SoftNAS Cloud OSÏÂÁî×¢ÈëÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-31
Îó²î±àºÅºÍ¼¶±ð

CVE-2018-14417 ³§ÉÌ×ÔÆÀ£º¸ß  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

SoftNAS Cloud version < 4.0.3


Îó²î¸ÅÊö
SoftNAS CloudÊÇÒ»¸öÈí¼þ½ç˵µÄNASÎļþÖÎÀíÆ÷£¬ £¬£¬£¬£¬£¬×÷ΪÔÚ¹«¹²ÔÆ£¬ £¬£¬£¬£¬£¬Ë½ÓÐÔÆ»ò»ìÏýÔÆÖÐÔËÐеÄÐéÄâ´æ´¢×°±¸Ìṩ¡£¡£¡£ ¡£ SoftNAS CloudÌṩÆóÒµ¼¶NAS¹¦Ð§£¬ £¬£¬£¬£¬£¬°üÀ¨¼ÓÃÜ£¬ £¬£¬£¬£¬£¬¿ìÕÕ£¬ £¬£¬£¬£¬£¬¿ìËٻعöºÍ¿çÇøÓò¸ß¿ÉÓÃÐÔÒÔ¼°×Ô¶¯¹ÊÕÏ×ªÒÆ¹¦Ð§¡£¡£¡£ ¡£

ÍâµØÊ±¼ä7ÔÂ26ÈÕ£¬ £¬£¬£¬£¬£¬SoftNAS Cloud±»ÆØ³ö±£´æ1¸öOSÏÂÁî×¢ÈëÎó²î£¨CVE-2018-14417£©¡£¡£¡£ ¡£¸ÃÎó²îÔ´ÓÚwebÖÎÀíÔ±¿ØÖÆÌ¨ÖеÄsnserv¾ç±¾Ã»ÓÐÇå¾²µÄ¹ýÂ˽ÓÊܵ½µÄÊäÈë²ÎÊý£¬ £¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔÔÚϵͳÖÐÖ´ÐÐÏÂÁî¡£¡£¡£ ¡£


Îó²îÑéÖ¤

POC£ºhttps://0day.city/cve-2018-14417.html


Ó°Ïì¹æÄ£
 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÐÞ¸´½¨Òé

SoftNAS¹Ù·½ÒѾ­Ðû²¼ÁË×îеÄ4.0.3ÐÞ¸´ÁËÉÏÊöÎó²î£¬ £¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§¿ÉÒÔÔÚ²úÆ·Öд洢ÖÐÐÄ£¨SotrageCenter£©µÄÖÎÀíÔ±½çÃæ¾ÙÐÐÉý¼¶¡£¡£¡£ ¡£


²Î¿¼Á´½Ó
https://www.softnas.com
https://www.coresecurity.com/advisories/softnas-cloud-os-command-injection
https://0day.city/cve-2018-14417.html