ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ15ÖÜ

Ðû²¼Ê±¼ä 2021-04-13

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê04ÔÂ05ÈÕÖÁ04ÔÂ11ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´41¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414ÈÎÒâ´úÂëÖ´ÐЩ¶´ £»LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉý©¶´ £»OpenIAM Groovy Script´úÂëÖ´ÐЩ¶´ £»SonicWall GMSÔ¶³ÌȨÏÞÌáÉý©¶´ £»Skyworth Digital Technology RN510»º³åÇøÒç³ö©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇTIMÍŶÓÅû¶CA Technologies²úÎïÖеĶà¸ö0day £»KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯ £»Ð¼Óƹ¤»áe2iÔâµ½µöÓã¹¥»÷£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢ £»Å·Ã˳ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬Ê¼þÈÔÔÚÊÓ²ìÖÐ £»ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÒøÐÐľÂíJaneleiro¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Cisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414ÈÎÒâ´úÂëÖ´ÐЩ¶´


CCisco RV345P Dual WAN Gigabit VPN Routers WEB¹ÜÀí½Ó¿Ú´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÌáÉýȨÏÞ¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b


2.LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉý©¶´


LiteSpeed Technologies OpenLiteSpeed web server´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÔÚÖ÷»úÉÏÖ´ÐÐÈÎÒâÃüÁî¡£

https://github.com/litespeedtech/openlitespeed/issues/217


3.OpenIAM Groovy Script´úÂëÖ´ÐЩ¶´


OpenIAM Groovy Script´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md


4.SonicWall GMSÔ¶³ÌȨÏÞÌáÉý©¶´


SonicWall GMS´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTȨÏÞÖ´ÐÐÈÎÒâ´úÂë¡£

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0009


5.Skyworth Digital Technology RN510»º³åÇøÒç³ö©¶´


Skyworth Digital Technology RN510 /cgi-bin/app-staticIP.asp»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://s3curityb3ast.github.io/KSA-Dev-011.md


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢TIMÍŶÓÅû¶CA Technologies²úÎïÖеĶà¸ö0day


1.jpg


CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרעÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬ÏúÊÛ½ü200ÖÖ²úÎÉæ¼°ÂþÑÜʽ¼ÆËã¡¢ÔƼÆËã¡¢DevOpsºÍ¼ÆËã»úÄþ¾²Èí¼þÒÔ¼°Òƶ¯É豸¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÎïÖеÄ5¸öЩ¶´¡£·Ö±ðΪÌáȨ©¶´£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã½Å±¾Â©¶´£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ©¶´£¨CVE-2021-28250£©ºÍÉí·ÝÑé֤©¶´£¨CVE-2021-28248£©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html


2¡¢KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯


2.jpg


KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½ÄÏÕþ¸®ºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬¿É½øÐÐÎļþϵͳÀûÓᢽø³ÌÀûÓá¢ÆÁÄ»½Øͼ²¶×½ºÍÈÎÒâÃüÁîÖ´ÐС£´ËÍ⣬Kaspersky³Æ¸Ã×éÖ¯ÔÚÅÓ´óÐÔ·½ÃæÈ¡µÃÁËÖØ´ó½ø²½£¬ÀýÈ磬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÄ¿±êºÍÔ´£©±»ÍêÈ«°þÀ룬ʣϵÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ£¬Õâ´ó´óÔö¼ÓÁËÑо¿ÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄѶÈ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spy-operations-vietnam-rat/165243/


3¡¢Ð¼Óƹ¤»áe2iÔâµ½µöÓã¹¥»÷£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢


3.jpg


мÓÆÂÈ«¹ú¹¤»á´ú±í´ó»á¾ÍÒµÓë¾ÍÒµÑо¿Ëù£¨e2i£©ÔÚ±¾ÖÜÒ»£¨4ÔÂ5ÈÕ£©Ðû²¼ÉùÃ÷³Æ£¬¹¥»÷Õß¿ÉÄÜÒѾ­·ÃÎÊÆäÓû§µÄ¸öÈËÐÅÏ¢¡£´Ë´Î鶵ÄÐÅÏ¢°üÂÞÓû§µÄÐÕÃû¡¢½ÌÓý×ʸñºÍNRIC¡¢ÁªÏµ·½Ê½ºÍ¾Íҵϸ½ÚµÈ¡£Ê¼þ·¢ÉúÔÚ3ÔÂ12ÈÕ£¬ÆäµÚÈý·½¹©Ó¦ÉÌ¡ª¡ªÁªÂçÖÐÐÄ·þÎñ¹«Ë¾i-vic InternationalÔ±¹¤µÄÓÊÏäÔâµ½µöÓã¹¥»÷£¬¸ÃÓÊÏäµÄÔƶ˰üÂÞÁËÔ¼3Íò¸ö¼ÓÈëÁËe2i»î¶¯µÄÓû§ÐÅÏ¢£¬µ«ÊǸûú¹¹¾Ü¾ø͸¶×ܹ²Óм¸¶àÈËÔøʹÓùýe2iµÄ·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.straitstimes.com/tech/tech-news/personal-data-of-30000-people-who-use-ntucs-e2i-services-may-have-been-breached


4¡¢Å·Ã˳ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬Ê¼þÈÔÔÚÊÓ²ìÖÐ


4.jpg


Å·ÃËίԱ»á·¢ÑÔÈ˳Æ£¬°üÂÞίԱ»áÔÚÄڵĶà¸öÅ·ÃË×éÖ¯ÔÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷¡£ÏÖÔÚ¶Ô¸ÃʼþµÄÈ¡Ö¤·ÖÎöÈÔ´¦ÓÚ³õÆڽ׶Σ¬ÉÐδ¼ì²âµ½´æÔÚÐÅϢй¶ÎÊÌâ¡£Åí²©ÉçÌåÏÖ£¬´Ë´Îʼþ±ÈÅ·ÃËÒÔÍùÔâµ½µÄ¹¥»÷¸üΪÑÏÖØ£¬Å·ÃËij¹ÙÔ±»¹Í¸Â¶£¬ÆäÊÂÇéÈËÔ±½üÆÚÊÕµ½ÁËÓйØÕë¶ÔÅ·Ã˵ĵöÓã¹¥»÷Ô¤¾¯¡£Ä¿Ç°£¬Å·ÃËÈÔδ¹ûÈ»Óйش˴ÎʼþµÄÐÔÖÊ»òÆä±³ºóµÄ¹¥»÷ÕßÉí·ÝµÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-04-06/european-institutions-were-targeted-in-a-cyber-attack-last-week


5¡¢ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÒøÐÐľÂíJaneleiro


5.jpg


ESETµÄÑо¿ÈËÔ±Åû¶ÁËÕë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÐÍÒøÐÐľÂíJaneleiro¡£¸ÃľÂíÖÁÉÙ´Ó2019ÄêÒÔÀ´¾Í¿ªÊ¼Õë¶Ô°ÍÎ÷µÄÆóÒµ£¬Éæ¼°¹¤³Ì¡¢Ò½ÁƱ£½¡¡¢ÁãÊÛ¡¢ÖÆÔìÒµ¡¢½ðÈÚ¡¢ÔËÊäºÍÕþ¸®µÈ¸÷¸öÁìÓò¡£Janeleiroͨ¹ýαÔì´óÐÍÒøÐÐÍøÕ¾£¨SantanderºÍBanco do BrasilµÈ£©µÄµ¯´°À´ÓÕ»óÄ¿±ê£¬ÕâЩµ¯´°°üÂÞÐé¼ÙµÄ±í¸ñÀ´ÓÕʹĿ±êÊäÈëÒøÐÐƾ֤ºÍ¸öÈËÐÅÏ¢¡£´ËÍ⣬JaneleiroÊÇÓÉVisual Basic .NET±àдµÄ£¬ÕâÓë¸ÃµØÓòµÄºÚ¿ÍËùϲ»¶µÄDelphiÓкܴóµÄÊÕÖ§¡£    


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/experts-uncover-new-banking-trojan.html