ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ08ÖÜ
°ä²¼¹¦·ò 2020-02-24> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê02ÔÂ17ÈÕÖÁ23ÈÕ¹²ÊÕ¼°²È«·ì϶51¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇB&R Industrial Automation Automation Studio SNMP·þÎñÊÚȨ·ì϶; Apache Tomcat AJPconnectorÎļþÔ̺¬·ì϶£»Adobe Media EncoderÔ½½çд´úÂëÖ´Ðзì϶£»Cisco Enterprise NFV Infrastructure SoftwareÉý¼¶×é¼þÑéÖ¤·ì϶£»Ansible pipe lookup²å¼þËÁÒâºÅÁîÖ´Ðзì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÖйúÈËÃñÒøÐа䲼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·£»Apache TomcatÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©£»°²È«×êÑÐÈËÔ±Åû¶΢Èí¶à¸ö×ÓÓòÃû±»½Ù³ÖÎÊÌ⣻ÃÀ¹úÌìÈ»Æø¹Ü·ÔËÓªÉÌÔâµ½ÀÕË÷Èí¼þ¹¥»÷£»ÒÁÀʺڿÍÀûÓÃVPNÈí¼þ·ì϶¹¥»÷È«ÇòµÄÆóÒµºÍµ±¾Ö»ú¹¹¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
>³ÁÒª°²È«·ì϶Áбí
1. B&R Industrial Automation Automation Studio SNMP·þÎñÊÚȨ·ì϶
B&R Industrial Automation Automation Studio SNMP·þÎñ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÅú¸Ä·þÎñÅäÖá£
https://www.us-cert.gov/ics/advisories/icsa-20-051-01
2. Apache Tomcat AJPconnectorÎļþÔ̺¬·ì϶
Apache Tomcat AJPconnector´æÔÚʵÏÖȱµãµ¼ÖÂÓйزÎÊý¿É¿Ø£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɶÁȡϵͳÎļþ»òÖ´ÐÐËÁÒâ´úÂë¡£
https://mp.weixin.qq.com/s/qIG_z9imxdLUobviSv7knw
3. Adobe Media EncoderÔ½½çд´úÂëÖ´Ðзì϶
Adobe Media Encoder´¦ÖÃÎļþ´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓÃÓÚ½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://helpx.adobe.com/security/products/media-encoder/apsb20-10.html
4. Cisco Enterprise NFV Infrastructure SoftwareÉý¼¶×é¼þÑéÖ¤·ì϶
Cisco Enterprise NFV Infrastructure SoftwareÉý¼¶×é¼þ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Éý¼¶¶ñÒâ¹Ì¼þ£¬Ö´ÐÐËÁÒâ´úÂë¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-codex-shs4NhvS
5. Ansible pipe lookup²å¼þËÁÒâºÅÁîÖ´Ðзì϶
Ansible pipe lookup²å¼þsubprocess.Popen()´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâºÅÁî¡£
https://access.redhat.com/security/cve/cve-2020-1734
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÖйúÈËÃñÒøÐа䲼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·
ÖйúÈËÃñÒøÐÐÏ·¢¡¶¹ØÓÚ<ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶>ÐÐÒµ³ß¶ÈµÄ֪ͨ¡·£¨Òø·¢[2020]35ºÅ£©£¬°ä²¼ÐÂ°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·(JR/T 0068-2020)£¬¸Ã°æ±¾ÊÇ2012°æ¹æ·¶(JR/T 0068-2012)µÄ´úÌæ¶©Õý°æ±¾¡£ÐÂ°æ¹æ·¶ÓÐÈý¸ö³Áµã¶©ÕýÄÚÈÝ£º1¡¢Õë¶Ôм¼Êõ³öÏÖºÍÀûÓÃÌá³öÁËÐµİ²È«ÒªÇó£¨ÀýÈçÔö³¤ÁËÐé¹¹»¯¡¢ÔÆÍÆË㰲ȫÓйØÒªÇó£¬Ôö³¤¹úÃÜSMϵÁÐËã·¨ÓйصݲȫҪÇó£¬Ôö³¤¶Ô°²È«µ¥ÔªºÍÒÆ¶¯ÖÕ¶ËÖ§¸¶¿ÉÐÅ»·¾³ÓйØÒªÇ󣩣»2¡¢¾ÍеÄÒµÎñºÍ¼à¹ÜÒªÇó½øÐÐÁ˲¹³äºÍÃ÷È·£¨ÀýÈçÔö³¤ÁËÌõÂëÖ§¸¶¡¢ÂòÂô°²È«ËøºÍ¢ò¡¢¢óÀàÕË»§µÄÓйØÒªÇ󣩣»3¡¢³ÁÐÂÊáÀí²¢ÌáÉý¹ØÓÚÒµÎñÂ½ÐøÐÔÓë¿àÄѸ´Ô¡¢°²È«ÊÂÎñÓëÓ¦¼±ÏìÓ¦µÄ°²È«ÒªÇó¡£
ÔÎÄÁ´½Ó£º
https://www.cebnet.com.cn/20200219/102639904.html
2¡¢Apache TomcatÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©
Apache Tomcat·þÎñÆ÷´æÔÚÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶¶ÁÈ¡»òÔ̺¬TomcatÉÏËùÓÐwebappĿ¼ÏµÄËÁÒâÎļþ£¬È磺webappÅäÖÃÎļþ»òÔ´´úÂëµÈ¡£¸Ã·ì϶ÓëTomcat AJPºÍ̸Óйأ¬Tomcat AJP ConnectorĬÈÏÅäÖÃϼ´Îª¿ªÆô״̬£¬²¢ÇÒ¼àÌý¶Ë¿Ú8009¡£¸Ã·ì϶ӰÏìÁËTomcat 6/7/8/9È«°æ±¾£¬Apache¹Ù·½ÒѰ䲼9.0.31¡¢8.5.51¼°7.0.100°æ±¾Õë¶Ô´Ë·ì϶½øÐн¨¸´£¬½¨ÒéÓû§ÏÂÔØÊ¹Óá£ÓÉÓÚTomcat 6ÒѾÖÕ³¡ÊØ»¤£¬½¨ÒéÓû§Éý¼¶µ½×îÐÂÊÜÖ§³ÖµÄTomcat°æ±¾ÒÔÃâÔâ·ê¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.cnvd.org.cn/flaw/show/CNVD-2020-10487
3¡¢°²È«×êÑÐÈËÔ±Åû¶΢Èí¶à¸ö×ÓÓòÃû±»½Ù³ÖÎÊÌâ
NIC.gp°²È«×êÑÐÔ±Michel GaschetÖ¸³ö΢Èí´æÔÚ¶à¸ö×ÓÓòÃû½Ù³ÖÎÊÌ⣬ÕâЩ×ÓÓòÃû¿ÉÄܱ»½Ù³ÖºÍÓÃÓÚ¹¥»÷Óû§¡¢Ô±¹¤»òÏÔʾÀ¬»øÄÚÈÝ¡£ÔÚ´ÓǰÈýÄêÖУ¬GaschetÒ»ÏòÔÚÏò΢Èí»ã±¨´øÓÐÃýÎóÅäÖõÄDNS¼Í¼µÄ×ÓÓòÃû£¬ÀýÈç2017ÄêËû»ã±¨ÁË21¸öÒ×±»½Ù³ÖµÄmsn.com×ÓÓòÃû£¬2019ÄêËûÓֻ㱨ÁË142¸öÅäÖÃÃýÎóµÄmicrosoft.com×ÓÓòÃû£¬µ«Î¢Èí½ö½¨¸´ÁËÆäÖÐ5£¥µ½10£¥µÄ×ÓÓòÃû¡£Gaschet»¹Ö¸³öËûÖÁÉÙÔÚ4¸öºÏ·¨µÄ΢Èí×ÓÓòÖз¢ÏÖÁËÓ¡¶ÈÄáÎ÷ÑÇÆË¿Ë¶Ä³¡µÄ¸æ°×£¬Ô̺¬portal.ds.microsoft.com¡¢perfect10.microsoft.com¡¢ies.global.microsoft.comºÍblog-ambassadors.microsoft.com¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-has-a-subdomain-hijacking-problem/
4¡¢ÃÀ¹úÌìÈ»Æø¹Ü·ÔËÓªÉÌÔâµ½ÀÕË÷Èí¼þ¹¥»÷
ƾ¾ÝÃÀ¹úºÓɽ°²È«ÊýÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨DHS CISA£©°ä²¼µÄ´«µÝ£¬Ò»¼Òδ¾ßÃûµÄÃÀ¹úÌìÈ»ÆøÑ¹Ëõ¹¤³§ÔâÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÔËÓªÖжÏÁËÁ½ÌìµÄ¹¦·ò¡£CISA°µÊ¾¹¥»÷ÕßÊ×ÏÈÀûÓô¹µöÁ´½Ó»ñµÃÁ˶ԸÃ×éÖ¯ITÍøÂçµÄ½Ó¼û£¬¶øºóתÏòÆäOTÍøÂç²¢²¿ÊðÁËÉÌÓÃÀÕË÷Èí¼þ¡£¸ÃÈí¼þͬʱÔÚITºÍOTÍøÂçÉ϶Թ«Ë¾µÄÊý¾Ý½øÐмÓÃÜ£¬ÒÔ×î´óˮƽµØ·ÛËéÆóÒµ£¬¶øºó²ÅÒªÇóÖ§¸¶Êê½ð¡£¸ÃÀÕË÷Èí¼þ²¢Î´Ó°ÏìÈκÎPLC£¬µ«ÈËÀà²Ù×÷Ô±ÎÞ·¨»ã×ܺͶÁÈ¡Óйع¤Òµ¹ý³ÌÖеÄÊý¾Ý£¬ÀýÈçHMI¡¢Êý¾Ýº¹Çà¼Í¼ºÍÂÖѯ·þÎñÆ÷£¬´Ó¶øµ¼ÖÂÔ±¹¤ÎÞ·¨°ÑÎչܷÉèÊ©µÄÔËÐÐÇé¿ö¡£¹Ü·ÔËÓªÉÌÖ´ÐÐÁË¡°ÓдòËãµÄ¡¢ÊܿصĹعء±´ëÊ©£¬ÒÔÔ¤·À²¢Ô¤·ÀÈκÎÊÂÎñµÄ²úÉú¡£CISA°µÊ¾ÔËÓªÖжϳÖÐøÁËÔ¼Á½Ì죬¶øºó¸´ÔÁËÕý³£ÔË×÷¡£CISAûÓÐй©ÀÕË÷Èí¼þµÄÃû³Æ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/dhs-says-ransomware-hit-us-gas-pipeline-operator/
5¡¢ÒÁÀʺڿÍÀûÓÃVPNÈí¼þ·ì϶¹¥»÷È«ÇòµÄÆóÒµºÍµ±¾Ö»ú¹¹
ƾ¾Ý°²È«³§ÉÌClearSkyµÄÒ»·Ý»ã±¨£¬ÒÁÀʺڿÍÒ»ÏòÔÚÀûÓÃVPNÈí¼þÖеķì϶ÔÚÊÀ½ç¸÷µØµÄ¹«Ë¾ÖÐÖ²ÈëºóÃÅ£¬ÆäÖ¸±êº¸ÇIT¡¢µçÐÅ¡¢Ê¯ÓͺÍÌìÈ»Æø¡¢º½¿Õ¡¢°²È«ÁìÓòµÄ¹«Ë¾ºÍµ±¾Ö»ú¹¹¡£ÒÁÀʺڿÍÒѽ«Pulse Secure¡¢Fortinet¡¢Palo Alto NetworksºÍCitrixµÄVPN¶¨Î»ÎªÈëÇÖ´óÐ͹«Ë¾µÄ¹¤¾ß£¬ÆäÀûÓõķì϶Ô̺¬Pulse Secure VPN(CVE-2019-11510)¡¢Fortinet FortiOS VPN(CVE-2018-13379)¡¢Palo Alto Networks VPN(CVE-2019-1579)ÒÔ¼°Citrix VPN(CVE-2019-19781)µÈ¡£¶ÔÕâЩϵͳµÄ¹¥»÷ʼÓÚÈ¥ÄêÏÄÌ죬µ«µ½2020ÄêÕâÖÖ¹¥»÷ÈÔÔÚ³ÖÐø¡£ClearSky»ã±¨Ç¿µ÷£¬¶ÔÈ«ÇòVPN·þÎñÆ÷µÄ¹¥»÷ËÆºõÊÇÖÁÉÙÈý¸öÒÁÀʺڿÍ×éÖ¯µÄ¹¤×÷£¬Ô̺¬APT33¡¢APT34ºÍAPT39¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/iranian-hackers-have-been-hacking-vpn-servers-to-plant-backdoors-in-companies-around-the-world/


¾©¹«Íø°²±¸11010802024551ºÅ