ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ35ÖÜ

Ðû²¼Ê±¼ä 2020-09-01

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê08ÔÂ24ÈÕÖÁ30ÈÕ¹²ÊÕ¼Çå¾²Îó²î55¸ö £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇRed Lion N-TronδÃ÷½Ó¿ÚÎó²î£»£»£»FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯Îó²î£»£»£»Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´ÐÐÎó²î£»£»£»Foxit Studio Photo PSDÔ½½çд´úÂëÖ´ÐÐÎó²î; Moog EXO Series EXVF5C-2ÖÎÀí¿ØÖÆÌ¨'statusbroadcast'í§ÒâÏÂÁîÖ´ÐÐÎó²î¡£ ¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇCiscoÐû²¼Çå¾²¸üР£¬£¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖеÄÎó²î£»£»£»ClarotyÐû²¼2020ÄêÉϰëÄêICSÎó²îÆÊÎö±¨¸æ£»£»£»Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÉèÖùýʧй¶3700ÍòÌõ¼Í¼£»£»£»Î¢ÈíÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸öÎó²î£»£»£»CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú¡£ ¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£ ¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Red Lion N-TronδÃ÷½Ó¿ÚÎó²î


Red Lion N-Tron±£´æÎ´Îĵµ»¯½Ó¿ÚÎó²î £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬ÒÔROOTȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£ ¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-240-01


2. FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯Îó²î


FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource±£´æÐòÁл¯Îó²î £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£

https://github.com/FasterXML/jackson-databind/issues/2814


3. Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´ÐÐÎó²î


Advantech iView DeviceTreeTable exportTaskMgrReport±£´æÄ¿Â¼±éÀúÎó²î £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎĶÁȡϵͳÎļþ»òÕßÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1084/


4. Foxit Studio Photo PSDÔ½½çд´úÂëÖ´ÐÐÎó²î


Foxit Studio PhotoÆÊÎöPSDÎļþ±£´æÔ½½çдÎó²î £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬£¬¿ÉÒÔϵͳÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1078/


5. Moog EXO Series EXVF5C-2ÖÎÀí¿ØÖÆÌ¨'statusbroadcast'í§ÒâÏÂÁîÖ´ÐÐÎó²î


Moog EXO Series EXVF5C-2ÖÎÀí¿ØÖÆÌ¨'statusbroadcast'±£´æÇå¾²Îó²î £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬Ê¹ÓÃ'${IFS}'±äÁ¿ÈƹýÏÞÖÆ £¬£¬£¬£¬¿ÉÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£ ¡£¡£¡£

https://ioactive.com/moog-exo-series-multiple-vulnerabilities/



> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢CiscoÐû²¼Çå¾²¸üР£¬£¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖеÄÎó²î


1.png


CiscoÐû²¼Çå¾²¸üР£¬£¬£¬£¬ÒÔÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄÎó²î¡£ ¡£¡£¡£´Ë´ÎÇå¾²¸üÐÂÖÐÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²îΪTreck IP¿ÍÕ»ÖеÄÎó²îRipple20 £¬£¬£¬£¬ÕâЩÎó²î¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢¾Ü¾øÐ§ÀÍ£¨DoS£©»òÐÅϢй¶£»£»£»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏÆ¾Ö¤Îó²î£¨CVE-2020-3446£© £¬£¬£¬£¬¿É±»Ê¹ÓÃÒÔÖÎÀíԱȨÏÞ»á¼ûNFVIS CLI£»£»£»Ë¼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM On-Prem£©ÍâµØÌØÈ¨Éý¼¶Îó²î£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢Ã÷ЭÒéÔ¶³ÌÖ´Ðк;ܾøÐ§ÀÍÎó²î£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates


2¡¢ClarotyÐû²¼2020ÄêÉϰëÄêICSÎó²îÆÊÎö±¨¸æ


2.png


¹¤ÒµÍøÂçÇå¾²¹«Ë¾ClarotyÐû²¼2020ÄêÉϰëÄêICSÎó²îÆÊÎö±¨¸æ¡£ ¡£¡£¡£ClarotyÆÊÎöÁËÐÂÌí¼Óµ½¹ú¼ÒÎó²îÊý¾Ý¿â£¨NVD£©ÖеÄ365¸öICSÎó²îÒÔ¼°ICS-CERT£¨CISA£©Ðû²¼µÄת´ïÖк­¸ÇµÄ385¸öÎó²î¡£ ¡£¡£¡£Óë2019ÄêͬÆÚÅû¶µÄÎó²îÊýÄ¿Ïà±È £¬£¬£¬£¬2020ÄêÉϰëÄêÐÂÔöµ½NVDÖеÄÎó²îÊýĿԼζà³ö10£¥¡£ ¡£¡£¡£ÔÚËùʶ±ðµÄÎó²îÖÐ £¬£¬£¬£¬ÓÐ70£¥ÒÔÉϵÄÎó²î¿É±»Ô¶³ÌʹÓà £¬£¬£¬£¬ÓпìÒªÒ»°ë¿ÉÓÃÓÚÔ¶³ÌÖ´ÐдúÂë £¬£¬£¬£¬ÆäÖÐ41£¥µÄÎó²î¿ÉÈù¥»÷Õß¶ÁȡӦÓóÌÐòÊý¾Ý £¬£¬£¬£¬39£¥µÄÎó²î¿ÉÓÃÓÚDoS¹¥»÷ £¬£¬£¬£¬37£¥µÄÎó²î¿ÉÈÆ¹ýÇå¾²»úÖÆ¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/over-70-ics-vulnerabilities-disclosed-first-half-2020-remotely-exploitable


3¡¢Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÉèÖùýʧй¶3700ÍòÌõ¼Í¼


3.png


SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢Ã÷ÁËRailYatriµÄûÓÐÃÜÂë±£»£»£»¤µÄElasticsearchЧÀÍÆ÷ £¬£¬£¬£¬Ð¹Â¶3700ÍòÌõ¼Í¼¿Í»§ºÍ¹«Ë¾Êý¾Ý £¬£¬£¬£¬°üÀ¨Óû§µÄÈ«Ãû¡¢ÄêËê¡¢ÐÔ±ð¡¢ÏÖʵºÍµç×ÓÓʼþµØµã¡¢ÊÖ»úºÅÂë¡¢Ô¤¶©ÏêϸÐÅÏ¢¡¢GPSλÖÃÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄǰËÄλºÍºóËÄλ¡£ ¡£¡£¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý¾ÙÐб£»£»£»¤Ö®Ç° £¬£¬£¬£¬Meow»úеÈËÓÚ8ÔÂ12ÈÕ¶ÔÆä±¬·¢¹¥»÷ £¬£¬£¬£¬É¾³ýÁ˳ý1GBÖ®ÍâµÄËùÓÐÊý¾Ý£¨×ܹ²43 GB£©¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/


4¡¢Î¢ÈíÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸öÎó²î


4.png


΢ÈíÐû²¼Îó²î²¹¶¡ £¬£¬£¬£¬ÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸öÎó²î¡£ ¡£¡£¡£´Ë´ÎÐû²¼µÄ²¹¶¡³ÌÐòÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²îºÍ2¸öÌáȨÎó²î £¬£¬£¬£¬ÕâЩÎó²î¶¼ÊÇÓÉCisco TalosµÄÇå¾²Ñо¿Ö°Ô±ÓÚ7Ô·ݷ¢Ã÷¡£ ¡£¡£¡£µÚÒ»¸öΪREAD_IMPLIES_EXEC personalityδÊðÃû´úÂëÖ´ÐÐÎó²î £¬£¬£¬£¬µÚ¶þ¸öRCEÎó²î±£´æÓÚ/proc/thread-self/ memÖС£ ¡£¡£¡£±ðµÄ £¬£¬£¬£¬È¨ÏÞ»á¼û¿ØÖƹ¦Ð§Öб£´æÒ»¸öÌáȨÎó²î £¬£¬£¬£¬¶øµÚ¶þ¸öÌáȨÎó²î±£´æÓÚAzure Sphere 20.06µÄuid_map¹¦Ð§ÖС£ ¡£¡£¡£Î¢ÈíÌåÏÖ»áÈ·±£½â¾öÕâЩÎÊÌⲢΪ¿Í»§Ìṩ¸üР£¬£¬£¬£¬¿ÉÊǾܾøÐû²¼ÈκÎCVEs¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/four-more-bugs-patched-in-microsofts-azure-sphere-iot-platform/158643/


5¡¢CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú


5.png


˼¿ÆÇ°Ô±¹¤Sudhish Kasaba RameshÈÏ×ïÆäɾ³ýÁËWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú¡£ ¡£¡£¡£¾ÝÆäÈÏ×ïЭÒéÖÐ³Æ £¬£¬£¬£¬ÆäÈÏ¿ÉÔÚÈ¥Ö°5¸öÔºóµÄ2018Äê9ÔÂ24ÈÕ £¬£¬£¬£¬Î´¾­¹«Ë¾µÄÔÊÐíÓÐÒâ»á¼û˼¿ÆµÄÔÆ»ù´¡¼Ü¹¹ £¬£¬£¬£¬²¢´ÓÆä×Ô¼ºµÄGoogle Cloud ProjectÕÊ»§Öа²ÅÅÁËÒ»¸ö´úÂë £¬£¬£¬£¬É¾³ýÁË˼¿ÆWebEx TeamsÓ¦ÓóÌÐòµÄ456¸öÐéÄâ»ú¡£ ¡£¡£¡£¾ÝϤ £¬£¬£¬£¬¸ÃÊÂÎñµ¼ÖÂ16000¸öWebEx TeamsÕÊ»§±»¹Ø±ÕÁ˳¤´ïÁ½¸öÐÇÆÚ £¬£¬£¬£¬CiscoÆÆ·ÑÁËԼĪ140ÍòÃÀÔªÀ´»Ö¸´ÆäÓ¦ÓÃÊܵ½µÄË𺦠£¬£¬£¬£¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§ÍË»¹ÁËÁè¼Ý100ÍòÃÀÔªµÄ¿î×Ó¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/ex-cisco-employee-pleads-guilty-to-deleting-16k-webex-teams-accounts/158748/