ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ35ÖÜ

Ðû²¼Ê±¼ä 2020-09-01

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê08ÔÂ24ÈÕÖÁ30ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´55¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇRed Lion N-TronδÃ÷½Ó¿Ú©¶´£»FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯Â©¶´£»Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´ÐЩ¶´£»Foxit Studio Photo PSDÔ½½çд´úÂëÖ´ÐЩ¶´; Moog EXO Series EXVF5C-2¹ÜÀí¿ØÖÆ̨'statusbroadcast'ÈÎÒâÃüÁîÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇCiscoÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¶à¸ö²úÎïÖеÄ©¶´£»ClarotyÐû²¼2020ÄêÉÏ°ëÄêICS©¶´·ÖÎö³ÂËߣ»Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖôíÎóй¶3700ÍòÌõ¼Ç¼£»Î¢ÈíÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö©¶´£»CiscoÇ°Ô±¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Red Lion N-TronδÃ÷½Ó¿Ú©¶´


Red Lion N-Tron´æÔÚδÎĵµ»¯½Ó¿Ú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔROOTȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-240-01


2. FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource·´ÐòÁл¯Â©¶´


FasterXML jackson-databind br.com.anteros.dbcp.AnterosDBCPDataSource´æÔÚÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://github.com/FasterXML/jackson-databind/issues/2814


3. Advantech iView DeviceTreeTable exportTaskMgrReportĿ¼±éÀú´úÂëÖ´ÐЩ¶´


Advantech iView DeviceTreeTable exportTaskMgrReport´æÔÚĿ¼±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎĶÁȡϵͳÎļþ»òÕßÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1084/


4. Foxit Studio Photo PSDÔ½½çд´úÂëÖ´ÐЩ¶´


Foxit Studio Photo½âÎöPSDÎļþ´æÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔϵͳÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1078/


5. Moog EXO Series EXVF5C-2¹ÜÀí¿ØÖÆ̨'statusbroadcast'ÈÎÒâÃüÁîÖ´ÐЩ¶´


Moog EXO Series EXVF5C-2¹ÜÀí¿ØÖÆ̨'statusbroadcast'´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Ê¹ÓÃ'${IFS}'±äÁ¿ÈƹýÏÞÖÆ£¬¿ÉÒÔrootȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£

https://ioactive.com/moog-exo-series-multiple-vulnerabilities/



> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢CiscoÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¶à¸ö²úÎïÖеÄ©¶´


1.png


CiscoÐû²¼Äþ¾²¸üУ¬ÒÔÐÞ¸´Æä¶à¸ö²úÎïÖеÄ©¶´¡£´Ë´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄ½ÏΪÑÏÖصÄ©¶´ÎªTreck IP¶ÑÕ»ÖеÄ©¶´Ripple20£¬ÕâЩ©¶´¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢¾Ü¾ø·þÎñ£¨DoS£©»òÐÅϢй¶£»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏƾ¾Ý©¶´£¨CVE-2020-3446£©£¬¿É±»ÀûÓÃÒÔ¹ÜÀíԱȨÏÞ·ÃÎÊNFVIS CLI£»Ë¼¿ÆÖÇÄÜÈí¼þ¹ÜÀíÆ÷£¨SSM On-Prem£©µ±µØÌØȨÉý¼¶Â©¶´£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓƵ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢ÏÖЭÒéÔ¶³ÌÖ´Ðк;ܾø·þÎñ©¶´£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates


2¡¢ClarotyÐû²¼2020ÄêÉÏ°ëÄêICS©¶´·ÖÎö³ÂËß


2.png


¹¤ÒµÍøÂçÄþ¾²¹«Ë¾ClarotyÐû²¼2020ÄêÉÏ°ëÄêICS©¶´·ÖÎö³ÂËß¡£Claroty·ÖÎöÁËÐÂÌí¼Óµ½¹ú¼Ò©¶´Êý¾Ý¿â£¨NVD£©ÖеÄ365¸öICS©¶´ÒÔ¼°ICS-CERT£¨CISA£©Ðû²¼µÄͨ±¨Öк­¸ÇµÄ385¸ö©¶´¡£Óë2019ÄêͬÆÚÅû¶µÄ©¶´ÊýÁ¿Ïà±È£¬2020ÄêÉÏ°ëÄêÐÂÔöµ½NVDÖеÄ©¶´ÊýÁ¿Ô¼Äª¶à³ö10£¥¡£ÔÚËùʶ´ËÍ⩶´ÖУ¬ÓÐ70£¥ÒÔÉϵÄ©¶´¿É±»Ô¶³ÌÀûÓã¬Óн«½üÒ»°ë¿ÉÓÃÓÚÔ¶³ÌÖ´ÐдúÂ룬ÆäÖÐ41£¥µÄ©¶´¿ÉÈù¥»÷Õ߶ÁÈ¡Ó¦Ó÷¨Ê½Êý¾Ý£¬39£¥µÄ©¶´¿ÉÓÃÓÚDoS¹¥»÷£¬37£¥µÄ©¶´¿ÉÈƹýÄþ¾²»úÖÆ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/over-70-ics-vulnerabilities-disclosed-first-half-2020-remotely-exploitable


3¡¢Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖôíÎóй¶3700ÍòÌõ¼Ç¼


3.png


SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢ÏÖÁËRailYatriµÄûÓÐÃÜÂë±£»¤µÄElasticsearch·þÎñÆ÷£¬Ð¹Â¶3700ÍòÌõ¼Ç¼¿Í»§ºÍ¹«Ë¾Êý¾Ý£¬°üÂÞÓû§µÄÈ«Ãû¡¢ÄêÁä¡¢ÐÔ±ð¡¢Êµ¼ÊºÍµç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂë¡¢Ô¤¶©ÏêϸÐÅÏ¢¡¢GPSλÖÃÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄÇ°ËÄλºÍºóËÄλ¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý½øÐб£»¤Ö®Ç°£¬Meow»úÆ÷ÈËÓÚ8ÔÂ12ÈÕ¶ÔÆä·¢Éú¹¥»÷£¬É¾³ýÁ˳ý1GBÖ®ÍâµÄËùÓÐÊý¾Ý£¨×ܹ²43 GB£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/


4¡¢Î¢ÈíÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö©¶´


4.png


΢ÈíÐû²¼Â©¶´²¹¶¡£¬ÐÞ¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö©¶´¡£´Ë´ÎÐû²¼µÄ²¹¶¡·¨Ê½ÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´ºÍ2¸öÌáȨ©¶´£¬ÕâЩ©¶´¶¼ÊÇÓÉCisco TalosµÄÄþ¾²Ñо¿ÈËÔ±ÓÚ7Ô·ݷ¢ÏÖ¡£µÚÒ»¸öΪREAD_IMPLIES_EXEC personalityδǩÃû´úÂëÖ´ÐЩ¶´£¬µÚ¶þ¸öRCE©¶´´æÔÚÓÚ/proc/thread-self/ memÖС£´ËÍ⣬ȨÏÞ·ÃÎÊ¿ØÖƹ¦Ð§ÖдæÔÚÒ»¸öÌáȨ©¶´£¬¶øµÚ¶þ¸öÌáȨ©¶´´æÔÚÓÚAzure Sphere 20.06µÄuid_map¹¦Ð§ÖС£Î¢ÈíÌåÏÖ»áÈ·±£½â¾öÕâЩÎÊÌⲢΪ¿Í»§Ìṩ¸üУ¬µ«ÊǾܾøÐû²¼ÈκÎCVEs¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/four-more-bugs-patched-in-microsofts-azure-sphere-iot-platform/158643/


5¡¢CiscoÇ°Ô±¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú


5.png


˼¿ÆÇ°Ô±¹¤Sudhish Kasaba RameshÈÏ×ïÆäɾ³ýÁËWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú¡£¾ÝÆäÈÏ×ïЭÒéÖгÆ£¬ÆäÈÏ¿ÉÔÚÀëÖ°5¸öÔºóµÄ2018Äê9ÔÂ24ÈÕ£¬Î´¾­¹«Ë¾µÄÐí¿ÉÓÐÒâ·ÃÎÊ˼¿ÆµÄÔÆ»ù´¡¼Ü¹¹£¬²¢´ÓÆä×Ô¼ºµÄGoogle Cloud ProjectÕÊ»§Öв¿ÊðÁËÒ»¸ö´úÂ룬ɾ³ýÁË˼¿ÆWebEx TeamsÓ¦Ó÷¨Ê½µÄ456¸öÐéÄâ»ú¡£¾ÝϤ£¬¸Ãʼþµ¼ÖÂ16000¸öWebEx TeamsÕÊ»§±»¹Ø±ÕÁ˳¤´ïÁ½¸öÐÇÆÚ£¬Cisco»¨·ÑÁËԼĪ140ÍòÃÀÔªÀ´»Ö¸´ÆäÓ¦ÓÃÊܵ½µÄË𺦣¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§ÍË»¹ÁËÁè¼Ý100ÍòÃÀÔªµÄ¿îÏî¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/ex-cisco-employee-pleads-guilty-to-deleting-16k-webex-teams-accounts/158748/