¡¾Îó²îͨ¸æ¡¿Dell PowerProtect DD¿çÕ¾¾ç±¾Îó²î£¨CVE-2023-44286£©
Ðû²¼Ê±¼ä 2023-12-15Ò»¡¢Îó²î¸ÅÊö
CVE ID | CVE-2023-44286 | ·¢Ã÷ʱ¼ä | 2023-12-15 |
Àà ÐÍ | XSS | µÈ ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
¹¥»÷ÖØƯºó | µÍ | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Dell£¨´÷¶û¹«Ë¾£©ÊÇÈ«Çò×ÅÃûµÄÅÌËã»úϵͳ¹«Ë¾¡¢ÅÌËã»ú²úÆ·¼°·þÎñÌṩÉÌ£¬Ö÷ÒªÒÔÉú²ú¡¢Éè¼Æ¡¢ÏúÊÛ¼ÒÓÃÒÔ¼°°ì¹«ÊÒµçÄÔ¶øÖøÃû£¬Í¬Ê±Ò²Éú²úÓëÏúÊÛ·þÎñÆ÷¡¢Êý¾ÝÖü´æ×°±¸¡¢ÍøÂç×°±¸µÈ¡£Dell PowerProtect Data Domain (DD) ϵÁÐ×°±¸Ö¼ÔÚ×ÊÖú×éÖ¯´ó¹æÄ£±£»¤¡¢ÖÎÀíºÍ»Ö¸´Êý¾Ý¡£
12ÔÂ15ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøVSRC¼à²âµ½DellÐû²¼ÁËPowerProtect Çå¾²¸üУ¬ÐÞ¸´ÁËPowerProtect DDÖеÄÒ»¸ö¿çÕ¾¾ç±¾Îó²î£¨CVE-2023-44286£©£¬ÆäCVSSÆÀ·ÖΪ8.8¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉʹÓøÃÎó²î×¢Èë¶ñÒâHTML»òJavaScript´úÂ룬¿ÉÄÜÔÚÓû§½»»¥µÄÇéÐÎϵ¼ÖÂÐÅϢй¶¡¢»á»°É¥Ê§»ò¿Í»§¶ËÇëÇóαÔì¡£
±ðµÄ£¬±¾´ÎPowerProtectÇå¾²¸üл¹ÐÞ¸´ÁËÒÔÏÂ7¸öÎó²î£º
CVE-2023-48668£ºDell PowerProtect DDÏÂÁî×¢ÈëÎó²î£¨¸ßΣ£©
CVE-2023-44285£ºDell PowerProtect DD»á¼û¿ØÖƲ»ÎÈÍâµØȨÏÞÌáÉýÎó²î£¨¸ßΣ£©
CVE-2023-44277£ºDell PowerProtect DDÏÂÁî×¢ÈëÎó²î£¨¸ßΣ£©
CVE-2023-48667£ºDell PowerProtect DDÏÂÁî×¢ÈëÎó²î£¨¸ßΣ£©
CVE-2023-44279£ºDell PowerProtect DDÏÂÁî×¢ÈëÎó²î£¨ÖÐΣ£©
CVE-2023-44278£ºDell PowerProtect DDĿ¼±éÀúÎó²î£¨ÖÐΣ£©
CVE-2023-44284£ºDell PowerProtect DD SQL ×¢ÈëÎó²î£¨ÖÐΣ£©
¶þ¡¢Ó°Ïì¹æÄ£
CVE | ÊÜÓ°Ïì²úÆ· | Ó°Ïì¹æÄ£ | ÐÞ¸´°æ±¾ |
CVE-2023-44286¡¢CVE-2023-44285¡¢CVE-2023-44277¡¢CVE-2023-48667¡¢CVE-2023-44279¡¢CVE-2023-44278¡¢CVE-2023-44284 | Dell PowerProtect DD ϵÁÐ×°±¸¡¢Dell PowerProtect DD Virtual Edition¡¢Dell APEX Protection Storage | 7.0 -7.12.0.0 | Éý¼¶µ½7.13.0.10 ¼°¸ü¸ß°æ±¾ £¨»òÕß7.10.1.15¼°ÒÔÉÏ°æ±¾¼ÌÐøʹÓÃLTS2023 7.10¡¢7.7.5.25 ¼°¸ü¸ß°æ±¾¼ÌÐøʹÓà LTS2022 7.7£© |
6.2.1.100¼°Ö®Ç°°æ±¾ | Éý¼¶µ½6.2.1.110¼°ÒÔÉÏ°æ±¾ | ||
CVE-2023-44286¡¢CVE-2023-48668¡¢CVE-2023-44285¡¢CVE-2023-44277¡¢CVE-2023-48667¡¢CVE-2023-44279¡¢CVE-2023-44278 | Dell PowerProtect DD management Center | 7.0 - 7.12.0.0 | Éý¼¶µ½7.13.0.10 ¼°¸ü¸ß°æ±¾ £¨»òÕß7.10.1.15 ¼°¸ü¸ß°æ±¾¼ÌÐøʹÓà LTS2023 7.10 ¡¢ 7.7.5.25 ¼°¸ü¸ß°æ±¾¼ÌÐøʹÓà LTS2022 7.7£© |
6.2.1.100¼°Ö®Ç°°æ±¾ | Éý¼¶µ½6.2.1.110¼°ÒÔÉÏ°æ±¾ | ||
CVE-2023-44286¡¢CVE-2023-44285¡¢CVE-2023-44277¡¢CVE-2023-48667¡¢CVE-2023-44279¡¢CVE-2023-44278¡¢CVE-2023-44284 | PowerProtect DP ϵÁÐ×°±¸ (IDPA)£ºËùÓÐÐͺŠ| 2.7.4 ¼°Ö®Ç°°æ±¾ | Éý¼¶µ½2.7.6 ¼°ÒÔÉÏ°æ±¾£¨Ô¤¼Æ2023 Äê 12 Ô 21 ÈÕÐû²¼£© |
CVE-2023-44284 | PowerProtect Êý¾ÝÖÎÀíÆ÷×°±¸ÐͺţºDM5500 | 5.14¼°Ö®Ç°°æ±¾ | Éý¼¶µ½5.15.0.0¼°ÒÔÉÏ°æ±¾ |
CVE-2023-44286¡¢CVE-2023-44285¡¢CVE-2023-44277¡¢CVE-2023-48667¡¢CVE-2023-44279¡¢CVE-2023-44278¡¢CVE-2023-44284 | ´óÐÍ»ú´ÅÅÌ¿â (DLm) ÇéÐÎÖÐʹÓõĴ÷¶û PowerProtect DD ϵÁÐ×°±¸ºÍ´÷¶û PowerProtect DD ÐéÄâ°æ | 7.0 - 7.12.0.0 | Éý¼¶µ½7.13.0.10 ¼°¸ü¸ß°æ±¾ £¨»òÕß7.10.1.15 ¼°¸ü¸ß°æ±¾¼ÌÐøʹÓà LTS2023 7.10 ¡¢ 7.7.5.25 ¼°¸ü¸ß°æ±¾¼ÌÐøʹÓà LTS2022 7.7£© |
6.2.1.100¼°Ö®Ç°°æ±¾ | Éý¼¶µ½6.2.1.110¼°ÒÔÉÏ°æ±¾ |
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÏìÓ¦ÐÞ¸´°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://www.dell.com/support/kbdoc/en-in/000220264/dsa-2023-412-dell-technologies-powerprotect-security-update-for-multiple-security-vulnerabilities
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://www.dell.com/support/kbdoc/en-in/000220264/dsa-2023-412-dell-technologies-powerprotect-security-update-for-multiple-security-vulnerabilities
https://www.securityweek.com/dell-urges-customers-to-patch-vulnerabilities-in-powerprotect-products/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-12-15 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£
5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º