ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ35ÖÜ
Ðû²¼Ê±¼ä 2020-09-01> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê08ÔÂ24ÈÕÖÁ30ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´55¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇRed Lion N-TronδÃ÷½Ó¿Ú©¶´£»FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯Â©¶´£»Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´ÐЩ¶´£»Foxit Studio Photo PSDÔ½½çд´úÂëÖ´ÐЩ¶´; Moog EXO Series EXVF5C-2¹ÜÀí¿ØÖÆ̨'statusbroadcast'ÈÎÒâÃüÁîÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇCiscoÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¶à¸ö²úÎïÖеÄ©¶´£»ClarotyÐû²¼2020ÄêÉÏ°ëÄêICS©¶´·ÖÎö³ÂËߣ»Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖôíÎóй¶3700ÍòÌõ¼Ç¼£»Î¢ÈíÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö©¶´£»CiscoÇ°Ô±¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Red Lion N-TronδÃ÷½Ó¿Ú©¶´
Red Lion N-Tron´æÔÚδÎĵµ»¯½Ó¿Ú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔROOTȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£
https://us-cert.cisa.gov/ics/advisories/icsa-20-240-01
2. FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯Â©¶´
FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource´æÔÚÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://github.com/FasterXML/jackson-databind/issues/2814
3. Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´ÐЩ¶´
Advantech iView DeviceTreeTable exportTaskMgrReport´æÔÚĿ¼±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎĶÁȡϵͳÎļþ»òÕßÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-1084/
4. Foxit Studio Photo PSDÔ½½çд´úÂëÖ´ÐЩ¶´
Foxit Studio Photo½âÎöPSDÎļþ´æÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔϵͳÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-1078/
5. Moog EXO Series EXVF5C-2¹ÜÀí¿ØÖÆ̨'statusbroadcast'ÈÎÒâÃüÁîÖ´ÐЩ¶´
Moog EXO Series EXVF5C-2¹ÜÀí¿ØÖÆ̨'statusbroadcast'´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Ê¹ÓÃ'${IFS}'±äÁ¿ÈƹýÏÞÖÆ£¬¿ÉÒÔrootȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£
https://ioactive.com/moog-exo-series-multiple-vulnerabilities/
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢CiscoÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¶à¸ö²úÎïÖеÄ©¶´
CiscoÐû²¼Äþ¾²¸üУ¬ÒÔÐÞ¸´Æä¶à¸ö²úÎïÖеÄ©¶´¡£´Ë´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄ½ÏΪÑÏÖصÄ©¶´ÎªTreck IP¶ÑÕ»ÖеÄ©¶´Ripple20£¬ÕâЩ©¶´¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢¾Ü¾ø·þÎñ£¨DoS£©»òÐÅϢй¶£»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏƾ¾Ý©¶´£¨CVE-2020-3446£©£¬¿É±»ÀûÓÃÒÔ¹ÜÀíԱȨÏÞ·ÃÎÊNFVIS CLI£»Ë¼¿ÆÖÇÄÜÈí¼þ¹ÜÀíÆ÷£¨SSM On-Prem£©µ±µØÌØȨÉý¼¶Â©¶´£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓƵ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢ÏÖÐÒéÔ¶³ÌÖ´Ðк;ܾø·þÎñ©¶´£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates
2¡¢ClarotyÐû²¼2020ÄêÉÏ°ëÄêICS©¶´·ÖÎö³ÂËß
¹¤ÒµÍøÂçÄþ¾²¹«Ë¾ClarotyÐû²¼2020ÄêÉÏ°ëÄêICS©¶´·ÖÎö³ÂËß¡£Claroty·ÖÎöÁËÐÂÌí¼Óµ½¹ú¼Ò©¶´Êý¾Ý¿â£¨NVD£©ÖеÄ365¸öICS©¶´ÒÔ¼°ICS-CERT£¨CISA£©Ðû²¼µÄͨ±¨Öк¸ÇµÄ385¸ö©¶´¡£Óë2019ÄêͬÆÚÅû¶µÄ©¶´ÊýÁ¿Ïà±È£¬2020ÄêÉÏ°ëÄêÐÂÔöµ½NVDÖеÄ©¶´ÊýÁ¿Ô¼Äª¶à³ö10£¥¡£ÔÚËùʶ´ËÍ⩶´ÖУ¬ÓÐ70£¥ÒÔÉϵÄ©¶´¿É±»Ô¶³ÌÀûÓã¬Óн«½üÒ»°ë¿ÉÓÃÓÚÔ¶³ÌÖ´ÐдúÂ룬ÆäÖÐ41£¥µÄ©¶´¿ÉÈù¥»÷Õ߶ÁÈ¡Ó¦Ó÷¨Ê½Êý¾Ý£¬39£¥µÄ©¶´¿ÉÓÃÓÚDoS¹¥»÷£¬37£¥µÄ©¶´¿ÉÈƹýÄþ¾²»úÖÆ¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/over-70-ics-vulnerabilities-disclosed-first-half-2020-remotely-exploitable
3¡¢Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖôíÎóй¶3700ÍòÌõ¼Ç¼
SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢ÏÖÁËRailYatriµÄûÓÐÃÜÂë±£»¤µÄElasticsearch·þÎñÆ÷£¬Ð¹Â¶3700ÍòÌõ¼Ç¼¿Í»§ºÍ¹«Ë¾Êý¾Ý£¬°üÂÞÓû§µÄÈ«Ãû¡¢ÄêÁä¡¢ÐÔ±ð¡¢Êµ¼ÊºÍµç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂë¡¢Ô¤¶©ÏêϸÐÅÏ¢¡¢GPSλÖÃÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄÇ°ËÄλºÍºóËÄλ¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý½øÐб£»¤Ö®Ç°£¬Meow»úÆ÷ÈËÓÚ8ÔÂ12ÈÕ¶ÔÆä·¢Éú¹¥»÷£¬É¾³ýÁ˳ý1GBÖ®ÍâµÄËùÓÐÊý¾Ý£¨×ܹ²43 GB£©¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/
4¡¢Î¢ÈíÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö©¶´
΢ÈíÐû²¼Â©¶´²¹¶¡£¬ÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö©¶´¡£´Ë´ÎÐû²¼µÄ²¹¶¡·¨Ê½ÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´ºÍ2¸öÌáȨ©¶´£¬ÕâЩ©¶´¶¼ÊÇÓÉCisco TalosµÄÄþ¾²Ñо¿ÈËÔ±ÓÚ7Ô·ݷ¢ÏÖ¡£µÚÒ»¸öΪREAD_IMPLIES_EXEC personalityδǩÃû´úÂëÖ´ÐЩ¶´£¬µÚ¶þ¸öRCE©¶´´æÔÚÓÚ/proc/thread-self/ memÖС£´ËÍ⣬ȨÏÞ·ÃÎÊ¿ØÖƹ¦Ð§ÖдæÔÚÒ»¸öÌáȨ©¶´£¬¶øµÚ¶þ¸öÌáȨ©¶´´æÔÚÓÚAzure Sphere 20.06µÄuid_map¹¦Ð§ÖС£Î¢ÈíÌåÏÖ»áÈ·±£½â¾öÕâЩÎÊÌⲢΪ¿Í»§Ìṩ¸üУ¬µ«ÊǾܾøÐû²¼ÈκÎCVEs¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/four-more-bugs-patched-in-microsofts-azure-sphere-iot-platform/158643/
5¡¢CiscoÇ°Ô±¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú
˼¿ÆÇ°Ô±¹¤Sudhish Kasaba RameshÈÏ×ïÆäɾ³ýÁËWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú¡£¾ÝÆäÈÏ×ïÐÒéÖгƣ¬ÆäÈÏ¿ÉÔÚÀëÖ°5¸öÔºóµÄ2018Äê9ÔÂ24ÈÕ£¬Î´¾¹«Ë¾µÄÐí¿ÉÓÐÒâ·ÃÎÊ˼¿ÆµÄÔÆ»ù´¡¼Ü¹¹£¬²¢´ÓÆä×Ô¼ºµÄGoogle Cloud ProjectÕÊ»§Öв¿ÊðÁËÒ»¸ö´úÂ룬ɾ³ýÁË˼¿ÆWebEx TeamsÓ¦Ó÷¨Ê½µÄ456¸öÐéÄâ»ú¡£¾ÝϤ£¬¸Ãʼþµ¼ÖÂ16000¸öWebEx TeamsÕÊ»§±»¹Ø±ÕÁ˳¤´ïÁ½¸öÐÇÆÚ£¬Cisco»¨·ÑÁËԼĪ140ÍòÃÀÔªÀ´»Ö¸´ÆäÓ¦ÓÃÊܵ½µÄË𺦣¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§ÍË»¹ÁËÁè¼Ý100ÍòÃÀÔªµÄ¿îÏî¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/ex-cisco-employee-pleads-guilty-to-deleting-16k-webex-teams-accounts/158748/