ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ35ÖÜ
Ðû²¼Ê±¼ä 2020-09-01> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2020Äê08ÔÂ24ÈÕÖÁ30ÈÕ¹²ÊÕ¼Çå¾²Îó²î55¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇRed Lion N-TronδÃ÷½Ó¿ÚÎó²î£»FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯Îó²î£»Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´ÐÐÎó²î£»Foxit Studio Photo PSDÔ½½çд´úÂëÖ´ÐÐÎó²î; Moog EXO Series EXVF5C-2ÖÎÀí¿ØÖÆ̨'statusbroadcast'í§ÒâÏÂÁîÖ´ÐÐÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇCiscoÐû²¼Çå¾²¸üУ¬ÐÞ¸´¶à¸ö²úÆ·ÖеÄÎó²î£»ClarotyÐû²¼2020ÄêÉÏ°ëÄêICSÎó²îÆÊÎö±¨¸æ£»Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÉèÖùýʧй¶3700ÍòÌõ¼Í¼£»Î¢ÈíÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸öÎó²î£»CiscoÇ°Ô±¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Red Lion N-TronδÃ÷½Ó¿ÚÎó²î
Red Lion N-Tron±£´æδÎĵµ»¯½Ó¿ÚÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÒÔROOTȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£
https://us-cert.cisa.gov/ics/advisories/icsa-20-240-01
2. FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯Îó²î
FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource±£´æÐòÁл¯Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://github.com/FasterXML/jackson-databind/issues/2814
3. Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´ÐÐÎó²î
Advantech iView DeviceTreeTable exportTaskMgrReport±£´æĿ¼±éÀúÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎĶÁȡϵͳÎļþ»òÕßÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-1084/
4. Foxit Studio Photo PSDÔ½½çд´úÂëÖ´ÐÐÎó²î
Foxit Studio PhotoÆÊÎöPSDÎļþ±£´æÔ½½çдÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉÒÔϵͳÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-1078/
5. Moog EXO Series EXVF5C-2ÖÎÀí¿ØÖÆ̨'statusbroadcast'í§ÒâÏÂÁîÖ´ÐÐÎó²î
Moog EXO Series EXVF5C-2ÖÎÀí¿ØÖÆ̨'statusbroadcast'±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬Ê¹ÓÃ'${IFS}'±äÁ¿ÈƹýÏÞÖÆ£¬¿ÉÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£
https://ioactive.com/moog-exo-series-multiple-vulnerabilities/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢CiscoÐû²¼Çå¾²¸üУ¬ÐÞ¸´¶à¸ö²úÆ·ÖеÄÎó²î
CiscoÐû²¼Çå¾²¸üУ¬ÒÔÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄÎó²î¡£´Ë´ÎÇå¾²¸üÐÂÖÐÐÞ¸´µÄ½ÏΪÑÏÖصÄÎó²îΪTreck IP¿ÍÕ»ÖеÄÎó²îRipple20£¬ÕâЩÎó²î¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢¾Ü¾ø·þÎñ£¨DoS£©»òÐÅϢй¶£»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏƾ֤Îó²î£¨CVE-2020-3446£©£¬¿É±»Ê¹ÓÃÒÔÖÎÀíԱȨÏÞ»á¼ûNFVIS CLI£»Ë¼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM On-Prem£©ÍâµØÌØȨÉý¼¶Îó²î£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓƵ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢Ã÷ÐÒéÔ¶³ÌÖ´Ðк;ܾø·þÎñÎó²î£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates
2¡¢ClarotyÐû²¼2020ÄêÉÏ°ëÄêICSÎó²îÆÊÎö±¨¸æ
¹¤ÒµÍøÂçÇå¾²¹«Ë¾ClarotyÐû²¼2020ÄêÉÏ°ëÄêICSÎó²îÆÊÎö±¨¸æ¡£ClarotyÆÊÎöÁËÐÂÌí¼Óµ½¹ú¼ÒÎó²îÊý¾Ý¿â£¨NVD£©ÖеÄ365¸öICSÎó²îÒÔ¼°ICS-CERT£¨CISA£©Ðû²¼µÄת´ïÖк¸ÇµÄ385¸öÎó²î¡£Óë2019ÄêͬÆÚÅû¶µÄÎó²îÊýÄ¿Ïà±È£¬2020ÄêÉÏ°ëÄêÐÂÔöµ½NVDÖеÄÎó²îÊýĿԼĪ¶à³ö10£¥¡£ÔÚËùʶ±ðµÄÎó²îÖУ¬ÓÐ70£¥ÒÔÉϵÄÎó²î¿É±»Ô¶³ÌʹÓã¬ÓпìÒªÒ»°ë¿ÉÓÃÓÚÔ¶³ÌÖ´ÐдúÂ룬ÆäÖÐ41£¥µÄÎó²î¿ÉÈù¥»÷Õ߶ÁÈ¡Ó¦ÓóÌÐòÊý¾Ý£¬39£¥µÄÎó²î¿ÉÓÃÓÚDoS¹¥»÷£¬37£¥µÄÎó²î¿ÉÈƹýÇå¾²»úÖÆ¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/over-70-ics-vulnerabilities-disclosed-first-half-2020-remotely-exploitable
3¡¢Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÉèÖùýʧй¶3700ÍòÌõ¼Í¼
SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢Ã÷ÁËRailYatriµÄûÓÐÃÜÂë±£»¤µÄElasticsearch·þÎñÆ÷£¬Ð¹Â¶3700ÍòÌõ¼Í¼¿Í»§ºÍ¹«Ë¾Êý¾Ý£¬°üÀ¨Óû§µÄÈ«Ãû¡¢ÄêËê¡¢ÐÔ±ð¡¢ÏÖʵºÍµç×ÓÓʼþµØµã¡¢ÊÖ»úºÅÂë¡¢Ô¤¶©ÏêϸÐÅÏ¢¡¢GPSλÖÃÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄÇ°ËÄλºÍºóËÄλ¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý¾ÙÐб£»¤Ö®Ç°£¬Meow»úеÈËÓÚ8ÔÂ12ÈÕ¶ÔÆ䱬·¢¹¥»÷£¬É¾³ýÁ˳ý1GBÖ®ÍâµÄËùÓÐÊý¾Ý£¨×ܹ²43 GB£©¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/
4¡¢Î¢ÈíÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸öÎó²î
΢ÈíÐû²¼Îó²î²¹¶¡£¬ÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸öÎó²î¡£´Ë´ÎÐû²¼µÄ²¹¶¡³ÌÐòÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²îºÍ2¸öÌáȨÎó²î£¬ÕâЩÎó²î¶¼ÊÇÓÉCisco TalosµÄÇå¾²Ñо¿Ö°Ô±ÓÚ7Ô·ݷ¢Ã÷¡£µÚÒ»¸öΪREAD_IMPLIES_EXEC personalityδÊðÃû´úÂëÖ´ÐÐÎó²î£¬µÚ¶þ¸öRCEÎó²î±£´æÓÚ/proc/thread-self/ memÖС£±ðµÄ£¬È¨ÏÞ»á¼û¿ØÖƹ¦Ð§Öб£´æÒ»¸öÌáȨÎó²î£¬¶øµÚ¶þ¸öÌáȨÎó²î±£´æÓÚAzure Sphere 20.06µÄuid_map¹¦Ð§ÖС£Î¢ÈíÌåÏÖ»áÈ·±£½â¾öÕâЩÎÊÌⲢΪ¿Í»§Ìṩ¸üУ¬¿ÉÊǾܾøÐû²¼ÈκÎCVEs¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/four-more-bugs-patched-in-microsofts-azure-sphere-iot-platform/158643/
5¡¢CiscoÇ°Ô±¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú
˼¿ÆÇ°Ô±¹¤Sudhish Kasaba RameshÈÏ×ïÆäɾ³ýÁËWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú¡£¾ÝÆäÈÏ×ïÐÒéÖгƣ¬ÆäÈÏ¿ÉÔÚÈ¥Ö°5¸öÔºóµÄ2018Äê9ÔÂ24ÈÕ£¬Î´¾¹«Ë¾µÄÔÊÐíÓÐÒâ»á¼û˼¿ÆµÄÔÆ»ù´¡¼Ü¹¹£¬²¢´ÓÆä×Ô¼ºµÄGoogle Cloud ProjectÕÊ»§Öа²ÅÅÁËÒ»¸ö´úÂ룬ɾ³ýÁË˼¿ÆWebEx TeamsÓ¦ÓóÌÐòµÄ456¸öÐéÄâ»ú¡£¾ÝϤ£¬¸ÃÊÂÎñµ¼ÖÂ16000¸öWebEx TeamsÕÊ»§±»¹Ø±ÕÁ˳¤´ïÁ½¸öÐÇÆÚ£¬CiscoÆÆ·ÑÁËԼĪ140ÍòÃÀÔªÀ´»Ö¸´ÆäÓ¦ÓÃÊܵ½µÄË𺦣¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§ÍË»¹ÁËÁè¼Ý100ÍòÃÀÔªµÄ¿î×Ó¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/ex-cisco-employee-pleads-guilty-to-deleting-16k-webex-teams-accounts/158748/