¬CVE-2025-0282Îó²î±»ÆÀ¶¨ÎªÑÏÖØ£¬CVSSÆÀ·ÖΪ9.0·Ö£»CVE-2025-0283Îó²îÔò±»ÆÀ¶¨Îª¸ßΣ£¬CVSSÆÀ·ÖΪ7.0·Ö¡£
CVE-2025-0282£ºÔ¶³Ìδ¾ÈÏÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý´ËÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬CVE-2025-0283£ºÍâµØÒÑÈÏÖ¤¹¥»÷Õß¿ÉʹÓôËÎó²îÌáÉýȨÏÞ¡£
¶þ¡¢Ó°Ïì¹æÄ£
22.7R2 <= Ivanti Neurons for ZTA <= 22.7R2.3
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 ÔÝʱ²½·¥
3.3 ͨÓý¨Òé
? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£