SoftNAS Cloud OSÏÂÁî×¢ÈëÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-07-31CVE-2018-14417 ³§ÉÌ×ÔÆÀ£º¸ß CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
SoftNAS Cloud version < 4.0.3
SoftNAS CloudÊÇÒ»¸öÈí¼þ½ç˵µÄNASÎļþÖÎÀíÆ÷£¬£¬£¬£¬£¬×÷ΪÔÚ¹«¹²ÔÆ£¬£¬£¬£¬£¬Ë½ÓÐÔÆ»ò»ìÏýÔÆÖÐÔËÐеÄÐéÄâ´æ´¢×°±¸Ìṩ¡£¡£¡£¡£¡£ SoftNAS CloudÌṩÆóÒµ¼¶NAS¹¦Ð§£¬£¬£¬£¬£¬°üÀ¨¼ÓÃÜ£¬£¬£¬£¬£¬¿ìÕÕ£¬£¬£¬£¬£¬¿ìËٻعöºÍ¿çÇøÓò¸ß¿ÉÓÃÐÔÒÔ¼°×Ô¶¯¹ÊÕÏ×ªÒÆ¹¦Ð§¡£¡£¡£¡£¡£
ÍâµØÊ±¼ä7ÔÂ26ÈÕ£¬£¬£¬£¬£¬SoftNAS Cloud±»ÆØ³ö±£´æ1¸öOSÏÂÁî×¢ÈëÎó²î£¨CVE-2018-14417£©¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚwebÖÎÀíÔ±¿ØÖÆÌ¨ÖеÄsnserv¾ç±¾Ã»ÓÐÇå¾²µÄ¹ýÂ˽ÓÊܵ½µÄÊäÈë²ÎÊý£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔÔÚϵͳÖÐÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£
POC£ºhttps://0day.city/cve-2018-14417.html
SoftNAS¹Ù·½ÒѾÐû²¼ÁË×îеÄ4.0.3ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§¿ÉÒÔÔÚ²úÆ·Öд洢ÖÐÐÄ£¨SotrageCenter£©µÄÖÎÀíÔ±½çÃæ¾ÙÐÐÉý¼¶¡£¡£¡£¡£¡£
https://www.softnas.com
https://www.coresecurity.com/advisories/softnas-cloud-os-command-injection
https://0day.city/cve-2018-14417.html


¾©¹«Íø°²±¸11010802024551ºÅ