ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ35ÖÜ

°ä²¼¹¦·ò 2020-09-01

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê08ÔÂ24ÈÕÖÁ30ÈÕ¹²ÊÕ¼°²È«·ì϶55¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇRed Lion N-TronδÃ÷½Ó¿Ú·ì϶ £»FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯·ì϶ £»Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´Ðзì϶ £»Foxit Studio Photo PSDÔ½½çд´úÂëÖ´Ðзì϶; Moog EXO Series EXVF5C-2ÖÎÀí½ÚÔį̀'statusbroadcast'ËÁÒâºÅÁîÖ´Ðзì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇCisco°ä²¼°²È«¸üР£¬½¨¸´¶à¸ö²úÆ·Öеķì϶ £»Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨ £»Ó¡¶ÈÓÎÀÀÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶3700Íò±Ê¼Í¼ £»Î¢Èí½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶ £»CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖС£


³ÁÒª°²È«·ì϶Áбí


1.Red Lion N-TronδÃ÷½Ó¿Ú·ì϶


Red Lion N-Tron´æÔÚδÎĵµ»¯½Ó¿Ú·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬ÒÔROOTȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-240-01


2. FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯·ì϶


FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource´æÔÚÐòÁл¯·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://github.com/FasterXML/jackson-databind/issues/2814


3. Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´Ðзì϶


Advantech iView DeviceTreeTable exportTaskMgrReport´æÔÚĿ¼±éÀú·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎĶÁȡϵͳÎļþ»òÕßÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1084/


4. Foxit Studio Photo PSDÔ½½çд´úÂëÖ´Ðзì϶


Foxit Studio Photo½âÎöPSDÎļþ´æÔÚÔ½½çд·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó £¬ÓÕʹÓû§½âÎö £¬Äܹ»ÏµÍ³¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1078/


5. Moog EXO Series EXVF5C-2ÖÎÀí½ÚÔį̀'statusbroadcast'ËÁÒâºÅÁîÖ´Ðзì϶


Moog EXO Series EXVF5C-2ÖÎÀí½ÚÔį̀'statusbroadcast'´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Ê¹ÓÃ'${IFS}'±äÁ¿ÈƹýÏÞ¶È £¬Äܹ»rootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£

https://ioactive.com/moog-exo-series-multiple-vulnerabilities/



> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Cisco°ä²¼°²È«¸üР£¬½¨¸´¶à¸ö²úÆ·Öеķì϶


1.png


Cisco°ä²¼°²È«¸üР£¬ÒÔ½¨¸´Æä¶à¸ö²úÆ·Öеķì϶¡£Õâ´Î°²È«¸üÐÂÖн¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪTreck IP²Ö¿âÖеķì϶Ripple20 £¬ÕâЩ·ì϶¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢»Ø¾ø·þÎñ£¨DoS£©»òÐÅϢй¶ £»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏÍ´´¦·ì϶£¨CVE-2020-3446£© £¬¿É±»ÀûÓÃÒÔÖÎÀíԱȨÏÞ½Ó¼ûNFVIS CLI £»Ë¼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM On-Prem£©±¾µØÌØÈ¨Éý¼¶·ì϶£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢ÏÖºÍ̸Զ³ÌÖ´Ðкͻؾø·þÎñ·ì϶£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates


2¡¢Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨


2.png


¹¤ÒµÍøÂ簲ȫ¹«Ë¾Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨¡£Claroty·ÖÎöÁËÐÂÔö³¤µ½¹ú¶È·ì϶Êý¾Ý¿â£¨NVD£©ÖеÄ365¸öICS·ì϶ÒÔ¼°ICS-CERT£¨CISA£©°ä²¼µÄ´«µÝÖк­¸ÇµÄ385¸ö·ì϶¡£Óë2019ÄêͬÆÚÅû¶µÄ·ì϶ÊýÁ¿Ïà±È £¬2020ÄêÉϰëÄêÐÂÔöµ½NVDÖеķì϶ÊýÁ¿Ô¼Äª¶à³ö10£¥¡£ÔÚËùʶ´ËÍâ·ì϶ÖÐ £¬ÓÐ70£¥ÒÔÉϵķì϶¿É±»Ô¶³ÌÀûÓà £¬Óн«½üÒ»°ë¿ÉÓÃÓÚÔ¶³ÌÖ´ÐдúÂë £¬ÆäÖÐ41£¥µÄ·ì϶¿ÉÈù¥»÷Õß¶ÁÈ¡ÀûÓ÷¨Ê½Êý¾Ý £¬39£¥µÄ·ì϶¿ÉÓÃÓÚDoS¹¥»÷ £¬37£¥µÄ·ì϶¿ÉÈÆ¹ý°²È«»úÔì¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/over-70-ics-vulnerabilities-disclosed-first-half-2020-remotely-exploitable


3¡¢Ó¡¶ÈÓÎÀÀÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶3700Íò±Ê¼Í¼


3.png


SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢ÏÖÁËRailYatriµÄûÓÐÃÜÂë± £»¤µÄElasticsearch·þÎñÆ÷ £¬Ð¹Â¶3700Íò±Ê¼Í¼¿Í»§ºÍ¹«Ë¾Êý¾Ý £¬Ô̺¬Óû§µÄÈ«Ãû¡¢´ºÇï¡¢ÐÔ±ð¡¢ÏÖʵºÍµç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂë¡¢Ô¤Ô¼¾ßÌåÐÅÏ¢¡¢GPSµØÎ»ÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄǰËÄλºÍºóËÄλ¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý½øÐб £»¤Ö®Ç° £¬Meow»úеÈËÓÚ8ÔÂ12ÈÕ¶ÔÆä²úÉú¹¥»÷ £¬É¾³ýÁ˳ý1GBÖ®±íµÄËùº±¼û¾Ý£¨×ܹ²43 GB£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/


4¡¢Î¢Èí½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶


4.png


΢Èí°ä²¼·ì϶²¹¶¡ £¬½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶¡£Õâ´Î°ä²¼µÄ²¹¶¡·¨Ê½½¨¸´ÁË2¸öÔ¶³Ì´úÂëÖ´Ðзì϶ºÍ2¸öÌáȨ·ì϶ £¬ÕâЩ·ì϶¶¼ÊÇÓÉCisco TalosµÄ°²È«×êÑÐÈËÔ±ÓÚ7Ô·ݷ¢ÏÖ¡£µÚÒ»¸öΪREAD_IMPLIES_EXEC personalityδÊðÃû´úÂëÖ´Ðзì϶ £¬µÚ¶þ¸öRCE·ì϶´æÔÚÓÚ/proc/thread-self/ memÖС£´Ë±í £¬È¨ÏÞ½Ó¼û½ÚÔìÖ°ÄÜÖдæÔÚÒ»¸öÌáȨ·ì϶ £¬¶øµÚ¶þ¸öÌáȨ·ì϶´æÔÚÓÚAzure Sphere 20.06µÄuid_mapÖ°ÄÜÖС£Î¢Èí°µÊ¾»áÈ·±£½â¾öÕâЩÎÊÌⲢΪ¿Í»§Ìṩ¸üР£¬µ«Êǻؾø°ä²¼ÈκÎCVEs¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/four-more-bugs-patched-in-microsofts-azure-sphere-iot-platform/158643/


5¡¢CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú


5.png


˼¿ÆÇ°Ô±¹¤Sudhish Kasaba RameshÈÏ×ïÆäɾ³ýÁËWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú¡£¾ÝÆäÈÏ×ïºÍ̸ÖгÆ £¬ÆäÈÏ¿ÉÔÚÈ¥Ö°5¸öÔºóµÄ2018Äê9ÔÂ24ÈÕ £¬Î´¾­¹«Ë¾µÄÐí¿ÉÓÐÒâ½Ó¼û˼¿ÆµÄÔÆ»ù´¡¼Ü¹¹ £¬²¢´ÓÆä×Ô¼ºµÄGoogle Cloud ProjectÕÊ»§Öв¿ÊðÁËÒ»¸ö´úÂë £¬É¾³ýÁË˼¿ÆWebEx TeamsÀûÓ÷¨Ê½µÄ456¸öÐé¹¹»ú¡£¾ÝϤ £¬¸ÃÊÂÎñµ¼ÖÂ16000¸öWebEx TeamsÕÊ»§±»¹Ø¹ØÁ˳¤´ïÁ½¸öÐÇÆÚ £¬CiscoÆÆ·ÑÁËԼĪ140ÍòÃÀÔªÀ´¸´Ô­ÆäÀûÓÃÊܵ½µÄÇÖº¦ £¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§ÍË»¹Á˳¬¹ý100ÍòÃÀÔªµÄ¿î×Ó¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/ex-cisco-employee-pleads-guilty-to-deleting-16k-webex-teams-accounts/158748/