支持本站 — 捐款将帮助我们持续运营

目标: 1000 元,已筹: 1000

100.0%
获取后续新漏洞提醒登录后订阅
一、 漏洞 CVE-2025-1146 基础信息
漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
CrowdStrike Falcon Sensor for Linux TLS Issue
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection routine to the CrowdStrike cloud can incorrectly process server certificate validation. This could allow an attacker with the ability to control network traffic to potentially conduct a man-in-the-middle (MiTM) attack. CrowdStrike identified this issue internally and released a security fix in all Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor versions 7.06 and above. CrowdStrike identified this issue through our longstanding, rigorous security review process, which has been continually strengthened with deeper source code analysis and ongoing program enhancements as part of our commitment to security resilience. CrowdStrike has no indication of any exploitation of this issue in the wild. CrowdStrike has leveraged its world class threat hunting and intelligence capabilities to actively monitor for signs of abuse or usage of this flaw and will continue to do so. Windows and Mac sensors are not affected by this.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
证书信任链回溯不恰当
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
CrowdStrike Falcon 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
CrowdStrike Falcon是美国CrowdStrike公司的一个端点、云和身份保护产品。 CrowdStrike Falcon存在安全漏洞,该漏洞源于TLS连接例程验证逻辑错误,会导致受到中间人攻击。受影响产品如下: Falcon Sensor for Linux、Falcon Kubernetes Admission Controller和Falcon Container Sensor。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD
受影响产品
厂商产品影响版本CPE订阅
CrowdStrikeFalcon sensor for Linux 7.21.17405 -
CrowdStrikeFalcon Kubernetes Admission Controller 7.21.1904 -
CrowdStrikeFalcon Container Sensor 7.21.6003 -
二、漏洞 CVE-2025-1146 的公开POC
#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC
三、漏洞 CVE-2025-1146 的情报信息
Please 登录 to view more intelligence information
四、漏洞 CVE-2025-1146 的评论

暂无评论


发表评论