ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ14ÖÜ
Ðû²¼Ê±¼ä 2021-04-06> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2021Äê03ÔÂ29ÈÕÖÁ04ÔÂ04ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´56¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Azure SphereδǩÃû´úÂëÖ´ÐЩ¶´£»SAP Solution Manager User-Experience MonitoringÊÚȨ¼ì²éȱʧ©¶´£»Adobe Creative Cloud Desktop ApplicationÈÎÒâÎļþдÈ멶´£»F5 BIG-IP Advanced WAF/ASM»º³åÇøÒç³ö©¶´£»Schneider Electric Interactive Graphical SCADA System CGFÎļþ½âÎöÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇNPM¿âNetmask×é¼þ´æÔÚ©¶´£¬¿ÉÓ°ÏìÊýÍò¸öÓ¦Ó÷¨Ê½£»Ó¢¹ú¹«Ë¾FatFaceѬȾConti£¬Áè¼Ý200GBÊý¾Ýй¶£»PHP¹Ù·½Git´æ´¢¿âÔâµ½¹©Ó¦Á´¹¥»÷£¬´úÂë¿âÒѱ»¸Ä¶¯£»Õë¶ÔÓ¡¶ÈµÄAPT×éÖ¯RedEchoÒѹرÕÆäʹÓõĻù´¡ÉèÊ©£»VMwareÐÞ¸´vRealize OperationsÖеÄSSRFµÈ¶à¸ö©¶´¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Microsoft Azure SphereδǩÃû´úÂëÖ´ÐЩ¶´
Microsoft Azure Sphere´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27080
2.SAP Solution Manager User-Experience MonitoringÊÚȨ¼ì²éȱʧ©¶´
SAP Solution Manager User-Experience Monitoring´æÔÚÊÚȨ¼ì²éȷʵ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ¿ØÖÆϵͳ¡£
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=571343107
3.Adobe Creative Cloud Desktop ApplicationÈÎÒâÎļþдÈ멶´
Adobe Creative Cloud Desktop Application´æÔÚÈÎÒâÎļþдÈ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£
https://helpx.adobe.com/security/products/creative-cloud/apsb21-18.html
4.F5 BIG-IP Advanced WAF/ASM»º³åÇøÒç³ö©¶´
F5 BIG-IP Advanced WAF/ASM´¦ÖöñÒâHTTPÏìÓ¦´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.auscert.org.au/bulletins/ESB-2021.0872
5.Schneider Electric Interactive Graphical SCADA System CGFÎļþ½âÎöÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´
Schneider Electric Interactive Graphical SCADA System CGFÎļþ½âÎö´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-070-01
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢NPM¿âNetmask×é¼þ´æÔÚ©¶´£¬¿ÉÓ°ÏìÊýÍò¸öÓ¦Ó÷¨Ê½
¸Ã×é¼þÿÖÜÏÂÔØÁ¿Áè¼Ý300Íò´Î£¬½ØÖÁÏÖÔÚÀÛ¼ÆÏÂÔØÁ¿ÒÑÁè¼Ý2.38ÒڴΣ¬Ô¼ÓÐ27.8Íò¸öGitHub´æ´¢¿âÒÀÀµÓÚnetmask¡£¸Ã©¶´±»×·×ÙΪCVE-2021-28918£¬Ê®½øÖÆIPv4µØÖ·°üÂÞÇ°µ¼Áãʱ£¬ÍøÂçÑÚÂë´¦ÖûìºÏ¸ñʽIPµØÖ·µÄ·½Ê½¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓ°ÏìÓ¦Ó÷¨Ê½½âÎöµÄIPµØÖ·£¬Ôò¸Ã©¶´¿ÉÄÜ»áÒýÆðÖÖÖÖ©¶´£¬ÀýÈçµ¼Ö·þÎñÆ÷¶ËÇëÇóαÔ죨SSRF£©ºÍµ½Ô¶³ÌÎļþ°üÂÞ£¨RFI£©¡£Ä¿Ç°£¬¸Ã©¶´Òѱ»ÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-netmask-networking-bug-impacts-thousands-of-applications/
2¡¢Ó¢¹ú¹«Ë¾FatFaceѬȾConti£¬Áè¼Ý200GBÊý¾Ýй¶
Ó¢¹ú·þ×°¹«Ë¾FatFaceÔâµ½ContiÀÕË÷Èí¼þ¹¥»÷£¬Áè¼Ý200GBÊý¾Ýй¶¡£¹¥»÷·¢ÉúÔÚ2021Äê1ÔÂ17ÈÕ£¬¹¥»÷Õß·ÃÎÊÁËFatFaceµÄÍøÂçºÍϵͳ£¬²¢ÀÕË÷850ÍòÃÀÔª£¬×îÖվ̸ÅÐÊê½ðÈ·¶¨Îª200ÍòÃÀÔª¡£´Ë´Îй¶µÄ¿Í»§ÐÅÏ¢°üÂÞÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÓʼĵØÖ·ºÍ²¿ÃÅÐÅÓÿ¨ÐÅÏ¢£¨×îºóËÄλÊý×ÖºÍÓÐЧÆÚ£©¡£´ËÍ⣬¸Ã¹«Ë¾ÔÚÊý¾Ýй¶֪ͨÓʼþÖÐÒªÇóÆäÊÕ¼þÈËÎñ±Ø¶Ô´ËÓʼþ¼°ÆäÖаüÂÞµÄÐÅÏ¢Ñϸñ±£ÃÜ£¬ÒÔ´ËÊÔͼÑÚ¸ÇÊý¾Ý鶵ÄÊÂʵ£¬´ËʼþÔÚÍøÉÏÒýÆðÐùÈ»´ó²¨¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fatface-sends-controversial-data-breach-email-after-ransomware-attack/
3¡¢PHP¹Ù·½Git´æ´¢¿âÔâµ½¹©Ó¦Á´¹¥»÷£¬´úÂë¿âÒѱ»¸Ä¶¯
ÉÏÖÜÈÕ£¬Î¬»¤ÈËÔ±Rasmus Lerdorf·¢Ïֺڿ͹¥»÷ÁË·þÎñÆ÷git.php.net£¬²¢Ôڸ÷þÎñÆ÷µÄ×ÔÍйÜphp-src´æ´¢¿âÖÐÉÏ´«ÁË2¸öδ¾ÊÚȨµÄ¸üаü£¬ÆäÖеÄÔ´´úÂë±»²åÈëÁËÃØÃܺóÃÅ´úÂë¡£´ËÍ⣬ÕâЩ¶ñÒâ´úÂëÊÇÒÔPHP´´½¨ÕßRasmus LerdorfµÄÃûÒåÌá½»µÄ¡£Ñо¿ÈËÔ±ÍƲâ´Ë´ÎÊÇÃûΪÒÀÀµ»ìÏý£¨dependency confusion£©µÄÐÂÐ͹©Ó¦Á´¹¥»÷·½Ê½£¬ËüÀûÓÃÁËÒ»¸ö¿ÉÄÜ°üÂÞÀ´×Ô˽Óк͹«¹²À´Ô´µÄ»ìºÏÒÀÀµ¿âµÄÈí¼þ¡£×÷ΪԤ·À´ëÊ©£¬PHPά»¤ÈËÔ±ÒѾö¶¨½«¹Ù·½PHPÔ´´úÂë´æ´¢¿âǨÒƵ½GitHub¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/
4¡¢Õë¶ÔÓ¡¶ÈµÄAPT×éÖ¯RedEchoÒѹرÕÆäʹÓõĻù´¡ÉèÊ©
APT×éÖ¯RedEchoÔÚ2Ôµױ»Ñо¿ÈËÔ±Åû¶ºó£¬ÒѹرÕÆäʹÓõĻù´¡ÉèÊ©¡£Recorded FutureµÄÄþ¾²ÈËÔ±ÓÚ2Ô·¢ÏÖÁ˸ÃAPT×éÖ¯£¬³Æ¸ÃÍÅ»ï×Ô2020Äê³õ¹¥»÷ÁËÓ¡¶ÈµÄÖÁÉÙ10¸öµçÁ¦²¿ÃÅ£¬»¹½«Ä¿±êÃé×¼Á˸ßѹÊäµç±äµçÕ¾ºÍȼú»ðÁ¦·¢µç³§¡£Ôڸ÷¢ÏÖÐû²¼¼¸Öܺó£¬RedEchoÒѾ¹Ø±ÕÁ˲¿ÃÅÓÃÓÚ¿ØÖÆ°²×°ÔÚÄ¿±êÍøÂçÖеÄShadowPadºóÃŵĻù´¡ÉèÊ©¡£Ñо¿ÈËÔ±ÍƲ⣬¸ÃAPT×éÖ¯ÔÚ±»·¢ÏÖºó¿ÉÄܽ«ÆäC2תÒƵ½ÁËÆäËûµØ·½¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116094/apt/redecho-apt-c2-shutdown.html
5¡¢VMwareÐÞ¸´vRealize OperationsÖеÄSSRFµÈ¶à¸ö©¶´
VMwareÐû²¼Äþ¾²¸üУ¬ÒÔÐÞ¸´VMware vRealize OperationsÖеĶà¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖصÄ©¶´ÊÇvRealize Operations Manager APIÖеķþÎñÆ÷¶ËÇëÇóαÔ쩶´£¨CVE-2021-21975£©£¬CVSSv3ÆÀ·ÖΪ8.6£¬Ô¶³Ìδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÎÞÐèÓëÓû§½»»¥¼´¿ÉÀûÓôË©¶´À´ÇÔÈ¡¹ÜÀíƾ¾Ý¡£´ËÍ⣬»¹ÐÞ¸´ÁËÈÎÒâÎļþдÈ멶´£¨CVE-2021-21983£©£¬CVSSv3ÆÀ·ÖΪ7.2£¬¹¥»÷Õß¿ÉÀûÓÃÆäÔڵײã¹â×Ó²Ù×÷ϵͳµÄÈÎÒâλÖÃдÈëÎļþ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116145/security/vmware-vrealize-operations-ssrf-flaw.html