ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ43ÖÜ

Ðû²¼Ê±¼ä 2018-10-29

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2018Äê10ÔÂ22ÈÕÖÁ29ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox ¶à¸öÄÚ´æÆÆ»µÈÎÒâ´úÂëÖ´ÐЩ¶´ £»Eaton UPS 9PX 8000 SP CVE-2018-9279Óû§ÃÜÂë鶩¶´ £»Citrix NetScaler SD-WAN OSÃüÁî×¢È멶´ £»Moxa ThingsPro CVE-2018-18393ÃÜÂë¸ü¸Ä©¶´ £»Symantec Veritas NetBackup ApplianceÊäÈëÔ¶³Ì´úÂëÖ´ÐЩ¶´; GEOVAP Reliance 4 SCADA/HMIÔ¶³Ì´úÂëÖ´ÐЩ¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǹúÌ©º½¿ÕÂÿÍ×ÊÁÏÒÉÍâй£¬²¨¼°Ô¼940Íò´î¿Í £»Ò½ÁƱ£ÏÕ¹«Ë¾AnthemͬÒâΪÊý¾Ýй¶Ê¼þÅ⸶1600ÍòÃÀÔª £»ÃÀHealthCare.govÒ½ÁÆϵͳÔâºÚ¿ÍÈëÇÖ£¬Ô¼7.5ÍòÓû§µÄÐÅÏ¢±»ÇÔ £»FacebookÒò½£ÇÅ·ÖÎö³óÎű»Ó¢¹úICO·£¿î50ÍòÓ¢°÷ £»CyberXÐû²¼È«ÇòICSºÍIIoT·çÏÕ³ÂËߣ¨2019°æ£© ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£




¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí


1. Mozilla Firefox ¶à¸öÄÚ´æÆÆ»µÈÎÒâ´úÂëÖ´ÐЩ¶´


Mozilla Firefox´æÔÚÕûÊýÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë ¡£

https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/



2. Eaton UPS 9PX 8000 SP CVE-2018-9279Óû§ÃÜÂë鶩¶´


Eaton UPS 9PX 8000 SPÍøÒ³ÖаüÂÞÃ÷ÎÄÃÜÂ룬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Óû§¹ÜÀíÃÜÂ룬δÊÚȨ·ÃÎÊÉ豸 ¡£

https://powerquality.eaton.com/support/software-drivers/downloads/connectivity-firmware.asp


3. Citrix NetScaler SD-WAN OSÃüÁî×¢È멶´


Citrix NetScaler SD-WAN´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâOSÃüÁî ¡£

https://support.citrix.com/article/CTX236992


4. Moxa ThingsPro CVE-2018-18393ÃÜÂë¸ü¸Ä©¶´


Moxa ThingsPro´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬸ü¸ÄÓû§ÃÜÂë ¡£

https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/10/18/klcert-18-021-moxa-thingspro-iiot-gateway-and-device-management-software-solutions-password-management-issue/


5. Symantec Veritas NetBackup ApplianceÊäÈëÔ¶³Ì´úÂëÖ´ÐЩ¶´


Symantec Veritas NetBackup£¨NBU£©Appliance´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔrootÉí·ÝÖ´ÐÐÈÎÒâÃüÁî ¡£

https://www.veritas.com/content/support/en_US/security/VTS18-003.html



Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢¹úÌ©º½¿ÕÂÿÍ×ÊÁÏÒÉÍâй£¬²¨¼°Ô¼940Íò´î¿Í

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹úÌ©º½¿Õ23ÈÕÍíÐû²¼Í¨¸æ³Æ£¬¸Ã¹«Ë¾¼°È«×Ê×Ó¹«Ë¾¸ÛÁúº½¿ÕÓÐÏÞ¹«Ë¾µÄ´î¿Í×ÊÁÏÔ⵽δÊÚȨ·ÃÎÊ£¬Ô¼940Íò´î¿Í×ÊÁϱ»ÇÔÈ¡£¬°üÂÞ´î¿ÍµÄÐÕÃû¡¢ÉúÈÕ¡¢µç»°¡¢µØÖ·¡¢Éí·ÝÖ¤¼°»¤ÕպŵÈÃô¸ÐÐÅÏ¢ ¡£´ËÍ⣬»¹ÓÐ403ÕÅÒÑÓâÆÚµÄÐÅÓÿ¨ºÅÂëй¶ ¡£¹úÌ©º½¿Õ³ÆÊÜÓ°ÏìµÄÐÅϢϵͳÓ뺽°àÔË×÷ϵͳΪ¶ÀÁ¢µÄϵͳ£¬´Ë´Îʼþ²»»á¶Ôº½°àÄþ¾²×é³ÉÈκÎÓ°Ïì ¡£


Ô­ÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/mcafee-labs/android-timpdoor-turns-mobile-devices-into-hidden-proxies/


2¡¢Ò½ÁƱ£ÏÕ¹«Ë¾AnthemͬÒâΪÊý¾Ýй¶Ê¼þÅ⸶1600ÍòÃÀÔª


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ò½ÁƱ£ÏÕ¹«Ë¾AnthemÒÑͬÒâΪ2015ÄêµÄÖØ´óÊý¾Ýй¶Ê¼þÏòÃÀ¹úÕþ¸®Ö§¸¶´´¼Í¼µÄ1600ÍòÃÀÔªºÍ½â½ð ¡£2015ÄêÔ¼7900ÍòAnthemÓû§µÄ¸öÈËÐÅϢй¶£¬¹¥»÷Õßͨ¹ýµöÓãÓʼþ·ÃÎÊÁ˸Ã×éÖ¯²¿ÃÅÓû§µÄÐÕÃû¡¢Éç±£ºÅÂë¡¢Ò½ÁÆID¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·ºÍ¾ÍÒµÐÅÏ¢µÈ ¡£AnthemÏÔȻδÄÜƾ¾Ý½¡¿µ±£ÏÕÁ÷ͨÓëÔðÈη¨°¸£¨HIPAA£©µÄÒªÇóÍ×ÉƱ £»¤Æä»ù´¡ÉèÊ© ¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/anthem-in-record-16m-hipaa/


3¡¢ÃÀHealthCare.govÒ½ÁÆϵͳÔâºÚ¿ÍÈëÇÖ£¬Ô¼7.5ÍòÓû§µÄÐÅÏ¢±»ÇÔ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÉÏÖÜÎåÃÀ¹úÒ½ÁƱ£ÏÕºÍÒ½ÁƲ¹Öú·þÎñÖÐÐÄ£¨CMS£©Ðû²¼ÏûÏ¢³Æ£¬ÓëHealthCare.govÏà¹ØµÄÒ»¸öÕþ¸®¼ÆËã»úϵͳÔâµ½ºÚ¿ÍÈëÇÖ£¬Ô¼7.5ÍòÃûÓû§µÄÃô¸Ð¸öÈËÐÅÏ¢±»ÇÔ ¡£CMSÌåÏÖÔÚ10ÔÂ16ÈÕÈ·ÈÏÁËÕâÒ»Êý¾Ýй¶Ê¼þ£¬²¢½ûÓÃÁËÓëÒì³ £»î¶¯Ïà¹ØµÄÓû§ÕË»§ ¡£CMSºÍFBIÕýÔڼƻ®Í¨ÖªËùÓÐÊÜÓ°ÏìµÄÓû§£¬²¢ÌṩÐÅÓñ £»¤µÈ×ÊÔ´ ¡£


Ô­ÎÄÁ´½Ó£º
https://www.apnews.com/212e1e36b10945968704bd7e86598a65


4¡¢FacebookÒò½£ÇÅ·ÖÎö³óÎű»Ó¢¹úICO·£¿î50ÍòÓ¢°÷


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹úÐÅϢרԱ°ì¹«ÊÒICO×îÖÕÒò½£ÇÅ·ÖÎö³óÎŶÔFacebook·£¿î50ÍòÓ¢°÷ ¡£Æ¾¾ÝICO¶Ô¸Ã³óÎŵÄÊӲ죬ÖÁÉÙÓÐ100ÍòÓ¢¹ú¹«ÃñµÄÊý¾ÝÔâµ½²»Õýµ±µÄ´¦Ö㬶øÇÒFacebookûÓÐÄܹ»½ÓÄɺÏÊʵļ¼ÊõÊֶκʹëÊ©×èÖ¹ÕâÒ»Êý¾Ýй¶ÐÐΪ ¡£È»¶ø£¬ÕâÒ»·£¿îÊý¶î¶ÔÓÚFacebook¶øÑÔ¾Åţһ룬FacebookÈ¥ÄêµÄÈ«Çò×ÜÊÕÈë´ï315ÒÚÓ¢°÷ ¡£Èç¹ûƾ¾Ý×îеÄGDPR¹æÔò£¬Facebook¿ÉÄÜÃæÁÙ×î¸ß12.6ÒÚÓ¢°÷µÄ·£¿î£¬µ«ÐÒÔ˵ÄÊÇGDPRÔڸóóÎÅ·¢×÷Ö®ºó²Å¿ªÊ¼ÉúЧ ¡£


Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/10/facebook-cambridge-analytica.html


5¡¢CyberXÐû²¼È«ÇòICSºÍIIoT·çÏÕ³ÂËߣ¨2019°æ£©


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝCyberXµÄÈ«ÇòICSºÍIIoT·çÏÕ³ÂËߣ¨2019°æ£©£¬ÓÉÓÚÔËÐйýʱµÄWindowsϵͳ£¬Áè¼ÝÒ»°ëµÄÒªº¦»ù´¡ÉèʩϵͳÒ×ÊÜÕë¶ÔÐÔ¹¥»÷µÄÓ°Ïì ¡£¸Ã³ÂËßÊÇ»ùÓÚ¶ÔÁù´óÖ޵Ķà¸ö¹¤ÒµÐÐÒµ£¨ÈçÖÆÔìÒµ¡¢»¯Ñ§Òµ¡¢¹«ÓÃÊÂÒµºÍÄÜÔ´ÒµµÈ£©µÄÁè¼Ý850¸öICS¼°SCADAÉú²úÍøÂç½øÐзÖÎöµÃÀ´ ¡£ÓÉÓÚʹÓùýʱµÄÍøÂçͨÐÅЭÒ飨ÈçSNMPºÍFTP£©£¬69%µÄICSÍøÂçʹÓÃÃ÷ÎÄ´«ÊäÃÜÂë ¡£


Ô­ÎÄÁ´½Ó£º
https://news.softpedia.com/news/53-percent-of-ics-networks-at-risk-because-of-legacy-windows-systems-523367.shtml


ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí