ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ35ÖÜ

°ä²¼¹¦·ò 2020-09-01

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê08ÔÂ24ÈÕÖÁ30ÈÕ¹²ÊÕ¼°²È«·ì϶55¸ö£¬ £¬ £¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇRed Lion N-TronδÃ÷½Ó¿Ú·ì϶ £»£»£»£»£»FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯·ì϶ £»£»£»£»£»Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´Ðзì϶ £»£»£»£»£»Foxit Studio Photo PSDÔ½½çд´úÂëÖ´Ðзì϶; Moog EXO Series EXVF5C-2ÖÎÀí½ÚÔį̀'statusbroadcast'ËÁÒâºÅÁîÖ´Ðзì϶¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇCisco°ä²¼°²È«¸üУ¬ £¬ £¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·Öеķì϶ £»£»£»£»£»Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨ £»£»£»£»£»Ó¡¶ÈÓÎÀÀÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶3700Íò±Ê¼Í¼ £»£»£»£»£»Î¢Èí½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶ £»£»£»£»£»CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬ £¬ £¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£


³ÁÒª°²È«·ì϶Áбí


1.Red Lion N-TronδÃ÷½Ó¿Ú·ì϶


Red Lion N-Tron´æÔÚδÎĵµ»¯½Ó¿Ú·ì϶£¬ £¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬ £¬£¬£¬£¬£¬ÒÔROOTȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-240-01


2. FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯·ì϶


FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource´æÔÚÐòÁл¯·ì϶£¬ £¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬ £¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://github.com/FasterXML/jackson-databind/issues/2814


3. Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´Ðзì϶


Advantech iView DeviceTreeTable exportTaskMgrReport´æÔÚĿ¼±éÀú·ì϶£¬ £¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬ £¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎĶÁȡϵͳÎļþ»òÕßÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1084/


4. Foxit Studio Photo PSDÔ½½çд´úÂëÖ´Ðзì϶


Foxit Studio Photo½âÎöPSDÎļþ´æÔÚÔ½½çд·ì϶£¬ £¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ £¬ £¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬ £¬ £¬£¬£¬£¬£¬Äܹ»ÏµÍ³¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1078/


5. Moog EXO Series EXVF5C-2ÖÎÀí½ÚÔį̀'statusbroadcast'ËÁÒâºÅÁîÖ´Ðзì϶


Moog EXO Series EXVF5C-2ÖÎÀí½ÚÔį̀'statusbroadcast'´æÔÚ°²È«·ì϶£¬ £¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬ £¬£¬£¬£¬£¬Ê¹ÓÃ'${IFS}'±äÁ¿ÈƹýÏÞ¶È£¬ £¬ £¬£¬£¬£¬£¬Äܹ»rootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£

https://ioactive.com/moog-exo-series-multiple-vulnerabilities/



> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Cisco°ä²¼°²È«¸üУ¬ £¬ £¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·Öеķì϶


1.png


Cisco°ä²¼°²È«¸üУ¬ £¬ £¬£¬£¬£¬£¬ÒÔ½¨¸´Æä¶à¸ö²úÆ·Öеķì϶¡£¡£¡£¡£¡£Õâ´Î°²È«¸üÐÂÖн¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪTreck IP²Ö¿âÖеķì϶Ripple20£¬ £¬ £¬£¬£¬£¬£¬ÕâЩ·ì϶¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢»Ø¾ø·þÎñ£¨DoS£©»òÐÅϢй¶ £»£»£»£»£»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏÍ´´¦·ì϶£¨CVE-2020-3446£©£¬ £¬ £¬£¬£¬£¬£¬¿É±»ÀûÓÃÒÔÖÎÀíԱȨÏÞ½Ó¼ûNFVIS CLI £»£»£»£»£»Ë¼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM On-Prem£©±¾µØÌØÈ¨Éý¼¶·ì϶£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢ÏÖºÍ̸Զ³ÌÖ´Ðкͻؾø·þÎñ·ì϶£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates


2¡¢Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨


2.png


¹¤ÒµÍøÂ簲ȫ¹«Ë¾Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨¡£¡£¡£¡£¡£Claroty·ÖÎöÁËÐÂÔö³¤µ½¹ú¶È·ì϶Êý¾Ý¿â£¨NVD£©ÖеÄ365¸öICS·ì϶ÒÔ¼°ICS-CERT£¨CISA£©°ä²¼µÄ´«µÝÖк­¸ÇµÄ385¸ö·ì϶¡£¡£¡£¡£¡£Óë2019ÄêͬÆÚÅû¶µÄ·ì϶ÊýÁ¿Ïà±È£¬ £¬ £¬£¬£¬£¬£¬2020ÄêÉϰëÄêÐÂÔöµ½NVDÖеķì϶ÊýÁ¿Ô¼Äª¶à³ö10£¥¡£¡£¡£¡£¡£ÔÚËùʶ´ËÍâ·ì϶ÖУ¬ £¬ £¬£¬£¬£¬£¬ÓÐ70£¥ÒÔÉϵķì϶¿É±»Ô¶³ÌÀûÓ㬠£¬ £¬£¬£¬£¬£¬Óн«½üÒ»°ë¿ÉÓÃÓÚÔ¶³ÌÖ´ÐдúÂ룬 £¬ £¬£¬£¬£¬£¬ÆäÖÐ41£¥µÄ·ì϶¿ÉÈù¥»÷Õß¶ÁÈ¡ÀûÓ÷¨Ê½Êý¾Ý£¬ £¬ £¬£¬£¬£¬£¬39£¥µÄ·ì϶¿ÉÓÃÓÚDoS¹¥»÷£¬ £¬ £¬£¬£¬£¬£¬37£¥µÄ·ì϶¿ÉÈÆ¹ý°²È«»úÔì¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/over-70-ics-vulnerabilities-disclosed-first-half-2020-remotely-exploitable


3¡¢Ó¡¶ÈÓÎÀÀÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶3700Íò±Ê¼Í¼


3.png


SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢ÏÖÁËRailYatriµÄûÓÐÃÜÂë± £»£»£»£»£»¤µÄElasticsearch·þÎñÆ÷£¬ £¬ £¬£¬£¬£¬£¬Ð¹Â¶3700Íò±Ê¼Í¼¿Í»§ºÍ¹«Ë¾Êý¾Ý£¬ £¬ £¬£¬£¬£¬£¬Ô̺¬Óû§µÄÈ«Ãû¡¢´ºÇï¡¢ÐÔ±ð¡¢ÏÖʵºÍµç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂë¡¢Ô¤Ô¼¾ßÌåÐÅÏ¢¡¢GPSµØÎ»ÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄǰËÄλºÍºóËÄλ¡£¡£¡£¡£¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý½øÐб £»£»£»£»£»¤Ö®Ç°£¬ £¬ £¬£¬£¬£¬£¬Meow»úеÈËÓÚ8ÔÂ12ÈÕ¶ÔÆä²úÉú¹¥»÷£¬ £¬ £¬£¬£¬£¬£¬É¾³ýÁ˳ý1GBÖ®±íµÄËùº±¼û¾Ý£¨×ܹ²43 GB£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/


4¡¢Î¢Èí½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶


4.png


΢Èí°ä²¼·ì϶²¹¶¡£¡£¡£¡£¡£¬ £¬ £¬£¬£¬£¬£¬½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶¡£¡£¡£¡£¡£Õâ´Î°ä²¼µÄ²¹¶¡·¨Ê½½¨¸´ÁË2¸öÔ¶³Ì´úÂëÖ´Ðзì϶ºÍ2¸öÌáȨ·ì϶£¬ £¬ £¬£¬£¬£¬£¬ÕâЩ·ì϶¶¼ÊÇÓÉCisco TalosµÄ°²È«×êÑÐÈËÔ±ÓÚ7Ô·ݷ¢ÏÖ¡£¡£¡£¡£¡£µÚÒ»¸öΪREAD_IMPLIES_EXEC personalityδÊðÃû´úÂëÖ´Ðзì϶£¬ £¬ £¬£¬£¬£¬£¬µÚ¶þ¸öRCE·ì϶´æÔÚÓÚ/proc/thread-self/ memÖС£¡£¡£¡£¡£´Ë±í£¬ £¬ £¬£¬£¬£¬£¬È¨ÏÞ½Ó¼û½ÚÔìÖ°ÄÜÖдæÔÚÒ»¸öÌáȨ·ì϶£¬ £¬ £¬£¬£¬£¬£¬¶øµÚ¶þ¸öÌáȨ·ì϶´æÔÚÓÚAzure Sphere 20.06µÄuid_mapÖ°ÄÜÖС£¡£¡£¡£¡£Î¢Èí°µÊ¾»áÈ·±£½â¾öÕâЩÎÊÌⲢΪ¿Í»§Ìṩ¸üУ¬ £¬ £¬£¬£¬£¬£¬µ«Êǻؾø°ä²¼ÈκÎCVEs¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/four-more-bugs-patched-in-microsofts-azure-sphere-iot-platform/158643/


5¡¢CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú


5.png


˼¿ÆÇ°Ô±¹¤Sudhish Kasaba RameshÈÏ×ïÆäɾ³ýÁËWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú¡£¡£¡£¡£¡£¾ÝÆäÈÏ×ïºÍ̸Öгƣ¬ £¬ £¬£¬£¬£¬£¬ÆäÈÏ¿ÉÔÚÈ¥Ö°5¸öÔºóµÄ2018Äê9ÔÂ24ÈÕ£¬ £¬ £¬£¬£¬£¬£¬Î´¾­¹«Ë¾µÄÐí¿ÉÓÐÒâ½Ó¼û˼¿ÆµÄÔÆ»ù´¡¼Ü¹¹£¬ £¬ £¬£¬£¬£¬£¬²¢´ÓÆä×Ô¼ºµÄGoogle Cloud ProjectÕÊ»§Öв¿ÊðÁËÒ»¸ö´úÂ룬 £¬ £¬£¬£¬£¬£¬É¾³ýÁË˼¿ÆWebEx TeamsÀûÓ÷¨Ê½µÄ456¸öÐé¹¹»ú¡£¡£¡£¡£¡£¾ÝϤ£¬ £¬ £¬£¬£¬£¬£¬¸ÃÊÂÎñµ¼ÖÂ16000¸öWebEx TeamsÕÊ»§±»¹Ø¹ØÁ˳¤´ïÁ½¸öÐÇÆÚ£¬ £¬ £¬£¬£¬£¬£¬CiscoÆÆ·ÑÁËԼĪ140ÍòÃÀÔªÀ´¸´Ô­ÆäÀûÓÃÊܵ½µÄÇÖº¦£¬ £¬ £¬£¬£¬£¬£¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§ÍË»¹Á˳¬¹ý100ÍòÃÀÔªµÄ¿î×Ó¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/ex-cisco-employee-pleads-guilty-to-deleting-16k-webex-teams-accounts/158748/