ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ08ÖÜ
°ä²¼¹¦·ò 2020-02-24> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê02ÔÂ17ÈÕÖÁ23ÈÕ¹²ÊÕ¼°²È«·ì϶51¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇB&R Industrial Automation Automation Studio SNMP·þÎñÊÚȨ·ì϶; Apache Tomcat AJPconnectorÎļþÔ̺¬·ì϶£»£»£»£»£»Adobe Media EncoderÔ½½çд´úÂëÖ´Ðзì϶£»£»£»£»£»Cisco Enterprise NFV Infrastructure SoftwareÉý¼¶×é¼þÑéÖ¤·ì϶£»£»£»£»£»Ansible pipe lookup²å¼þËÁÒâºÅÁîÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÖйúÈËÃñÒøÐа䲼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·£»£»£»£»£»Apache TomcatÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©£»£»£»£»£»°²È«×êÑÐÈËÔ±Åû¶΢Èí¶à¸ö×ÓÓòÃû±»½Ù³ÖÎÊÌ⣻£»£»£»£»ÃÀ¹úÌìÈ»Æø¹Ü·ÔËÓªÉÌÔâµ½ÀÕË÷Èí¼þ¹¥»÷£»£»£»£»£»ÒÁÀʺڿÍÀûÓÃVPNÈí¼þ·ì϶¹¥»÷È«ÇòµÄÆóÒµºÍµ±¾Ö»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1. B&R Industrial Automation Automation Studio SNMP·þÎñÊÚȨ·ì϶
B&R Industrial Automation Automation Studio SNMP·þÎñ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÅú¸Ä·þÎñÅäÖᣡ£¡£¡£¡£¡£¡£¡£
https://www.us-cert.gov/ics/advisories/icsa-20-051-01
2. Apache Tomcat AJPconnectorÎļþÔ̺¬·ì϶
Apache Tomcat AJPconnector´æÔÚʵÏÖȱµãµ¼ÖÂÓйزÎÊý¿É¿Ø£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿É¶ÁȡϵͳÎļþ»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://mp.weixin.qq.com/s/qIG_z9imxdLUobviSv7knw
3. Adobe Media EncoderÔ½½çд´úÂëÖ´Ðзì϶
Adobe Media Encoder´¦ÖÃÎļþ´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓÃÓÚ½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/media-encoder/apsb20-10.html
4. Cisco Enterprise NFV Infrastructure SoftwareÉý¼¶×é¼þÑéÖ¤·ì϶
Cisco Enterprise NFV Infrastructure SoftwareÉý¼¶×é¼þ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Éý¼¶¶ñÒâ¹Ì¼þ£¬£¬£¬£¬£¬£¬Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-codex-shs4NhvS
5. Ansible pipe lookup²å¼þËÁÒâºÅÁîÖ´Ðзì϶
Ansible pipe lookup²å¼þsubprocess.Popen()´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
https://access.redhat.com/security/cve/cve-2020-1734
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÖйúÈËÃñÒøÐа䲼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·
ÖйúÈËÃñÒøÐÐÏ·¢¡¶¹ØÓÚ<ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶>ÐÐÒµ³ß¶ÈµÄ֪ͨ¡·£¨Òø·¢[2020]35ºÅ£©£¬£¬£¬£¬£¬£¬°ä²¼ÐÂ°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·(JR/T 0068-2020)£¬£¬£¬£¬£¬£¬¸Ã°æ±¾ÊÇ2012°æ¹æ·¶(JR/T 0068-2012)µÄ´úÌæ¶©Õý°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ÐÂ°æ¹æ·¶ÓÐÈý¸ö³Áµã¶©ÕýÄÚÈÝ£º1¡¢Õë¶Ôм¼Êõ³öÏÖºÍÀûÓÃÌá³öÁËÐµİ²È«ÒªÇó£¨ÀýÈçÔö³¤ÁËÐé¹¹»¯¡¢ÔÆÍÆË㰲ȫÓйØÒªÇ󣬣¬£¬£¬£¬£¬Ôö³¤¹úÃÜSMϵÁÐËã·¨ÓйصݲȫҪÇ󣬣¬£¬£¬£¬£¬Ôö³¤¶Ô°²È«µ¥ÔªºÍÒÆ¶¯ÖÕ¶ËÖ§¸¶¿ÉÐÅ»·¾³ÓйØÒªÇ󣩣»£»£»£»£»2¡¢¾ÍеÄÒµÎñºÍ¼à¹ÜÒªÇó½øÐÐÁ˲¹³äºÍÃ÷È·£¨ÀýÈçÔö³¤ÁËÌõÂëÖ§¸¶¡¢ÂòÂô°²È«ËøºÍ¢ò¡¢¢óÀàÕË»§µÄÓйØÒªÇ󣩣»£»£»£»£»3¡¢³ÁÐÂÊáÀí²¢ÌáÉý¹ØÓÚÒµÎñÂ½ÐøÐÔÓë¿àÄѸ´Ô¡¢°²È«ÊÂÎñÓëÓ¦¼±ÏìÓ¦µÄ°²È«ÒªÇ󡣡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cebnet.com.cn/20200219/102639904.html
2¡¢Apache TomcatÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©
Apache Tomcat·þÎñÆ÷´æÔÚÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶¶ÁÈ¡»òÔ̺¬TomcatÉÏËùÓÐwebappĿ¼ÏµÄËÁÒâÎļþ£¬£¬£¬£¬£¬£¬È磺webappÅäÖÃÎļþ»òÔ´´úÂëµÈ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÓëTomcat AJPºÍ̸Óйأ¬£¬£¬£¬£¬£¬Tomcat AJP ConnectorĬÈÏÅäÖÃϼ´Îª¿ªÆô״̬£¬£¬£¬£¬£¬£¬²¢ÇÒ¼àÌý¶Ë¿Ú8009¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËTomcat 6/7/8/9È«°æ±¾£¬£¬£¬£¬£¬£¬Apache¹Ù·½ÒѰ䲼9.0.31¡¢8.5.51¼°7.0.100°æ±¾Õë¶Ô´Ë·ì϶½øÐн¨¸´£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÏÂÔØÊ¹Óᣡ£¡£¡£¡£¡£¡£¡£ÓÉÓÚTomcat 6ÒѾÖÕ³¡ÊØ»¤£¬£¬£¬£¬£¬£¬½¨ÒéÓû§Éý¼¶µ½×îÐÂÊÜÖ§³ÖµÄTomcat°æ±¾ÒÔÃâÔâ·ê¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cnvd.org.cn/flaw/show/CNVD-2020-10487
3¡¢°²È«×êÑÐÈËÔ±Åû¶΢Èí¶à¸ö×ÓÓòÃû±»½Ù³ÖÎÊÌâ
NIC.gp°²È«×êÑÐÔ±Michel GaschetÖ¸³ö΢Èí´æÔÚ¶à¸ö×ÓÓòÃû½Ù³ÖÎÊÌ⣬£¬£¬£¬£¬£¬ÕâЩ×ÓÓòÃû¿ÉÄܱ»½Ù³ÖºÍÓÃÓÚ¹¥»÷Óû§¡¢Ô±¹¤»òÏÔʾÀ¬»øÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ´ÓǰÈýÄêÖУ¬£¬£¬£¬£¬£¬GaschetÒ»ÏòÔÚÏò΢Èí»ã±¨´øÓÐÃýÎóÅäÖõÄDNS¼Í¼µÄ×ÓÓòÃû£¬£¬£¬£¬£¬£¬ÀýÈç2017ÄêËû»ã±¨ÁË21¸öÒ×±»½Ù³ÖµÄmsn.com×ÓÓòÃû£¬£¬£¬£¬£¬£¬2019ÄêËûÓֻ㱨ÁË142¸öÅäÖÃÃýÎóµÄmicrosoft.com×ÓÓòÃû£¬£¬£¬£¬£¬£¬µ«Î¢Èí½ö½¨¸´ÁËÆäÖÐ5£¥µ½10£¥µÄ×ÓÓòÃû¡£¡£¡£¡£¡£¡£¡£¡£Gaschet»¹Ö¸³öËûÖÁÉÙÔÚ4¸öºÏ·¨µÄ΢Èí×ÓÓòÖз¢ÏÖÁËÓ¡¶ÈÄáÎ÷ÑÇÆË¿Ë¶Ä³¡µÄ¸æ°×£¬£¬£¬£¬£¬£¬Ô̺¬portal.ds.microsoft.com¡¢perfect10.microsoft.com¡¢ies.global.microsoft.comºÍblog-ambassadors.microsoft.com¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-has-a-subdomain-hijacking-problem/
4¡¢ÃÀ¹úÌìÈ»Æø¹Ü·ÔËÓªÉÌÔâµ½ÀÕË÷Èí¼þ¹¥»÷
ƾ¾ÝÃÀ¹úºÓɽ°²È«ÊýÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨DHS CISA£©°ä²¼µÄ´«µÝ£¬£¬£¬£¬£¬£¬Ò»¼Òδ¾ßÃûµÄÃÀ¹úÌìÈ»ÆøÑ¹Ëõ¹¤³§ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂÔËÓªÖжÏÁËÁ½ÌìµÄ¹¦·ò¡£¡£¡£¡£¡£¡£¡£¡£CISA°µÊ¾¹¥»÷ÕßÊ×ÏÈÀûÓô¹µöÁ´½Ó»ñµÃÁ˶ԸÃ×éÖ¯ITÍøÂçµÄ½Ó¼û£¬£¬£¬£¬£¬£¬¶øºóתÏòÆäOTÍøÂç²¢²¿ÊðÁËÉÌÓÃÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þͬʱÔÚITºÍOTÍøÂçÉ϶Թ«Ë¾µÄÊý¾Ý½øÐмÓÃÜ£¬£¬£¬£¬£¬£¬ÒÔ×î´óˮƽµØ·ÛËéÆóÒµ£¬£¬£¬£¬£¬£¬¶øºó²ÅÒªÇóÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þ²¢Î´Ó°ÏìÈκÎPLC£¬£¬£¬£¬£¬£¬µ«ÈËÀà²Ù×÷Ô±ÎÞ·¨»ã×ܺͶÁÈ¡Óйع¤Òµ¹ý³ÌÖеÄÊý¾Ý£¬£¬£¬£¬£¬£¬ÀýÈçHMI¡¢Êý¾Ýº¹Çà¼Í¼ºÍÂÖѯ·þÎñÆ÷£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ±¹¤ÎÞ·¨°ÑÎչܷÉèÊ©µÄÔËÐÐÇé¿ö¡£¡£¡£¡£¡£¡£¡£¡£¹Ü·ÔËÓªÉÌÖ´ÐÐÁË¡°ÓдòËãµÄ¡¢ÊܿصĹعء±´ëÊ©£¬£¬£¬£¬£¬£¬ÒÔÔ¤·À²¢Ô¤·ÀÈκÎÊÂÎñµÄ²úÉú¡£¡£¡£¡£¡£¡£¡£¡£CISA°µÊ¾ÔËÓªÖжϳÖÐøÁËÔ¼Á½Ì죬£¬£¬£¬£¬£¬¶øºó¸´ÔÁËÕý³£ÔË×÷¡£¡£¡£¡£¡£¡£¡£¡£CISAûÓÐй©ÀÕË÷Èí¼þµÄÃû³Æ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/dhs-says-ransomware-hit-us-gas-pipeline-operator/
5¡¢ÒÁÀʺڿÍÀûÓÃVPNÈí¼þ·ì϶¹¥»÷È«ÇòµÄÆóÒµºÍµ±¾Ö»ú¹¹
ƾ¾Ý°²È«³§ÉÌClearSkyµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬ÒÁÀʺڿÍÒ»ÏòÔÚÀûÓÃVPNÈí¼þÖеķì϶ÔÚÊÀ½ç¸÷µØµÄ¹«Ë¾ÖÐÖ²ÈëºóÃÅ£¬£¬£¬£¬£¬£¬ÆäÖ¸±êº¸ÇIT¡¢µçÐÅ¡¢Ê¯ÓͺÍÌìÈ»Æø¡¢º½¿Õ¡¢°²È«ÁìÓòµÄ¹«Ë¾ºÍµ±¾Ö»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£ÒÁÀʺڿÍÒѽ«Pulse Secure¡¢Fortinet¡¢Palo Alto NetworksºÍCitrixµÄVPN¶¨Î»ÎªÈëÇÖ´óÐ͹«Ë¾µÄ¹¤¾ß£¬£¬£¬£¬£¬£¬ÆäÀûÓõķì϶Ô̺¬Pulse Secure VPN(CVE-2019-11510)¡¢Fortinet FortiOS VPN(CVE-2018-13379)¡¢Palo Alto Networks VPN(CVE-2019-1579)ÒÔ¼°Citrix VPN(CVE-2019-19781)µÈ¡£¡£¡£¡£¡£¡£¡£¡£¶ÔÕâЩϵͳµÄ¹¥»÷ʼÓÚÈ¥ÄêÏÄÌ죬£¬£¬£¬£¬£¬µ«µ½2020ÄêÕâÖÖ¹¥»÷ÈÔÔÚ³ÖÐø¡£¡£¡£¡£¡£¡£¡£¡£ClearSky»ã±¨Ç¿µ÷£¬£¬£¬£¬£¬£¬¶ÔÈ«ÇòVPN·þÎñÆ÷µÄ¹¥»÷ËÆºõÊÇÖÁÉÙÈý¸öÒÁÀʺڿÍ×éÖ¯µÄ¹¤×÷£¬£¬£¬£¬£¬£¬Ô̺¬APT33¡¢APT34ºÍAPT39¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/iranian-hackers-have-been-hacking-vpn-servers-to-plant-backdoors-in-companies-around-the-world/


¾©¹«Íø°²±¸11010802024551ºÅ