ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ37ÖÜ
Ðû²¼Ê±¼ä 2019-09-23> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2019Äê9ÔÂ16ÈÕÖÁ22ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´43¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFastjson<=1.2.60Ô¶³Ì´úÂëÖ´ÐЩ¶´£»e-cologyÔ¶³Ì´úÂëÖ´ÐЩ¶´£»CODESYS V3 Web ServerÕ»Òç³ö©¶´£»VMware ESXi 'busybox'ÃüÁî×¢È멶´£»Schneider Electric BMXNOR0200H Ethernet/Serial RTU module¾Ü¾ø·þÎñ©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǶò¹Ï¶à¶û´ó²¿ÃŹ«ÃñÒþ˽й¶£¬°üÂÞ670Íò¶ùͯÐÅÏ¢£»Ê¨×Óº½¿Õ¹«Ë¾ÊýǧÍòÓû§¼Ç¼ÔÚ°µÍøй¶£»MITREÐû²¼2019ÄêCWE×îΣÏÕÈí¼þ´íÎóÁбíTop25£»AMD RadeonÇý¶¯·¨Ê½±»ÆØ´æÔÚÐéÄâ»úÌÓÒÝ©¶´£»ÈýÐǺÍLGÖÇÄÜÉ豸½«Óû§Ãô¸ÐÊý¾Ý·¢Ë͵½ºÏ×÷¹«Ë¾¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1. Fastjson<=1.2.60Ô¶³Ì´úÂëÖ´ÐЩ¶´
Fastjson´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://github.com/alibaba/fastjson/commit/05a7aa7f748115018747f7676fd2aefdc545d17a
2. e-cologyÔ¶³Ì´úÂëÖ´ÐЩ¶´
e-cology BeanShell×é¼þ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâÃüÁî¡£
https://help.aliyun.com/noticelist/articleid/1060057523.html?spm=5176.2020520154.sas.20.36a91e43Zt9Vx7
3. CODESYS V3 Web ServerÕ»Òç³ö©¶´
CODESYS V3 Web Servers´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë»òʹӦÓ÷¨Ê½Í߽⡣
https://www.codesys.com/fileadmin/data/customers/security/2019/Advisory2019-06_CDS-64543.pdf
4. VMware ESXi 'busybox'ÃüÁî×¢È멶´
VMware ESXi 'busybox'´¦ÖÃÎļþÃû´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâÃüÁî¡£
https://www.vmware.com/security/advisories/VMSA-2019-0013.html
5. Schneider Electric BMXNOR0200H Ethernet/Serial RTU module¾Ü¾ø·þÎñ©¶´
Schneider Electric BMXNOR0200H Ethernet/Serial RTU module´¦ÖôóÁ¿IEC 60870-5-104±¨ÎÄ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½Í߽⡣
https://www.schneider-electric.com/en/download/document/SEVD-2019-225-03/
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢¶ò¹Ï¶à¶û´ó²¿ÃŹ«ÃñÒþ˽й¶£¬°üÂÞ670Íò¶ùͯÐÅÏ¢
Ñо¿ÈËÔ±·¢ÏÖÒ»¼Òµ±µØ¹«Ë¾NovaestratµÄElasticsearch·þÎñÆ÷̻¶Á˶ò¹Ï¶à¶û´ó¶àÊý¹«ÃñµÄÒþ˽ÐÅÏ¢¡£¶ò¹Ï¶à¶ûµÄÈË¿Ú»ùÊýΪ1660Íò£¬¶ø¸ÃÊý¾Ý¿â°üÂÞ½ü2080ÍòÌõÓû§¼Ç¼£¬Áè¼ÝÁ˸ùúµÄÈË¿ÚÊý¾Ý£¬ÆäÔÒòÊÇÊý¾Ý¿âÖаüÂÞһЩÖظ´¼Ç¼ºÍËÀÍö¹«ÃñµÄ¼Ç¼¡£Ð¹Â¶µÄÊý¾Ý°üÂÞÐÕÃû¡¢¼ÒÍ¥³ÉÔ±/¼Ò×åÊ÷¡¢¹«Ãñ×¢²áÊý¾Ý¡¢²ÆÕþ¼°ÊÂÇéÐÅÏ¢¡¢³µÁ¾ÐÅÏ¢µÈ¡£Êý¾Ý¿âÖл¹°üÂÞÕþ¸®Ô±¹¤ÐÅÏ¢ºÍ677Íò¶ùͯÐÅÏ¢£¬ÒÔ¼°700ÍòÌõ²ÆÕþ¼Ç¼ºÍ250ÍòÌõ³µÁ¾¼Ç¼¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/database-leaks-data-on-most-of-ecuadors-citizens-including-6-7-million-children/
2¡¢Ê¨×Óº½¿Õ¹«Ë¾ÊýǧÍòÓû§¼Ç¼ÔÚ°µÍøй¶
ʨ×Óº½¿ÕÆìÏÂÁ½¼Òº½¿Õ¹«Ë¾µÄÊýǧÍòÌõÂÿͼǼÔÚ°µÍøÂÛ̳ÉÏй¶¡£ÕâЩÊý¾Ý´æ´¢ÔڿɹûÈ»·ÃÎʵÄAmazon´æ´¢Í°ÖУ¬¹²ÓÐÁ½¸öÊý¾Ý¿â£¬Ò»¸ö°üÂÞ2100ÍòÌõ¼Ç¼£¬ÁíÒ»¸ö°üÂÞ1400ÍòÌõ¼Ç¼£¬¸ÃĿ¼Ï»¹°üÂÞ2019Äê5Ô·ݴ´½¨µÄ±¸·ÝÎļþ£¬Ö÷ÒªÊôÓÚMalindo AirºÍThai Lion Air¡£ÁíÒ»¸ö±¸·ÝÎļþµÄÃû³ÆÊÇBatik Air£¬¸Ã¹«Ë¾µÄĸ¹«Ë¾Ò²ÊÇʨ×Óº½¿Õ¡£Ð¹Â¶µÄÐÅÏ¢°üÂÞÂÿ͵ÄÔ¤¶©ID¡¢¾ÓסµØÖ·¡¢µç»°ºÅÂë¡¢ÓÊÏäµØÖ·¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢»¤ÕÕºÅÂëºÍµ½ÆÚÈÕÆڵȡ£Ä¿Ç°»¹²»Çå³þÕâЩÊý¾ÝÊ×´Î鶵Äʱ¼ä£¬µ«¾Ý³ÆÖÁÉÙ´Ó8ÔÂ10ÈÕÆð¸ÃÊý¾Ý¿âÒÑÔÚÂÛ̳ÉÏÁ÷ͨ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/millions-of-lion-air-passenger-records-exposed-and-exchanged-on-forums/
3¡¢MITREÐû²¼2019ÄêCWE×îΣÏÕÈí¼þ´íÎóÁбíTop25
·ÇÓªÀû×éÖ¯MITERÐû²¼2019Äê×îΣÏÕµÄÈí¼þ©¶´ºÍ´íÎóÁбíTop25¡£Æ¾¾ÝMITRE£¬×îΣÏÕµÄÈí¼þ´íÎóÊÇCWE-119£¬Ëü±»ÃèÊöΪ¡°¶ÔÄڴ滺³åÇø½çÏÞÄÚ²Ù×÷µÄ²»ÕýÈ·ÏÞÖÆ¡±£¬¼´»º³åÇøÒç³öµ¼ÖµÄÔ½½ç¶Á»òд¡£ÅÅÔÚµÚ¶þλµÄÊÇCWE-79£¬±»ÃèÊöΪ¡°ÍøÒ³Éú³ÉÆÚ¼äÊäÈëÔì³ÉµÄ²»ÕýÈ··´Ó³¡±£¬¼´XSS¹¥»÷¡£µÚÈýÃûÔòÊÇCWE-20£¬¼´¡°²»ÕýÈ·µÄÊäÈëÑéÖ¤¡±¡£¸ÃÁбíÊÇ»ùÓÚMITERÊý¾Ý¿âÖеÄCVEÊý¾Ý¼°NVDÊý¾Ý¿âºÍCVSS»ñµÃµÄÐÅÏ¢£¬×ܹ²ÓÐԼĪ2.5Íò¸öCVEÌṩÁËÔ´Êý¾Ý¡£ÍêÕûÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/these-software-vulnerabilities-top-mitres-most-dangerous-list-in-2019/
4¡¢AMD RadeonÇý¶¯·¨Ê½±»ÆØ´æÔÚÐéÄâ»úÌÓÒÝ©¶´
˼¿ÆTalosÅû¶AMD ATI Radeon ATIDXX64.DLLÇý¶¯·¨Ê½ÖеÄÐéÄâ»úÌÓÒÝ©¶´¡£¸Ã©¶´´æÔÚÓÚAMD Radeon RX 550¼°550ϵÁÐÏÔ¿¨ÖУ¬¶øÇÒÖ»ÄÜÔÚÔËÐÐVMWare Workstation 15ʱ´¥·¢¡£Ñо¿ÈËÔ±½âÊͳƣ¬¿ÉÔÚVMwareÐéÄâ»úϵͳÖÐͨ¹ý¶ñÒâÏñËØ×ÅÉ«Æ÷ÔÚAMD ATIDXX64.DLLÇý¶¯·¨Ê½Öд¥·¢ÄÚ´æÔ½½çдÈ룬Õâ¿ÉÄܻᴥ·¢VMwareÀ´±öģʽµÄ©¶´£¬´Ó¶øÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£¸Ã©¶´Ó°ÏìÁËATIDXX64.DLLÇý¶¯·¨Ê½°æ±¾25.20.15031.5004ºÍ25.20.15031.9002¡£¸Ã©¶´£¨CVE-2019-5049£©µÄCVSSÆÀ·ÖΪ9.0¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/amd-radeon-cards-vmware-workstations/148406/
5¡¢ÈýÐǺÍLGÖÇÄÜÉ豸½«Óû§Ãô¸ÐÊý¾Ý·¢Ë͵½ºÏ×÷¹«Ë¾
Ñо¿ÈËÔ±·¢ÏÖ¼´Ê¹ÊÇÔÚÉ豸ÏÐÖÃʱ£¬ÈýÐÇ¡¢LGºÍRokuµÈ¹«Ë¾µÄÖÇÄܵçÊÓÒ²»áÏòºÏ×÷µÄ¿Æ¼¼¹«Ë¾·¢ËÍÃô¸ÐµÄÓû§Êý¾Ý¡£Æ¾¾ÝÁ½¸öÍŶӵĶÀÁ¢Ñо¿£¬ÖÇÄܵçÊÓµÄOTTƽ̨»á½«Óû§µÄÃô¸ÐÊý¾Ýй¶¸øFacebook¡¢ÑÇÂíÑ·¡¢¹È¸èºÍNetflixµÈ¹«Ë¾¡£µÚÒ»·Ý³ÂËßÑо¿ÁË81̨É豸£¬·¢ÏÖÓÐ72̨É豸½«Êý¾Ý·¢Ë͵½·ÇÖÆÔìÉ̵ÄÆäËü¹«Ë¾¡£µÚ¶þ·Ý³ÂËß·¢ÏÖ´ÓÖÇÄܵçÊÓ·¢Ë͵ÄÊý¾ÝÒ²Óë¹È¸èºÍFacebook¹ÜÀíµÄ¸ú×ÙÆ÷Óйأ¬Ñо¿ÈËÔ±³Æ89%µÄAmazon Fire TVƵµÀºÍ69%µÄRokuƵµÀ¶¼°üÂÞÓÃÓÚ¸ú×ÙÓû§ÊÕ¿´Ï°¹ßºÍÆ«ºÃÐÅÏ¢µÄ¸ú×ÙÆ÷¡£ÕâЩ¸ú×ÙÆ÷»¹¿ÉÒÔʶ±ðÉ豸ºÍʹÓÃλÖ㬰üÂÞÉ豸ÐòÁкźÍID¡¢Wi-FiÃû³ÆºÍMACµØÖ·µÈ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/smart-tvs-leak-data/148482/