¡¾Îó²îͨ¸æ¡¿Aviatrix ControllerÏÂÁî×¢ÈëÎó²î£¨CVE-2024-50603£©

Ðû²¼Ê±¼ä 2025-01-08

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Aviatrix ControllerÏÂÁî×¢ÈëÎó²î

CVE   ID

CVE-2024-50603

Îó²îÀàÐÍ

ÏÂÁî×¢Èë

·¢Ã÷ʱ¼ä

2025-01-08

Îó²îÆÀ·Ö

10.0

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷

 

Aviatrix ControllerÊÇÒ»¿îǿʢµÄÔÆÍøÂçÖÎÀíÆ½Ì¨ £¬£¬£¬£¬ £¬£¬Ìṩ¼ò»¯µÄ¿çÔÆÍøÂçÖÎÀí¡¢×Ô¶¯»¯ÉèÖá¢Çå¾²Õ½ÂÔ¡¢Á÷Á¿¼à¿ØµÈ¹¦Ð§ £¬£¬£¬£¬ £¬£¬×ÊÖúÆóҵʵÏÖÔ½·¢ÎÞа¡¢Çå¾²ºÍ¸ßЧµÄÔÆÍøÂç¼Ü¹¹ £¬£¬£¬£¬ £¬£¬ÌØÊâÊÊÓÃÓÚ¶àÔÆºÍ»ìÏýÔÆÇéÐΡ£¡£¡£


2025Äê1ÔÂ8ÈÕ £¬£¬£¬£¬ £¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½Aviatrix ControllerÖб»Åû¶±£´æÒ»¸öÏÂÁî×¢ÈëÎó²î£¨CVE-2024-50603£© £¬£¬£¬£¬ £¬£¬ÆäCVSSÆÀ·ÖΪ10.0 £¬£¬£¬£¬ £¬£¬ÏÖÔÚ¸ÃÎó²îµÄÊÖÒÕϸ½Ú¼°PoCÒѹûÕæ¡£¡£¡£


Aviatrix ControllerÊÜÓ°Ïì°æ±¾ÖÐ £¬£¬£¬£¬ £¬£¬ÓÉÓÚ¶Ô /v1/api Ï list_flightpath_destination_instances ²Ù×÷ÖÐµÄ cloud_type ²ÎÊý»ò flightpath_connection_test ²Ù×÷ÖÐµÄ src_cloud_type ²ÎÊýȱ·¦Êʵ±µÄÊäÈëÕûÀí £¬£¬£¬£¬ £¬£¬¿ÉÄܵ¼ÖÂÏÂÁî×¢ÈëÎó²î £¬£¬£¬£¬ £¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇó £¬£¬£¬£¬ £¬£¬Ê¹ÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Aviatrix Controller < 7.1.4191

Aviatrix Controller 7.2.x < 7.2.4996


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´ £¬£¬£¬£¬ £¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º

Aviatrix Controller >= 7.1.4191

Aviatrix Controller 7.2.x >= 7.2.4996


ÏÂÔØÁ´½Ó£º

https://aviatrix.com/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬£¬£¬£¬ £¬£¬ïÔ̭ϵͳÎó²î £¬£¬£¬£¬ £¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£

ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬£¬£¬£¬ £¬£¬Ð޸ķÀ»ðǽսÂÔ £¬£¬£¬£¬ £¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ £¬£¬£¬£¬ £¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬£¬£¬£¬ £¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£

ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬£¬£¬£¬ £¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£

ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬£¬£¬£¬ £¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬£¬£¬£¬ £¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£

ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/

https://nvd.nist.gov/vuln/detail/CVE-2024-50603

https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aviatrix-systems.aviatrix-controller?tab=overview


ËÄ¡¢°æ±¾ÐÅÏ¢


°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2025-01-08

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼


5.1 ÄϹ¬NGÓéÀÖ¼ò½é


ÄϹ¬NGÓéÀÖ½¨ÉèÓÚ1996Äê £¬£¬£¬£¬ £¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£


¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÄϹ¬NGÓéÀÖ´óÏà £¬£¬£¬£¬ £¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬£¬£¬£¬ £¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬£¬£¬£¬ £¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡££¨¹ÉƱ´úÂ룺002439£©


¶àÄêÀ´ £¬£¬£¬£¬ £¬£¬ÄϹ¬NGÓéÀÖÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ £¬£¬£¬£¬ £¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ £¬£¬£¬£¬ £¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£


5.2 ¹ØÓÚÄϹ¬NGÓéÀÖ


ÄϹ¬NGÓéÀÖÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯ £¬£¬£¬£¬ £¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î £¬£¬£¬£¬ £¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£


¹Ø×¢ÎÒÃÇ£º


Çå¾²¼òѶ.jpg