ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ15ÖÜ

°ä²¼¹¦·ò 2021-04-13

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê04ÔÂ05ÈÕÖÁ04ÔÂ11ÈÕ¹²ÊÕ¼°²È«·ì϶41¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414ËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉý·ì϶£»£»£»£»£»£»OpenIAM Groovy Script´úÂëÖ´Ðзì϶£»£»£»£»£»£»SonicWall GMSÔ¶³ÌȨÏÞÌáÉý·ì϶£»£»£»£»£»£»Skyworth Digital Technology RN510»º³åÇøÒç¶Âí½Å¡£ ¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇTIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»£»£»£»£»£»KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯£»£»£»£»£»£»ÐÂ¼ÓÆÂ¹¤»áe2iÔâµ½´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢£»£»£»£»£»£»Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÊÂÎñÈÔÔÚµ÷²éÖУ»£»£»£»£»£»ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÒøÐÐľÂíJaneleiro¡£ ¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£ ¡£¡£¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.Cisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414ËÁÒâ´úÂëÖ´Ðзì϶


CCisco RV345P Dual WAN Gigabit VPN Routers WEBÖÎÀí½Ó¿Ú´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÌáÉýȨÏÞ¡£ ¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b


2.LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉý·ì϶


LiteSpeed Technologies OpenLiteSpeed web server´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÖ÷»úÉÏÖ´ÐÐËÁÒâºÅÁî¡£ ¡£¡£¡£¡£

https://github.com/litespeedtech/openlitespeed/issues/217


3.OpenIAM Groovy Script´úÂëÖ´Ðзì϶


OpenIAM Groovy Script´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£

https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md


4.SonicWall GMSÔ¶³ÌȨÏÞÌáÉý·ì϶


SonicWall GMS´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ROOTȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0009


5.Skyworth Digital Technology RN510»º³åÇøÒç¶Âí½Å


Skyworth Digital Technology RN510 /cgi-bin/app-staticIP.asp»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£

https://s3curityb3ast.github.io/KSA-Dev-011.md


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day


1.jpg


CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרһÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°É¢²¼Ê½ÍÆËã¡¢ÔÆÍÆËã¡¢DevOpsºÍÍÆËã»ú°²È«Èí¼þÒÔ¼°Òƶ¯É豸¡£ ¡£¡£¡£¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öзì϶¡£ ¡£¡£¡£¡£±ðÀëΪÌáȨ·ì϶£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ·ì϶£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤·ì϶£¨CVE-2021-28248£©¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html


2¡¢KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯


2.jpg


KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½Äϵ±¾ÖºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯¡£ ¡£¡£¡£¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬¿É½øÐÐÎļþϵͳ°Ñ³Ö¡¢¹ý³Ì°Ñ³Ö¡¢ÆÁÄ»½ØÍ¼²¶»ñºÍËÁÒâºÅÁîÖ´ÐС£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚ¸´ÔÓÐÔ·½Ãæ»ñµÃÁ˳ÁÃͽøÈ¡£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬£¬£¬£¬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÖ¸±êºÍÔ´£©±»ÆëÈ«°þÀ룬£¬£¬£¬£¬£¬£¬£¬Ê£ÏµÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ó´óÔö³¤ÁË×êÑÐÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄѶÈ¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spy-operations-vietnam-rat/165243/


3¡¢ÐÂ¼ÓÆÂ¹¤»áe2iÔâµ½´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢


3.jpg


ÐÂ¼ÓÆÂÈ«¹ú¹¤»á´ú±í´ó»á¾ÍÒµÓë¾ÍÒµ×êÑÐËù£¨e2i£©ÔÚ±¾ÖÜÒ»£¨4ÔÂ5ÈÕ£©°ä²¼ÉêÃ÷³Æ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÒѾ­½Ó¼ûÆäÓû§µÄÓ×ÎÒÐÅÏ¢¡£ ¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Óû§µÄÐÕÃû¡¢½ÌÓý×ʸñºÍNRIC¡¢ÁªÏµ·½Ê½ºÍ¾Íҵϸ½ÚµÈ¡£ ¡£¡£¡£¡£ÊÂÎñ²úÉúÔÚ3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÆäµÚÈý·½¹©¸øÉÌ¡ª¡ªÁªÏµÖÐÐÄ·þÎñ¹«Ë¾i-vic InternationalÔ±¹¤µÄÓÊÏäÔâµ½´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÓÊÏäµÄÔÆ¶ËÔ̺¬ÁËÔ¼3Íò¸ö²ÎÓëÁËe2i»î¶¯µÄÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬µ«ÊǸûú¹¹»Ø¾øÐ¹Â©×ܹ²Óм¸¶àÈËÔøÊ¹Óùýe2iµÄ·þÎñ¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.straitstimes.com/tech/tech-news/personal-data-of-30000-people-who-use-ntucs-e2i-services-may-have-been-breached


4¡¢Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÊÂÎñÈÔÔÚµ÷²éÖÐ


4.jpg


Å·ÃËίԱ»á½²»°È˳ƣ¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Î¯Ô±»áÔÚÄڵĶà¸öÅ·ÃË×éÖ¯ÔÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷¡£ ¡£¡£¡£¡£´Ë¿Ì¶Ô¸ÃÊÂÎñµÄȡ֤·ÖÎöÈÔ´¦ÓÚ³õÆÚ½×¶Î£¬£¬£¬£¬£¬£¬£¬£¬ÉÐδ¼ì²âµ½´æÔÚÐÅϢй¶ÎÊÌâ¡£ ¡£¡£¡£¡£Åí²©É簵ʾ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñ±ÈÅ·ÃËÒÔÍùÔâµ½µÄ¹¥»÷¸üΪÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬Å·ÃËij¹ÙÔ±»¹Ð¹Â©£¬£¬£¬£¬£¬£¬£¬£¬Æä¹¤×÷ÈËÔ±½üÆÚÊÕµ½ÁËÓйØÕë¶ÔÅ·Ã˵Ĵ¹µö¹¥»÷Ô¤¾¯¡£ ¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬Å·ÃËÈÔδ¹«¿ªÓйØÕâ´ÎÊÂÎñµÄÐÔÖÊ»òÆä±³ºóµÄ¹¥»÷ÕßÉí·ÝµÄÐÅÏ¢¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-04-06/european-institutions-were-targeted-in-a-cyber-attack-last-week


5¡¢ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÒøÐÐľÂíJaneleiro


5.jpg


ESETµÄ×êÑÐÈËÔ±Åû¶ÁËÕë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÐÍÒøÐÐľÂíJaneleiro¡£ ¡£¡£¡£¡£¸ÃľÂíÖÁÉÙ´Ó2019ÄêÒÔÀ´¾ÍÆðÍ·Õë¶Ô°ÍÎ÷µÄÆóÒµ£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°¹¤³Ì¡¢Ò½ÁƱ£½¡¡¢ÁãÊÛ¡¢Ôì×÷Òµ¡¢½ðÈÚ¡¢ÔËÊäºÍµ±¾ÖµÈ¸÷¸öÁìÓò¡£ ¡£¡£¡£¡£Janeleiroͨ¹ýαÔì´óÐÍÒøÐÐÍøÕ¾£¨SantanderºÍBanco do BrasilµÈ£©µÄµ¯´°À´ÒýÓÕÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩµ¯´°Ô̺¬ÐéαµÄ±í¸ñÀ´ÓÕʹָ±êÊäÈëÒøÐÐÆ¾Ö¤ºÍÓ×ÎÒÐÅÏ¢¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬JaneleiroÊÇÓÉVisual Basic .NET±àдµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÓë¸ÃµØÓòµÄºÚ¿ÍËùϲ»¶µÄDelphiÓкܴóµÄ³öÈë¡£ ¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/experts-uncover-new-banking-trojan.html