ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ35ÖÜ

°ä²¼¹¦·ò 2020-09-01

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê08ÔÂ24ÈÕÖÁ30ÈÕ¹²ÊÕ¼°²È«·ì϶55¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇRed Lion N-TronδÃ÷½Ó¿Ú·ì϶£»FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯·ì϶£»Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´Ðзì϶£»Foxit Studio Photo PSDÔ½½çд´úÂëÖ´Ðзì϶; Moog EXO Series EXVF5C-2ÖÎÀí½ÚÔį̀'statusbroadcast'ËÁÒâºÅÁîÖ´Ðзì϶ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇCisco°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·Öеķì϶£»Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨£»Ó¡¶ÈÓÎÀÀÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶3700Íò±Ê¼Í¼£»Î¢Èí½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶£»CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£


³ÁÒª°²È«·ì϶Áбí


1.Red Lion N-TronδÃ÷½Ó¿Ú·ì϶


Red Lion N-Tron´æÔÚδÎĵµ»¯½Ó¿Ú·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔROOTȨÏÞÖ´ÐÐËÁÒâºÅÁî ¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-240-01


2. FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯·ì϶


FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource´æÔÚÐòÁл¯·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£

https://github.com/FasterXML/jackson-databind/issues/2814


3. Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´Ðзì϶


Advantech iView DeviceTreeTable exportTaskMgrReport´æÔÚĿ¼±éÀú·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎĶÁȡϵͳÎļþ»òÕßÖ´ÐÐËÁÒâ´úÂë ¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1084/


4. Foxit Studio Photo PSDÔ½½çд´úÂëÖ´Ðзì϶


Foxit Studio Photo½âÎöPSDÎļþ´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬Äܹ»ÏµÍ³¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1078/


5. Moog EXO Series EXVF5C-2ÖÎÀí½ÚÔį̀'statusbroadcast'ËÁÒâºÅÁîÖ´Ðзì϶


Moog EXO Series EXVF5C-2ÖÎÀí½ÚÔį̀'statusbroadcast'´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Ê¹ÓÃ'${IFS}'±äÁ¿ÈƹýÏÞ¶È£¬Äܹ»rootȨÏÞÖ´ÐÐËÁÒâºÅÁî ¡£

https://ioactive.com/moog-exo-series-multiple-vulnerabilities/



> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Cisco°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·Öеķì϶


1.png


Cisco°ä²¼°²È«¸üУ¬ÒÔ½¨¸´Æä¶à¸ö²úÆ·Öеķì϶ ¡£Õâ´Î°²È«¸üÐÂÖн¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪTreck IP²Ö¿âÖеķì϶Ripple20£¬ÕâЩ·ì϶¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢»Ø¾ø·þÎñ£¨DoS£©»òÐÅϢй¶£»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏÍ´´¦·ì϶£¨CVE-2020-3446£©£¬¿É±»ÀûÓÃÒÔÖÎÀíԱȨÏÞ½Ó¼ûNFVIS CLI£»Ë¼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM On-Prem£©±¾µØÌØÈ¨Éý¼¶·ì϶£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢ÏÖºÍ̸Զ³ÌÖ´Ðкͻؾø·þÎñ·ì϶£¨CVE-2020-3506ºÍCVE-2020-3507£© ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates


2¡¢Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨


2.png


¹¤ÒµÍøÂ簲ȫ¹«Ë¾Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨ ¡£Claroty·ÖÎöÁËÐÂÔö³¤µ½¹ú¶È·ì϶Êý¾Ý¿â£¨NVD£©ÖеÄ365¸öICS·ì϶ÒÔ¼°ICS-CERT£¨CISA£©°ä²¼µÄ´«µÝÖк­¸ÇµÄ385¸ö·ì϶ ¡£Óë2019ÄêͬÆÚÅû¶µÄ·ì϶ÊýÁ¿Ïà±È£¬2020ÄêÉϰëÄêÐÂÔöµ½NVDÖеķì϶ÊýÁ¿Ô¼Äª¶à³ö10£¥ ¡£ÔÚËùʶ´ËÍâ·ì϶ÖУ¬ÓÐ70£¥ÒÔÉϵķì϶¿É±»Ô¶³ÌÀûÓã¬Óн«½üÒ»°ë¿ÉÓÃÓÚÔ¶³ÌÖ´ÐдúÂ룬ÆäÖÐ41£¥µÄ·ì϶¿ÉÈù¥»÷Õß¶ÁÈ¡ÀûÓ÷¨Ê½Êý¾Ý£¬39£¥µÄ·ì϶¿ÉÓÃÓÚDoS¹¥»÷£¬37£¥µÄ·ì϶¿ÉÈÆ¹ý°²È«»úÔì ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/over-70-ics-vulnerabilities-disclosed-first-half-2020-remotely-exploitable


3¡¢Ó¡¶ÈÓÎÀÀÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶3700Íò±Ê¼Í¼


3.png


SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢ÏÖÁËRailYatriµÄûÓÐÃÜÂë±£»¤µÄElasticsearch·þÎñÆ÷£¬Ð¹Â¶3700Íò±Ê¼Í¼¿Í»§ºÍ¹«Ë¾Êý¾Ý£¬Ô̺¬Óû§µÄÈ«Ãû¡¢´ºÇï¡¢ÐÔ±ð¡¢ÏÖʵºÍµç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂë¡¢Ô¤Ô¼¾ßÌåÐÅÏ¢¡¢GPSµØÎ»ÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄǰËÄλºÍºóËÄλ ¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý½øÐб£»¤Ö®Ç°£¬Meow»úеÈËÓÚ8ÔÂ12ÈÕ¶ÔÆä²úÉú¹¥»÷£¬É¾³ýÁ˳ý1GBÖ®±íµÄËùº±¼û¾Ý£¨×ܹ²43 GB£© ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/


4¡¢Î¢Èí½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶


4.png


΢Èí°ä²¼·ì϶²¹¶¡£¬½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶ ¡£Õâ´Î°ä²¼µÄ²¹¶¡·¨Ê½½¨¸´ÁË2¸öÔ¶³Ì´úÂëÖ´Ðзì϶ºÍ2¸öÌáȨ·ì϶£¬ÕâЩ·ì϶¶¼ÊÇÓÉCisco TalosµÄ°²È«×êÑÐÈËÔ±ÓÚ7Ô·ݷ¢ÏÖ ¡£µÚÒ»¸öΪREAD_IMPLIES_EXEC personalityδÊðÃû´úÂëÖ´Ðзì϶£¬µÚ¶þ¸öRCE·ì϶´æÔÚÓÚ/proc/thread-self/ memÖÐ ¡£´Ë±í£¬È¨ÏÞ½Ó¼û½ÚÔìÖ°ÄÜÖдæÔÚÒ»¸öÌáȨ·ì϶£¬¶øµÚ¶þ¸öÌáȨ·ì϶´æÔÚÓÚAzure Sphere 20.06µÄuid_mapÖ°ÄÜÖÐ ¡£Î¢Èí°µÊ¾»áÈ·±£½â¾öÕâЩÎÊÌⲢΪ¿Í»§Ìṩ¸üУ¬µ«Êǻؾø°ä²¼ÈκÎCVEs ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/four-more-bugs-patched-in-microsofts-azure-sphere-iot-platform/158643/


5¡¢CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú


5.png


˼¿ÆÇ°Ô±¹¤Sudhish Kasaba RameshÈÏ×ïÆäɾ³ýÁËWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú ¡£¾ÝÆäÈÏ×ïºÍ̸ÖгÆ£¬ÆäÈÏ¿ÉÔÚÈ¥Ö°5¸öÔºóµÄ2018Äê9ÔÂ24ÈÕ£¬Î´¾­¹«Ë¾µÄÐí¿ÉÓÐÒâ½Ó¼û˼¿ÆµÄÔÆ»ù´¡¼Ü¹¹£¬²¢´ÓÆä×Ô¼ºµÄGoogle Cloud ProjectÕÊ»§Öв¿ÊðÁËÒ»¸ö´úÂ룬ɾ³ýÁË˼¿ÆWebEx TeamsÀûÓ÷¨Ê½µÄ456¸öÐé¹¹»ú ¡£¾ÝϤ£¬¸ÃÊÂÎñµ¼ÖÂ16000¸öWebEx TeamsÕÊ»§±»¹Ø¹ØÁ˳¤´ïÁ½¸öÐÇÆÚ£¬CiscoÆÆ·ÑÁËԼĪ140ÍòÃÀÔªÀ´¸´Ô­ÆäÀûÓÃÊܵ½µÄÇÖº¦£¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§ÍË»¹Á˳¬¹ý100ÍòÃÀÔªµÄ¿î×Ó ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/ex-cisco-employee-pleads-guilty-to-deleting-16k-webex-teams-accounts/158748/