ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ24ÖÜ

°ä²¼¹¦·ò 2020-06-15

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê06ÔÂ08ÈÕÖÁ06ÔÂ14ÈÕ¹²ÊÕ¼°²È«·ì϶68¸ö £¬£¬£¬ £¬ £¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Server Message Block CVE-2020-1301´úÂëÖ´Ðзì϶; WAGO PFC 200 Web-Based Management´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Advantech WebAccess Node»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£»£»SAP Solution ManagerδÊÚȨ½Ó¼û·ì϶£»£»£»£»£»£»£»£»Siemens LOGO!8 BMδÊÚȨ½Ó¼û·ì϶¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇαÔìµÄÀÕË÷Èí¼þSTOP DjvuµÄ½âÃÜÆ÷¶ÔÊܺ¦ÕßÎļþ¶þ´Î¼ÓÃÜ£»£»£»£»£»£»£»£»Area1°ä²¼»ã±¨ £¬£¬£¬ £¬ £¬¶íÂÞ˹ͨ¹ýExim´úÀí(MTA)Öзì϶×ÌÈÅÃÀ¹ú´óÑ¡£¡£¡£¡£¡£»£»£»£»£»£»£»£»Î¢Èí°ä²¼×î´ó¹æÄ£µÄÖܶþ²¹¶¡·¨Ê½ £¬£¬£¬ £¬ £¬¹²½¨¸´129¸ö·ì϶£»£»£»£»£»£»£»£»Adobe½¨¸´ÁËFlash PlayerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»ÈÎÌìÌÃÈ·ÈÏÆä³¬¹ý30ÍòÕ˺ű»ÈëÇÖ £¬£¬£¬ £¬ £¬Ä¿Ç°¹úÐÐδÊÜÓ°Ïì¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬£¬£¬ £¬ £¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£



>³ÁÒª°²È«·ì϶Áбí


1.Microsoft Windows Server Message Block CVE-2020-1301´úÂëÖ´Ðзì϶


Microsoft Windows Server Message Block 1.0´¦ÖÃijЩҪÇó´æÔÚ°²È«·ì϶ £¬£¬£¬ £¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬ £¬ £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»ò¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1301


2. WAGO PFC 200 Web-Based Management´úÂëÖ´Ðзì϶


WAGO PFC 200 Web-Based Management´æÔÚ°²È«·ì϶ £¬£¬£¬ £¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬ £¬ £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://talosintelligence.com/vulnerability_reports/TALOS-2020-101


3. Advantech WebAccess Node»º³åÇøÒç¶Âí½Å


Advantech WebAccess Node´æÔÚ»º³åÇøÒç¶Âí½Å £¬£¬£¬ £¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬ £¬ £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://www.us-cert.gov/ics/advisories/icsa-20-161-01


4. SAP Solution ManagerδÊÚȨ½Ó¼û·ì϶


SAP Solution Manager Problem Context ManagerûÓÐÖ´ÐÐÑéÖ¤·ì϶ £¬£¬£¬ £¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬ £¬ £¬¿ÉδÊÚȨ½Ó¼û»ò½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775


5. Siemens LOGO!8 BMδÊÚȨ½Ó¼û·ì϶


Siemens LOGO!8 BM¶ÌȱÉí·ÝÖ¤ÑéÖ¤ £¬£¬£¬ £¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ïò135¶Ë¿ÚÌá½»ÒªÇó £¬£¬£¬ £¬ £¬¿É¶ÁÈ¡ºÍÅú¸ÄÉ豸ÅäÖò¢´ÓÉ豸ÖлñÈ¡ÏîÄ¿Îļþ¡£¡£¡£¡£¡£

https://cert-portal.siemens.com/productcert/pdf/ssa-817401.pdf



> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Î±ÔìµÄÀÕË÷Èí¼þSTOP DjvuµÄ½âÃÜÆ÷¶ÔÊܺ¦ÕßÎļþ¶þ´Î¼ÓÃÜ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-ransomware-decryptor-double-encrypts-desperate-victims-files/


2¡¢Area1°ä²¼»ã±¨ £¬£¬£¬ £¬ £¬¶íÂÞ˹ͨ¹ýExim´úÀí(MTA)Öзì϶×ÌÈÅÃÀ¹ú´óÑ¡


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://cdn.area1security.com/reports/Area-1-Security-EximReport.pdf


3¡¢Î¢Èí°ä²¼×î´ó¹æÄ£µÄÖܶþ²¹¶¡·¨Ê½ £¬£¬£¬ £¬ £¬¹²½¨¸´129¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2020-patch-tuesday-largest-ever-with-129-fixes/


4¡¢Adobe½¨¸´ÁËFlash PlayerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-remote-code-execution-bug-in-flash-player/


5¡¢ÈÎÌìÌÃÈ·ÈÏÆä³¬¹ý30ÍòÕ˺ű»ÈëÇÖ £¬£¬£¬ £¬ £¬Ä¿Ç°¹úÐÐδÊÜÓ°Ïì


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/nintendo-breach-now-300000/