¶à¿îÎÞÏßͶӰϵͳÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-05-06

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-3929£¬ £¬£¬£¬ £¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬ £¬£¬£¬ £¬ £¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2019-3930£¬ £¬£¬£¬ £¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬ £¬£¬£¬ £¬ £¬£¬CVSS·ÖÖµ£º9.8 



Ó°Ïì°æ±¾¼°²úÆ·



Crestron AM-100 1.6.0.2
Crestron AM-101 2.7.0.1
Barco wePresent WiPG-1000P 2.3.0.10
Barco wePresent WiPG-1600W before 2.4.1.19 
Extron ShareLink 200/250 2.0.3.4 
Teq AV IT WIPS710 1.1.0.7 
InFocus LiteShow3 1.0.16 
InFocus LiteShow4 2.0.0.7 
Optoma WPS-Pro 1.0.0.5 
Blackbox HD WPS 1.0.0.5

SHARP PN-L703WA 1.4.2.3



·ì϶¸ÅÊö



ÎÞÏßÑÝʾϵͳÔÊÐíÓû§Í¨¹ý×°ÖõÄÀûÓ÷¨Ê½»òWebä¯ÀÀÆ÷½«ÆäÉ豸Ïνӵ½ÏµÍ³£¬ £¬£¬£¬ £¬ £¬£¬´Ó¶øÖ±½Ó´ÓÆä±Ê¼Ç±¾µçÄÔÏÔʾÆäÄÚÈÝ¡£ ¡£¡£¡£¡£ ¡£¡£


TenableµÄ×êÑÐÈËÔ±Åû¶ÁËÁ½¸ö·ì϶CVE-2019-3929ºÍCVE-2019-3930£¬ £¬£¬£¬ £¬ £¬£¬Ó°ÏìÁËһϵÁÐÑÝʾƽ̨ϵͳ£ºÔ̺¬Crestron£¬ £¬£¬£¬ £¬ £¬£¬Barco wePresent£¬ £¬£¬£¬ £¬ £¬£¬Extron ShareLink£¬ £¬£¬£¬ £¬ £¬£¬InFocus LiteShow£¬ £¬£¬£¬ £¬ £¬£¬TEQ AV IT WIPS710£¬ £¬£¬£¬ £¬ £¬£¬SHARP PN-L703WA£¬ £¬£¬£¬ £¬ £¬£¬ Optoma WPS-Pro£¬ £¬£¬£¬ £¬ £¬£¬Blackbox HD WPS¡£ ¡£¡£¡£¡£ ¡£¡£ÕâÊÇÓÉÓÚËùÓа˸öÆ·ÅÆ¹²ÏíÒ»ÑùµÄ»ù´¡´úÂë¡£ ¡£¡£¡£¡£ ¡£¡£


CVE-2019-3929

δ¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌºÅÁî×¢Èë·ì϶£¬ £¬£¬£¬ £¬ £¬£¬Äܹ»Ê¹Ô¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòHTTP¶Ëµãfile_transfer.cgi·¢Ë;«ÐÄÉè¼ÆµÄÒªÇóÀ´Ö´ÐвÙ×÷ϵͳºÅÁî¡£ ¡£¡£¡£¡£ ¡£¡£


CVE-2019-3930

δ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì²Ö¿â»º³åÇøÒç¶Âí½Å£¬ £¬£¬£¬ £¬ £¬£¬Ëü´æÔÚÓÚÃûΪPARSERtoCHARµÄÉ豸µÄÖ°ÄÜÖУ¬ £¬£¬£¬ £¬ £¬£¬Í¨¹ýHTTP·¢ËͲ»»á¶ÔCGI¾ç±¾½øÐÐÉí·ÝÑéÖ¤¡£ ¡£¡£¡£¡£ ¡£¡£ÕâÒâζ×ÅÔ¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý¶Ôreturn.cgi¶ËµãµÄ¾«ÐÄÉè¼ÆÒªÇóÀ´ÀÄÓ÷ì϶À´Ö´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£ ¡£¡£



·ì϶ÑéÖ¤



EXP£ºhttps://www.exploit-db.com/exploits/46786¡£ ¡£¡£¡£¡£ ¡£¡£



½¨¸´½¨Òé



Crestron°ä²¼ÁË·ì϶½¨¸´·¨Ê½£º

https://www.crestron.com/en-US/Security/Security_Advisories¡£ ¡£¡£¡£¡£ ¡£¡£


Barco¸üй̼þ£º
https://www.barco.com/en/support/software/R33050103?majorVersion=2&minorVersion=3&patchVersion=2&buildVersion=20

https://www.barco.com/en/support/software/R33050104?majorVersion=2&minorVersion=4&patchVersion=1&buildVersion=19


Extron¸üй̼þ£º

https://www.extron.com/download/software.aspx?filehandle=sharelink200&material=44&type=archive



²Î¿¼Á´½Ó
https://threatpost.com/bugs-wireless-presentation-systems/144318/