ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ04ÖÜ

Ðû²¼Ê±¼ä 2020-02-04

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê01ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´42¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Webex Video Mesh WEB½Ó¿ÚÈÎÒâÃüÁîÖ´ÐЩ¶´; Ruckus Wireless Unleashed emfdÈÎÒâOSÃüÁîÖ´ÐЩ¶´£»Trustwave ModSecurity Transaction::addRequestHeader¾Ü¾ø·þÎñ©¶´£»Honeywell Maxpro VMS & NVR·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»Philips Hue Bridge ZCL¶ÑÒç³ö©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀ¹ú¹ú¼Ò³ß¶È¼¼ÊõÑо¿ÔºÐû²¼Òþ˽·çÏÕ¹ÜÀí¿ò¼Ü1.0°æ£»GDPR¼à¹Ü»ú¹¹Æù½ñΪֹÒÑ·£¿î1.26ÒÚÃÀÔª£»Î¢Èíй¶2.5ÒÚÌõºô½ÐÖÐÐļǼ£¬¿Í»§ÓÊÏä¼°IPµØַ̻¶£»Ñо¿ÈËÔ±Åû¶FortiSIEMÖеÄÓ²±àÂëSSHÃÜԿ©¶´£»Æ»¹ûÐû²¼Í¸Ã÷¶È³ÂËߣ¬Åû¶¸÷¹úÕþ¸®ÇëÇóÆ»¹ûÓû§Êý¾ÝÇé¿ö¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Cisco Webex Video Mesh WEB½Ó¿ÚÈÎÒâÃüÁîÖ´ÐЩ¶´


Cisco Webex Video Mesh WEB½Ó¿Ú´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔrootȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200108-webex-video


2. Ruckus Wireless Unleashed emfdÈÎÒâOSÃüÁîÖ´ÐЩ¶´


Ruckus Wireless Unleashed emfd admin/_cmdstat.jsp²»ÕýÈ·´¦ÖÃxcmd=import-categoryÊôÐÔ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄPOSTÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî¡£


https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.html


3. Trustwave ModSecurity Transaction::addRequestHeader¾Ü¾ø·þÎñ©¶´


Trustwave ModSecurity Transaction::addRequestHeader´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɽøÐоܾø·þÎñ¹¥»÷¡£


https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-denial-of-service-details-cve-2019-19886/


4. Honeywell Maxpro VMS & NVR·´ÐòÁл¯´úÂëÖ´ÐЩ¶´


Honeywell Maxpro VMS & NVR´¦ÖÃWEBÇëÇó´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.us-cert.gov/ics/advisories/icsa-20-021-01


5. Philips Hue Bridge ZCL¶ÑÒç³ö©¶´


Philips Hue Bridge´¦Ö󬳤ZCL×Ö·û´®´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www2.meethue.com/en-us/support/release-notes/bridge


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÃÀ¹ú¹ú¼Ò³ß¶È¼¼ÊõÑо¿ÔºÐû²¼Òþ˽·çÏÕ¹ÜÀí¿ò¼Ü1.0°æ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú¹ú¼Ò³ß¶È¼¼ÊõÑо¿Ôº£¨NIST£©ÉÏÖÜÐû²¼ÁËÒþ˽¿ò¼Ü1.0°æ£¬¸Ã¹¤¾ßÖ¼ÔÚ×ÊÖú×éÖ¯¹ÜÀíÒþ˽·çÏÕ¡£NISTÓÚ2019Äê9ÔÂÐû²¼ÁËÒþ˽¿ò¼Ü³õ¸å²¢ÊÕ¼¯¹«ÖÚÒâ¼û£¬¸Ã»ú¹¹×î³õÏ£ÍûÔÚ2019Äêµ×֮ǰÐû²¼1.0°æ£¬µ«Ö±µ½1ÔÂ16ÈÕ²ÅÕýʽÐû²¼¡£NISTÒþ˽¿ò¼ÜÖ¼ÔÚͨ¹ý¹Ø×¢Èý¸öÖ÷Òª·½ÃæÀ´×ÊÖúÖÖÖÖ¹æÄ£ºÍ¸÷¸ö²¿ÃŵÄ×éÖ¯¹ÜÀíÒþ˽·çÏÕ£ºÔÚ¿ª·¢²úÎï»ò·þÎñʱҪ¿¼Âǵ½Òþ˽¡¢½»Á÷Òþ˽¹ßÀýÒÔ¼°¿ç×éÖ¯µÄЭ×÷¡£¸Ã¿ò¼Ü°üÂÞÈý¸öÖ÷Òª²¿ÃÅ£ººËÐÄ¡¢ÌáÒªºÍʵÏֲ㡣ºËÐÄÌṩһ×éϸ»¯µÄ»î¶¯ºÍ½á¹û£¬ÆäÄ¿µÄÊÇʵÏÖÄÚ²¿Ïàͬ¡£ÌáÒª²ãÌåÏÖ×éÖ¯ÒÑÈ·¶¨ºËÐÄÖ°ÄÜ¡¢Àà±ðºÍ×ÓÀà´ËÍâÓÅÏȼ¶±ð¡£×îºó£¬ÊµÊ©²ã¿É×ÊÖú×éÖ¯ÓÅ»¯ÊµÏÖÌáÒª²ãËùÐèµÄ×ÊÔ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/nist-releases-framework-privacy-risk-management


2¡¢GDPR¼à¹Ü»ú¹¹Æù½ñΪֹÒÑ·£¿î1.26ÒÚÃÀÔª


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ò»ÏîеÄÊӲ췢ÏÖ£¬Æù½ñΪֹ¼à¹Ü»ú¹¹ÒѶÔÊý¾Ýй¶ºÍÆäËûGDPRÇÖȨÐÐΪ´¦ÒÔÁ˼ÛÖµ1.26ÒÚÃÀÔªµÄ·£¿î¡£Æ¾¾ÝDLA PiperµÄGDPRÊý¾ÝÎ¥¹æÊӲ죬Êý¾Ý±£»¤¼à¹Ü»ú¹¹ÔÚ2018Äê5ÔÂ25ÈÕÖÁ2020Äê1ÔÂ27ÈÕÆÚ¼ä¶ÔGDPRÏà¹ØµÄ·£¿îΪ1.14ÒÚÅ·Ôª£¨Ô¼ºÏ1.26ÒÚÃÀÔª/ 9,700ÍòÓ¢°÷£©¡£Õâ¼Ò¹ú¼ÊÂÉʦÊÂÎñËùÖ¸³ö£¬·¨¹ú¡¢µÂ¹úºÍ°ÂµØÀûµÄ·£¿î×ܶî×î¸ß£¬·Ö±ðΪ5100ÍòÅ·Ôª£¬2450ÍòÅ·ÔªºÍ1800ÍòÅ·Ôª¡£¸Ã³ÂËß²¢Î´º­¸ÇÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¶ÔÓ¢¹úº½¿Õ¹«Ë¾£¨British Airways£©´¦ÒÔ1.83ÒÚÓ¢°÷µÄGDPR·£¿î¼°¶ÔÍòºÀ¹ú¼Ê¹«Ë¾£¨Marriott International£©½øÐÐ9990ÍòÓ¢°÷µÄGDPR·£¿î£¬ÒòΪ½ØÖÁ³ÂËßÍê³ÉʱICOÉÐδ×îÖÕÈ·¶¨´¦ÒÔ·£¿î¡£


Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/gdpr-regulators-have-imposed-126m-in-fines-thus-far-finds-survey/


3¡¢Î¢Èíй¶2.5ÒÚÌõºô½ÐÖÐÐļǼ£¬¿Í»§ÓÊÏä¼°IPµØַ̻¶


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


È¥ÄêÄêµ×£¬ComparitechµÄÄþ¾²Ñо¿ÍŶӷ¢ÏÖÁ˼¸Ì¨·þÎñÆ÷£¬Ã¿Ì¨·þÎñÆ÷¶¼°üÂÞÓëMicrosoftÖ§³ÖÊðÀíºÍ¿Í»§ÏàͬµÄ2.5ÒÚºô½ÐÖÐÐļǼ¡£ÕâЩ¼Ç¼ËùÁýÕÖµÄʱ¼ä¶ÎΪ2005ÄêÖÁ2019Äê12Ô£¬Æ䲢ûÓÐʹÓÃÃÜÂë±£»¤»ò¼ÓÃÜ£¬ÕâÒ²Òâζ×Å£¬ÈκοÉÒÔ·ÃÎÊ»¥ÁªÍøµÄÈ˶¼¿ÉÒÔ¶ÔÆä½øÐзÃÎÊ¡£´ó¶àÊý¸öÈËÉí·ÝÐÅÏ¢ÒѴӼǼÖÐɾ³ý¡£µ«ÊÇ£¬ÈÔÈ»´æÔÚ´óÁ¿ÒÔ´¿Îı¾¸ñʽ´æ´¢µÄÐÅÏ¢£¬°üÂÞ£º¿Í»§µç×ÓÓʼþµØÖ·¡¢IPµØÖ·¡¢Î»Öá¢CSSÉùÃ÷ºÍ°¸ÀýµÄÃèÊö¡¢MicrosoftÖ§³ÖÊðÀíµç×ÓÓʼþ¡¢°¸Àý±àºÅ¡¢°¸Àý½â¾ö·½°¸£¬°¸Àý±¸×¢ºÍ±ê־Ϊ¡°»úÃÜ¡±µÄÄÚ²¿×¢ÊÍ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/microsoft-exposes-250-million-call/


4¡¢Ñо¿ÈËÔ±Åû¶FortiSIEMÖеÄÓ²±àÂëSSHÃÜԿ©¶´


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CyberaµÄÄþ¾²×¨¼ÒAndrew Klaus·¢ÏÖFortinetÄþ¾²ÐÅÏ¢ºÍʼþ¹ÜÀíÆ÷ FortiSIEMÖеÄÓ²±àÂëSSH¹«Ô¿Â©¶´£¬¿É±»ÀÄÓÃÓÚ·ÃÎÊFortiSIEM Supervisor¡£¸ÃÓ²±àÂëSSHÃÜÔ¿ÊôÓÚÓû§¡°tunneluser¡±¡£ÔÚËùÓа²×°Ö®¼ä¶¼Ïàͬ¡£Ê¹ÓôËÃÜÔ¿µÄ¹¥»÷Õß¿ÉÒÔÒÔ¸ÃÓû§Éí·ÝÀÖ³Éͨ¹ýFortiSIEM Supervisor½øÐÐÉí·ÝÑéÖ¤¡£ËäÈ»¸ÃÓû§µÄshell½öÏÞÓÚÔËÐнű¾/opt/phoenix/phscripts/bin/tunnelshell£¬SSHÈÏÖ¤ÈÔÈ»ÊÇÀֳɵÄ¡£FortinetÐû²¼Äþ¾²Í¨¸æ³Æ£¬¸Ã©¶´µÄ±àºÅÊÇ CVE-2019-17659£¬Ëü¿Éµ¼Ö¾ܾø·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/96649/security/hardcoded-ssh-key-fortinet.html


5¡¢Æ»¹ûÐû²¼Í¸Ã÷¶È³ÂËߣ¬Åû¶¸÷¹úÕþ¸®ÇëÇóÆ»¹ûÓû§Êý¾ÝÇé¿ö


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


1ÔÂ18ÈÕ£¬Æ»¹ûÖÜÎåÐû²¼ÁË°ëÄê¶È͸Ã÷¶È³ÂËߣ¬Åû¶Á˸÷¹úÕþ¸®ÔÚÈ«Çò·¶Î§ÄÚÏòÆäË÷È¡Óû§Êý¾ÝµÄ´ÎÊý¡£Æ¾¾ÝÆ»¹ûÐû²¼µÄ³ÂËߣ¬ÔÚ2019Äê1ÔÂ1ÈÕÖÁ6ÔÂ30ÈÕÖ®¼ä£¬¸÷¹úÕþ¸®Ìá³öÁË31778´ÎÉ豸ÇëÇ󣬱È2018ÄêÉÏ°ëÄêÔö¼ÓÁËÔ¼500´Î¡£ÕâÀàÐÅÏ¢°üÂÞÄÄЩÓû§ÓëÄÄЩÉ豸Ïà¹ØÁª£¬ÒÔ¼°¹ºÖᢿͻ§·þÎñºÍάÐÞÐÅÏ¢¡£Æ»¹ûÔÚÆäÖÐ82%µÄʱºòÂú×ãÁ˶Է½µÄÒªÇ󡣵¹úÌá³öÉ豸ҪÇóÔÙ´Îλ¾Ó°ñÊ×£¬µ½´ï13558´Î£¬ÃÀ¹úÔÚ6¸öÔÂÄÚÌá³öÁË4796´ÎÉ豸ÇëÇó¡£ÕÊ»§ÇëÇó£¨ÀýÈ磬ÓйØiCloudºÍiTunesÕÊ»§µÄÏêϸÐÅÏ¢£©ÔÚ6¸öÔÂÄÚµ½´ïÁË6480´Î¡£Æ»¹ûÔÚ85£¥µÄÇé¿ö϶¼ÊÐÌṩÏêϸÐÅÏ¢¡£´ó²¿ÃÅÕ˺ÅÇëÇóÀ´×ÔÃÀ¹ú£¬µ½´ï3619´Î¡£


Ô­ÎÄÁ´½Ó£º

https://www.apple.com/legal/transparency/pdf/requests-2019-H1-en.pdf