ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ¿ò¼Ü³õ¸å £»£»£»£»£»Verizon Wireless·ì϶µ¼ÖÂÔ¼200Íò¿Í»§µÄºÏͬй¶

°ä²¼¹¦·ò 2019-09-11

1.ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ¿ò¼Ü³õ¸å


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº£¨NIST£©°ä²¼ÁËÒ»¸öÒþÖÔ¿ò¼Ü³õ¸å £¬ £¬£¬£¬£¬£¬ £¬£¬Ö¼ÔÚͨ¹ýÆóÒµ·çÏÕÖÎÀíÔ®ÊÔìóÒµ¸ÄÉÆÓ×ÎÒÒþÖÔ¡£¡£¡£¡£ ¡£¡£NIST°µÊ¾ £¬ £¬£¬£¬£¬£¬ £¬£¬ÒþÖÔ¿ò¼ÜÖ¼ÔÚͨ¹ýÈý¸öÊÂÏîÔ®ÊÔìóÒµ± £»£»£»£»£»¤Ó×ÎÒÒþÖÔ£ºÍ¨¹ýÔÚ·þÎñºÍ²úÆ·ÖÐÖ§³Ö·µÂ¾ö²ßÀ´³ÉÁ¢¿Í»§ÐÅÀµ £»£»£»£»£»ÍƹãºÏ¹æÊ¹Ãü;ÒÔ¼°ÍƽøÓë¿Í»§ºÍ¼à¹Ü»ú¹¹¾ÍÒþÖÔʵ¼Ê½øÐйµÍ¨¡£¡£¡£¡£ ¡£¡£¸ÃÕþ²ß×ñÑ­ÍøÂ簲ȫ¿ò¼ÜµÄ½á¹¹ £¬ £¬£¬£¬£¬£¬ £¬£¬ÓÉÖ÷Ìâ¡¢¸Å¿öºÍÖ´Ðвã×é³É¡£¡£¡£¡£ ¡£¡£Ö÷ÌⲿÃÅÖ¼ÔÚÍÆ½ø¹ØÓÚÒþÖÔ± £»£»£»£»£»¤ÔËÓªºÍ½øÕ¹Á˾ֵĶԻ° £¬ £¬£¬£¬£¬£¬ £¬£¬¶ø¸Å¿ö²¿ÃÅÔòÍÆ¶¯Âú×ã×é֯ʹÃüºÍÒþÖÔ¼ÛÖµµÄ»î¶¯ºÍÁ˾ֵÄÓÅÏÈÖÈÐò¡£¡£¡£¡£ ¡£¡£Ö´ÐвãÔò¶Ô×éÖ¯´¦ÖÃÒþÖÔ·çÏÕÁ÷³ÌµÄ³ä·ÖÐÔ½øÐйµÍ¨ºÍ¾ö²ßÌṩ֧³Ö¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.executivegov.com/2019/09/nist-issues-preliminary-draft-of-privacy-framework/


2.Verizon Wireless·ì϶µ¼ÖÂÔ¼200Íò¿Í»§µÄºÏͬй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ó¢¹ú°²È«×êÑÐÔ±Daley Bee·¢ÏÖVerizon WirelessϵͳµÄÒ»¸ö×ÓÓò´æÔÚ²»°²È«µÄÖ±½Ó¶ÔÏóÒýÓã¨IDOR£©·ì϶ £¬ £¬£¬£¬£¬£¬ £¬£¬¿ÉÄܱ»ºÚ¿ÍÀûÓÃÀ´»ñÈ¡200Íò¿Í»§ºÏͬ¡£¡£¡£¡£ ¡£¡£¸Ã×ÓÓòÃûÊÇtelestore.verizonwireless.com £¬ £¬£¬£¬£¬£¬ £¬£¬Ëƺõ±»¹«Ë¾Ô±¹¤ÓÃÀ´½Ó¼ûÄÚ²¿PoS¹¤¾ßºÍ²é¿´¿Í»§ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£½øÒ»²½·ÖÎö·¢ÏÖÁËÒ»¸öÖ¸ÏòPDFÌåʽµÄVerizon¿Í»§ºÏͬµÄURL £¬ £¬£¬£¬£¬£¬ £¬£¬×êÑÐÈËԱͨ¹ýÅú¸ÄGET²ÎÊýÖµ¿É½Ó¼ûÔ¼200Íò¸öºÏͬ £¬ £¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢É豸ÐͺźÍÐòÁкÅÒÔ¼°¿Í»§ÊðÃûµÈÄÚÈÝ¡£¡£¡£¡£ ¡£¡£Verizon֤ʵÁËÕâÒ»·ì϶ £¬ £¬£¬£¬£¬£¬ £¬£¬²¢ÔÚ½Óµ½Í¨ÖªµÄÒ»¸öÔº󽨸´Á˸ÃÎÊÌâ¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/vulnerabilities-exposed-2-million-verizon-customer-contracts


3.Stealth FalconкóÃÅÀûÓÃWindows BITS·þÎñÇÔÈ¡Êý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ESET×êÑÐÈËÔ±·¢ÏÖAPT×éÖ¯Stealth FalconµÄкóÃÅÀÄÓÃWindows BITS·þÎñÀ´°µ²ØÆäÓëºÅÁîºÍ½ÚÔ죨C£¦C£©·þÎñÆ÷µÄͨѶÁ÷Á¿¡£¡£¡£¡£ ¡£¡£Windows BITSÊÇ΢ÈíÏòÈ«ÇòÓû§·¢ËÍWindows¸üеÄĬÈÏϵͳ £¬ £¬£¬£¬£¬£¬ £¬£¬×êÑÐÈËÔ±ÒÔΪ¸ÃºóÃÅÕâÑù×öÊÇΪÁËÈÆ¹ý·À»ðǽ £¬ £¬£¬£¬£¬£¬ £¬£¬ÓÉÓÚÆóÒµÒÔΪBITSÁ÷Á¿ºÜ¿ÉÄÜÔ̺¬Èí¼þ¸üжøÆ«²îÓÚºöÂÔËü¡£¡£¡£¡£ ¡£¡£ESET½«¸ÃºóÃŶ¨ÃûΪWin32/StealthFalcon £¬ £¬£¬£¬£¬£¬ £¬£¬ËüÔÊÐí¹¥»÷ÕßÔÚÊÜϰȾµÄϵͳ¸ßµÍÔØºÍÔËÐÐÆäËü¶ñÒâ´úÂë»òÇÔÈ¡Êý¾Ý·¢Ë͵½Ô¶³Ì·þÎñÆ÷¡£¡£¡£¡£ ¡£¡£¸ÃºóÃÅËÆºõÊÇ2015Äê´´½¨µÄ £¬ £¬£¬£¬£¬£¬ £¬£¬Ê¹ÓÃÁËÓë2016ÄêCitizen Lab»ã±¨ÖÐÏêÊöµÄPowershellºóÃÅÒ»ÑùµÄC£¦CÓòÃû¡£¡£¡£¡£ ¡£¡£ESETûÓÐй©ÐºóÃŵĹ¥»÷Çé¿ö»òÖ¸±ê¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/91019/apt/stealth-falcon-backdoor-bits.html


4.ZDIÅû¶Red Lion¹«Ë¾HMI²úÆ·ÖеĶà¸ö°²È«·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±ÔÚÃÀ¹úRed Lion¹«Ë¾Ôì×÷µÄÈË»ú½çÃæ£¨HMI£©±à³ÌÈí¼þÖз¢ÏÖ¶à¸ö°²È«·ì϶¡£¡£¡£¡£ ¡£¡£Red LionÊÇSpectrisµÄ×Ó¹«Ë¾ £¬ £¬£¬£¬£¬£¬ £¬£¬Æ¾¾ÝÃÀ¹úCISAµÄÐÅÏ¢ £¬ £¬£¬£¬£¬£¬ £¬£¬Red LionµÄ²úÆ·ÔÚÈ«ÇòÁìÓòÄÚʹÓà £¬ £¬£¬£¬£¬£¬ £¬£¬ÖØÒªÓÃÓڹؼüÔì×÷ÁìÓò¡£¡£¡£¡£ ¡£¡£Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±·¢ÏÖRed LionµÄCrimson±à³ÌÈí¼þ £¬ £¬£¬£¬£¬£¬ £¬£¬³ö¸ñÊÇ3.0¼°Ö®Ç°°æ±¾ºÍ3.112.00֮ǰµÄ3.1°æ±¾´æÔÚËĸö·ì϶ £¬ £¬£¬£¬£¬£¬ £¬£¬Ô̺¬CVE-2019-10996¡¢CVE-2019-10978¡¢CVE-2019-10984ºÍCVE-2019-10990¡£¡£¡£¡£ ¡£¡£ÆäÖÐ×îÑϳÁµÄÒ»¸ö·ì϶ÔÊÐí¹¥»÷Õßͨ¹ýÓÕʹָ±êÓû§´ò¿ª¶ñÒâCD3Îļþ £¬ £¬£¬£¬£¬£¬ £¬£¬ÔÚµ±Ç°¹ý³ÌµÄ¸ßµÍÎÄÖÐÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£ÁíÒ»¸ö·ì϶ÓëÓ²±àÂëµÄÍ´´¦Óйء£¡£¡£¡£ ¡£¡£Red Lion°ä²¼ÁËCrimson 3.1°æ±¾3112.00ÒÔ½¨²¹·ì϶ £¬ £¬£¬£¬£¬£¬ £¬£¬µ«·î¸æ¿Í»§Ëü²»³ïËã°ä²¼Crimson 3.0µÄ¸üС£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/several-vulnerabilities-found-red-lion-hmi-software


5.˼¿ÆTalosÅû¶NETGEARÎÞÏß·ÓÉÆ÷ÖеÄDoS·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


˼¿ÆTalos·¢ÏÖNETGEAR N300ϵÁÐÎÞÏß·ÓÉÆ÷Ô̺¬Á½¸ö»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£ ¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÏò·ÓÉÆ÷µÄ·ÖÆçÖ°ÄÜ·¢ËͶñÒâSOAPºÍHTTPÒªÇóÀ´ÀûÓÃÕâЩ·ì϶ £¬ £¬£¬£¬£¬£¬ £¬£¬´Ó¶øµ¼ÖÂÆäÆëÈ«±ÀÀ£¡£¡£¡£¡£ ¡£¡£µÚÒ»¸ö·ì϶ÊÇCVE-2019-5054 £¬ £¬£¬£¬£¬£¬ £¬£¬´æÔÚÓÚHTTP·þÎñÆ÷µÄ»á»°´¦ÖÃÖ°ÄÜÖÐ £¬ £¬£¬£¬£¬£¬ £¬£¬·¢Ë͵½Éí·ÝÑéÖ¤Ò³ÃæµÄ¿ÕUser-Agent×Ö·û´®HTTPÒªÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓà £¬ £¬£¬£¬£¬£¬ £¬£¬´Ó¶øµ¼ÖÂHTTP·þÎñ±ÀÀ£¡£¡£¡£¡£ ¡£¡£µÚ¶þ¸ö·ì϶CVE-2019-5055´æÔÚÓÚÖ÷»ú½Ó¼ûµãÊØ»¤·¨Ê½£¨hostapd£©ÖÐ £¬ £¬£¬£¬£¬£¬ £¬£¬·¢Ë͵½<WFAWLANConfig£º1££PutMessage>·þÎñµÄÎÞЧÐòÁÐSOAPÒªÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓà £¬ £¬£¬£¬£¬£¬ £¬£¬´Ó¶øµ¼ÖÂhostapd·þÎñ±ÀÀ£¡£¡£¡£¡£ ¡£¡£TalosÈ·ÈÏN300 WNR2000v5·ÓÉÆ÷£¨¹Ì¼þ°æ±¾V1.0.0.70£©Êܵ½Ó°Ïì¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2019/09/vuln-spotlight-Netgear-N300-routers-DoS-sept-2019.html


6.΢Èí°ä²¼9Ô°²È«¸üР£¬ £¬£¬£¬£¬£¬ £¬£¬½¨¸´Á½¸ö0day


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢ÈíÔÚ9ÔµÄWindows°²È«¸üÐÂÖн¨¸´ÁË80¸ö·ì϶ £¬ £¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬17¸öÑϳÁ·ì϶¡£¡£¡£¡£ ¡£¡£ÓÐÁ½¸ö·ì϶ÊÇ0day £¬ £¬£¬£¬£¬£¬ £¬£¬ÔÚ΢Èí°ä²¼²¹¶¡Ö®Ç°ËüÃÇÒÑÔÚÒ°±í±»ÀûÓᣡ£¡£¡£ ¡£¡£ÕâÁ½¸ö·ì϶±ðÀëÊÇWindowsͨÓÃÈÕÖ¾Îļþϵͳ£¨CLFS£©Çý¶¯·¨Ê½ÖеÄEoP£¨CVE-2019-1214£©ºÍÓ°Ïìws2ifsl.sys£¨Winsock£©·þÎñµÄEoP£¨CVE-2019-1215£© £¬ £¬£¬£¬£¬£¬ £¬£¬Î¢ÈíûÓÐÅû¶·ì϶ÔÚÒ°±íÀûÓõĸü¶àϸ½Ú¡£¡£¡£¡£ ¡£¡£±¾ÔÂ΢ÈíÒ²½¨¸´ÁËÔ¶³Ì×ÀÃæºÍ̸ÖеÄÁ½¸ö·ì϶ £¬ £¬£¬£¬£¬£¬ £¬£¬Ô̺¬CVE-2019-1290ºÍCVE-2019-1291¡£¡£¡£¡£ ¡£¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-patches-two-zero-days-in-massive-september-2019-patch-tuesday/