¶à¿îÎÞÏßͶӰϵͳÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-05-06

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-3929£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2019-3930£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8 



Ó°Ïì°æ±¾¼°²úÆ·



Crestron AM-100 1.6.0.2
Crestron AM-101 2.7.0.1
Barco wePresent WiPG-1000P 2.3.0.10
Barco wePresent WiPG-1600W before 2.4.1.19 
Extron ShareLink 200/250 2.0.3.4 
Teq AV IT WIPS710 1.1.0.7 
InFocus LiteShow3 1.0.16 
InFocus LiteShow4 2.0.0.7 
Optoma WPS-Pro 1.0.0.5 
Blackbox HD WPS 1.0.0.5

SHARP PN-L703WA 1.4.2.3



·ì϶¸ÅÊö



ÎÞÏßÑÝʾϵͳÔÊÐíÓû§Í¨¹ý×°ÖõÄÀûÓ÷¨Ê½»òWebä¯ÀÀÆ÷½«ÆäÉ豸Ïνӵ½ÏµÍ³£¬´Ó¶øÖ±½Ó´ÓÆä±Ê¼Ç±¾µçÄÔÏÔʾÆäÄÚÈÝ¡£


TenableµÄ×êÑÐÈËÔ±Åû¶ÁËÁ½¸ö·ì϶CVE-2019-3929ºÍCVE-2019-3930£¬Ó°ÏìÁËһϵÁÐÑÝʾƽ̨ϵͳ£ºÔ̺¬Crestron£¬Barco wePresent£¬Extron ShareLink£¬InFocus LiteShow£¬TEQ AV IT WIPS710£¬SHARP PN-L703WA£¬ Optoma WPS-Pro£¬Blackbox HD WPS¡£ÕâÊÇÓÉÓÚËùÓа˸öÆ·ÅÆ¹²ÏíÒ»ÑùµÄ»ù´¡´úÂë¡£


CVE-2019-3929

δ¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌºÅÁî×¢Èë·ì϶£¬Äܹ»Ê¹Ô¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòHTTP¶Ëµãfile_transfer.cgi·¢Ë;«ÐÄÉè¼ÆµÄÒªÇóÀ´Ö´ÐвÙ×÷ϵͳºÅÁî¡£


CVE-2019-3930

δ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì²Ö¿â»º³åÇøÒç¶Âí½Å£¬Ëü´æÔÚÓÚÃûΪPARSERtoCHARµÄÉ豸µÄÖ°ÄÜÖУ¬Í¨¹ýHTTP·¢ËͲ»»á¶ÔCGI¾ç±¾½øÐÐÉí·ÝÑéÖ¤¡£ÕâÒâζ×ÅÔ¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý¶Ôreturn.cgi¶ËµãµÄ¾«ÐÄÉè¼ÆÒªÇóÀ´ÀÄÓ÷ì϶À´Ö´ÐÐËÁÒâ´úÂë¡£



·ì϶ÑéÖ¤



EXP£ºhttps://www.exploit-db.com/exploits/46786¡£



½¨¸´½¨Òé



Crestron°ä²¼ÁË·ì϶½¨¸´·¨Ê½£º

https://www.crestron.com/en-US/Security/Security_Advisories¡£


Barco¸üй̼þ£º
https://www.barco.com/en/support/software/R33050103?majorVersion=2&minorVersion=3&patchVersion=2&buildVersion=20

https://www.barco.com/en/support/software/R33050104?majorVersion=2&minorVersion=4&patchVersion=1&buildVersion=19


Extron¸üй̼þ£º

https://www.extron.com/download/software.aspx?filehandle=sharelink200&material=44&type=archive



²Î¿¼Á´½Ó
https://threatpost.com/bugs-wireless-presentation-systems/144318/