ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ30ÖÜ

Ðû²¼Ê±¼ä 2019-08-05

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê7ÔÂ29ÈÕÖÁ8ÔÂ04ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAlcatel-Lucent Enterprise 8008 Cloud Edition Deskphone VoIPÃÜÂë¸ü¸ÄÃüÁî×¢È멶´£»Puppet Enterprise PE's express installĬÈÏÃÜÂ멶´£»Wind River Systems VxWorks IPÑ¡Ïî½âÎö»º³åÇøÒç³ö©¶´£»Polycom UC SoftwareÉÏ´«Îļþ´úÂëÖ´ÐЩ¶´£»cPanel SQL×¢È멶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇŦԼͨ¹ýÐÂÊý¾Ýй¶֪ͨ·¨°¸£¬Êý¾Ý¼à¹ÜÔÙ´ÎÉý¼¶£»Capital Oneй¶1.06ÒÚÓû§ÐÅÏ¢£¬ÏÓÒÉÈËÒѱ»²¶£»VxWorksÐÞ¸´11¸öÄþ¾²Â©¶´£¬Ó°ÏìÁè¼Ý20ÒŲ́É豸£»Amcrest¼ÒÓÃÉãÏñÍ·ÑÏÖØ©¶´£¬¿ÉÔÊÐí¹¥»÷ÕßÔ¶³Ì¼àÌýÓû§£»ÖÇÀû1430Íò¹«ÃñÐÅϢй¶£¬Õ¼È«¹ú×ÜÈË¿Ú½ü80%¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£



> ÖØÒªÄþ¾²Â©¶´Áбí



1. Alcatel-Lucent Enterprise 8008 Cloud Edition Deskphone VoIPÃÜÂë¸ü¸ÄÃüÁî×¢È멶´


Alcatel-Lucent Enterprise 8008 Cloud Edition Deskphone VoIP ÃÜÂë¸ü¸Ä½çÃæ¸ü¸ÄÃÜÂë´¦ÖôæÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâOSÃüÁî¡£

https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_Alcatel_8008CloudEditionDeskPhone.pdf?_=1559026340

2. Puppet Enterprise PE's express installĬÈÏÃÜÂ멶´


Puppet Enterprise PE's express install´æÔÚĬÈÏÃÜÂ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊ¡£
https://puppet.com/security/cve/CVE-2019-10694

3. Wind River Systems VxWorks IPÑ¡Ïî½âÎö»º³åÇøÒç³ö©¶´


Wind River Systems VxWorks IPÑ¡Ïî´¦ÖôæÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.us-cert.gov/ics/advisories/icsa-19-211-01

4. Polycom UC SoftwareÉÏ´«Îļþ´úÂëÖ´ÐЩ¶´


Polycom UC SoftwareÉÏ´«Îļþ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://support.polycom.com/content/dam/polycom-support/global/documentation/remote-code-execution-vulnerability-in-ucs-software-v1-0.pdf

5. cPanel SQL×¢È멶´


cPanel´æÔÚSQL×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://documentation.cpanel.net/display/CL/58+Change+Log


 > ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢Å¦Ô¼Í¨¹ýÐÂÊý¾Ýй¶֪ͨ·¨°¸£¬Êý¾Ý¼à¹ÜÔÙ´ÎÉý¼¶


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ŦԼÖÝÖݳ¤Andrew M. Cuomo½üÈÕÇ©ÊðÁËÒ»ÏîеÄÊý¾Ýй¶֪ͨ·¨°¸£¬¸Ã·¨°¸µÄÃû³ÆΪ¡°×èÖ¹ºÚ¿Í¼°¸ïеç×ÓÊý¾ÝÄþ¾²¡±£¬¼´SHIELD·¨°¸£¬Ö¼ÔÚ±£»¤Å¦Ô¼¹«ÃñµÄÒþ˽Êý¾Ý²¢¼ÓÇ¿¸ÃÖݵÄÊý¾Ýй¶Õþ²ß¡£¸Ã·¨°¸À©´óÁ˸öÈËÐÅÏ¢µÄ·¶Î§£¬½«ÉúÎïʶ±ðÐÅÏ¢¡¢µç×ÓÓʼþµØÖ·¼°ÃÜÂë¡¢Äþ¾²ÎÊÌâ¼°´ð°¸ÁÐÈëÆäÖС£¸Ã·¨°¸»¹Ôö¼ÓÁËÃñÊ´¦·££¬²¢½«Í¨ÖªÒªÇóÓ¦ÓÃÓÚÈκÎÓµÓÐŦԼ¹«ÃñÒþ˽ÐÅÏ¢µÄ¸öÈË»òʵÌ壬¶ø²»½ö½öÊÇÔÚŦԼÖÝ¿ªÕ¹ÒµÎñµÄʵÌå¡£¸Ã·¨°¸»¹½«ÌṩÉí·Ý͵ÇÔ±£»¤·þÎñдÈëÖ´·¨£¬ÒªÇóCRAÔÚ·¢ÉúÉæ¼°Éç»áÄþ¾²ºÅÂëµÄÊý¾Ýй¶ºó±ØÐëÏòÏû·ÑÕßÌṩºÏÀíµÄ±£»¤·þÎñ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-york-passes-law-to-update-data-breach-notification-requirements/

2¡¢Capital Oneй¶1.06ÒÚÓû§ÐÅÏ¢£¬ÏÓÒÉÈËÒѱ»²¶


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Capital OneÈ·ÈÏÆäϵͳÓÚ3ÔÂ22ÈÕÖÁ23ÈÕÆÚ¼äÔâδÊÚȨ·ÃÎÊ£¬µ¼ÖÂ1.06ÒÚÓû§µÄÐÅϢй¶£¬°üÂÞ½»Ò×Êý¾Ý¡¢ÐÅÓÃÆÀ·Ö¡¢Ö§¸¶ÀúÊ·¡¢Óà¶îÒÔ¼°¹ØÁªµÄÒøÐÐÕË»§ºÍÉç»áÄþ¾²ºÅÂë¡£ÊÜÓ°ÏìµÄÓû§°üÂÞ1ÒÚÃÀ¹úÈ˺Í600Íò¼ÓÄôóÈË¡£Æ¾¾ÝÏà¹ØÖ¤¾Ý£¬FBIÒѾ­´þ²¶ÁËÏÓÒÉÈËPaige Thompson¡£Capital OneÌåÏÖÓÉÓÚ¿Í»§Í¨Öª¡¢Ãâ·ÑµÄÐÅÓüà¿Ø·þÎñ¡¢Äþ¾²¸ïгɱ¾ÒÔ¼°Ö´·¨ÓöÈ£¬Õâһʼþ½«µ¼ÖÂÔ¼1ÒÚÖÁ1.5ÒÚÃÀÔªµÄ³É±¾¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/capital-one-data-breach-affects-106-million-people-suspect-arrested/

3¡¢VxWorksÐÞ¸´11¸öÄþ¾²Â©¶´£¬Ó°ÏìÁè¼Ý20ÒŲ́É豸


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ArmisÑо¿ÈËÔ±ÔÚVxWorks RTOSÖз¢ÏÖ11¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´Ó°ÏìÁ˺½¿Õº½Ìì¡¢¹ú·À¡¢¹¤Òµ¡¢Ò½ÁÆ¡¢Æû³µ¡¢Ïû·Ñµç×ÓµÈÁìÓòµÄ20¶àÒŲ́É豸¡£ÕâЩ©¶´±»Í³³ÆΪURGENT/11£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÈƹý´«Í³µÄÄþ¾²½â¾ö·½°¸²¢ÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄÉ豸»òÀàËÆÓÀºãÖ®À¶Ò»Ñùµ¼Ö´ó¹æÄ£µÄÉ豸ÖжÏ£¬¶øÇÒÎÞÐèÓû§½»»¥¡£ÕâЩ©¶´´æÔÚÓÚVxWorks 6.5Ö®ºóµÄTCP/IPЭÒéÕ»ÖУ¬Ó°ÏìÁ˹ýÈ¥13ÄêÀ´Ðû²¼µÄËùÓÐVxWorks°æ±¾¡£¸Ã¹«Ë¾ÒѾ­ÔÚÉϸöÔÂÐû²¼ÁËÐÞ¸´²¹¶¡£¬µ«ÕâЩ²¹¶¡Í¨¹ýÉ豸³§É̵½´ïÏû·ÑÕß¿ÉÄÜ»¹ÐèÒªÒ»¶¨µÄʱ¼ä¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/vxworks-rtos-vulnerability.html

4¡¢Amcrest¼ÒÓÃÉãÏñÍ·ÑÏÖØ©¶´£¬¿ÉÔÊÐí¹¥»÷ÕßÔ¶³Ì¼àÌýÓû§



¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Äþ¾²³§ÉÌTenable·¢ÏÖAmcrest IP2M-841B¼ÒÓÃÉãÏñÍ·´æÔÚÒ»¸öÑÏÖØ©¶´£¬¿ÉÔÊÐí¹¥»÷Õßͨ¹ýHTTPÔ¶³Ì¼àÌýÉãÏñÍ·µÄÒôƵÊäÈë¡£¸Ã©¶´±»±ê־ΪCVE-2019-3948£¬Ó°ÏìÁËÉãÏñÍ·¹Ì¼þ°æ±¾V2.520.AC00.18.R£¬¶øÇÒÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÀûÓᣴËÍ⣬¸Ã²úÎïÒ²Ò×ÊÜÉí·ÝÑéÖ¤Èƹý©¶´£¨CVE-2017-7927£©¹¥»÷¡£AmcrestÒѾ­Ðû²¼Ïà¹ØÐÞ¸´²¹¶¡¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/iot-home-security-camera-allows-hackers-to-listen-in-over-http/

5¡¢ÖÇÀû1430Íò¹«ÃñÐÅϢй¶£¬Õ¼È«¹ú×ÜÈË¿Ú½ü80%


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


WizcaseÑо¿ÍŶӷ¢ÏÖÒ»¸öElasticsearchÊý¾Ý¿â̻¶ÁËÁè¼Ý1430ÍòÖÇÀû¹«ÃñµÄÑ¡¾ÙÐÅÏ¢£¬Õ¼¸Ã¹ú×ÜÈ˿ڵĽü80%¡£ÕâЩÐÅÏ¢°üÂÞÐÕÃû¡¢¼Òͥסַ¡¢ÐÔ±ð¡¢ÄêÁäºÍÄÉË°ºÅÂë¡£ÖÇÀûÑ¡¾Ù·þÎñServelµÄ·¢ÑÔÈËÈ·ÈÏÁËÕâЩÊý¾ÝµÄÕæʵÐÔ£¬µ«·ñÈϸ÷þÎñÆ÷ÊôÓÚËûÃÇ¡£¸Ã·¢ÑÔÈËÌåÏÖÕâЩÐÅÏ¢¶ÔÓ¦ÓÚ2017ÄêµÄÊý¾Ý£¬¿ÉÄÜÊǵÚÈý·½´ÓÆäÍøÕ¾ÉÏÊÕ¼¯»ã×ܵÃÀ´¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/voter-records-for-80-of-chiles-population-left-exposed-online/