ÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿ÔºÐû²¼Òþ˽¿ò¼Ü³õ¸å£»£»£»Verizon WirelessÎó²îµ¼ÖÂÔ¼200Íò¿Í»§µÄÌõԼй¶
Ðû²¼Ê±¼ä 2019-09-111.ÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿ÔºÐû²¼Òþ˽¿ò¼Ü³õ¸å
ÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿Ôº£¨NIST£©Ðû²¼ÁËÒ»¸öÒþ˽¿ò¼Ü³õ¸å£¬£¬£¬Ö¼ÔÚͨ¹ýÆóҵΣº¦ÖÎÀí×ÊÖúÆóÒµ¸ÄÉÆÐ¡ÎÒ˽¼ÒÒþ˽¡£¡£¡£¡£¡£¡£NISTÌåÏÖ£¬£¬£¬Òþ˽¿ò¼ÜÖ¼ÔÚͨ¹ýÈý¸öÊÂÏî×ÊÖúÆóÒµ±£»£»£»¤Ð¡ÎÒ˽¼ÒÒþ˽£ºÍ¨¹ýÔÚЧÀͺͲúÆ·ÖÐÖ§³ÖÆ·µÂ¾öÒéÀ´½¨Éè¿Í»§ÐÅÈΣ»£»£»ÍÆÐкϹæÒåÎñ;ÒÔ¼°Ôö½øÓë¿Í»§ºÍî¿Ïµ»ú¹¹¾ÍÒþ˽ʵ¼ù¾ÙÐÐÏàͬ¡£¡£¡£¡£¡£¡£¸ÃÕþ²ß×ñÕÕÍøÂçÇå¾²¿ò¼ÜµÄ½á¹¹£¬£¬£¬Óɽ¹µã¡¢¸Å¿öºÍʵÑé²ã×é³É¡£¡£¡£¡£¡£¡£½¹µã²¿·ÖÖ¼ÔÚÔö½ø¹ØÓÚÒþ˽±£»£»£»¤ÔËÓªºÍÆÚÍûЧ¹ûµÄ¶Ô»°£¬£¬£¬¶ø¸Å¿ö²¿·ÖÔòÍÆ½øÖª×ã×é֯ʹÃüºÍÒþ˽¼ÛÖµµÄ»î¶¯ºÍЧ¹ûµÄÓÅÏÈÐò´Î¡£¡£¡£¡£¡£¡£ÊµÑé²ãÔò¶Ô×éÖ¯´¦Öóͷ£Òþ˽Σº¦Á÷³ÌµÄ³ä·ÖÐÔ¾ÙÐÐÏàͬºÍ¾öÒéÌṩ֧³Ö¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.executivegov.com/2019/09/nist-issues-preliminary-draft-of-privacy-framework/
2.Verizon WirelessÎó²îµ¼ÖÂÔ¼200Íò¿Í»§µÄÌõԼй¶
Ó¢¹úÇå¾²Ñо¿Ô±Daley Bee·¢Ã÷Verizon WirelessϵͳµÄÒ»¸ö×ÓÓò±£´æ²»Çå¾²µÄÖ±½Ó¹¤¾ßÒýÓã¨IDOR£©Îó²î£¬£¬£¬¿ÉÄܱ»ºÚ¿ÍʹÓÃÀ´»ñÈ¡200Íò¿Í»§ÌõÔ¼¡£¡£¡£¡£¡£¡£¸Ã×ÓÓòÃûÊÇtelestore.verizonwireless.com£¬£¬£¬Ëƺõ±»¹«Ë¾Ô±¹¤ÓÃÀ´»á¼ûÄÚ²¿PoS¹¤¾ßºÍÉó²é¿Í»§ÐÅÏ¢¡£¡£¡£¡£¡£¡£½øÒ»²½ÆÊÎö·¢Ã÷ÁËÒ»¸öÖ¸ÏòPDFÃûÌõÄVerizon¿Í»§ÌõÔ¼µÄURL£¬£¬£¬Ñо¿Ö°Ô±Í¨¹ýÐÞ¸ÄGET²ÎÊýÖµ¿É»á¼ûÔ¼200Íò¸öÌõÔ¼£¬£¬£¬ÆäÖаüÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢×°±¸ÐͺźÍÐòÁкÅÒÔ¼°¿Í»§ÊðÃûµÈÄÚÈÝ¡£¡£¡£¡£¡£¡£Verizon֤ʵÁËÕâÒ»Îó²î£¬£¬£¬²¢ÔÚ½Óµ½Í¨ÖªµÄÒ»¸öÔºóÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/vulnerabilities-exposed-2-million-verizon-customer-contracts
3.Stealth FalconкóÃÅʹÓÃWindows BITSЧÀÍÇÔÈ¡Êý¾Ý
ESETÑо¿Ö°Ô±·¢Ã÷APT×éÖ¯Stealth FalconµÄкóÃÅÀÄÓÃWindows BITSЧÀÍÀ´Òþ²ØÆäÓëÏÂÁîºÍ¿ØÖÆ£¨C£¦C£©Ð§ÀÍÆ÷µÄͨѶÁ÷Á¿¡£¡£¡£¡£¡£¡£Windows BITSÊÇ΢ÈíÏòÈ«ÇòÓû§·¢ËÍWindows¸üеÄĬÈÏϵͳ£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪ¸ÃºóÃÅÕâÑù×öÊÇΪÁËÈÆ¹ý·À»ðǽ£¬£¬£¬ÓÉÓÚÆóÒµÒÔΪBITSÁ÷Á¿ºÜ¿ÉÄܰüÀ¨Èí¼þ¸üжøÇãÏòÓÚºöÂÔËü¡£¡£¡£¡£¡£¡£ESET½«¸ÃºóÃÅÃüÃûΪWin32/StealthFalcon£¬£¬£¬ËüÔÊÐí¹¥»÷ÕßÔÚÊÜѬȾµÄϵͳÉÏÏÂÔØºÍÔËÐÐÆäËü¶ñÒâ´úÂë»òÇÔÈ¡Êý¾Ý·¢Ë͵½Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¸ÃºóÃÅËÆºõÊÇ2015Ä꽨ÉèµÄ£¬£¬£¬Ê¹ÓÃÁËÓë2016ÄêCitizen Lab±¨¸æÖÐÏêÊöµÄPowershellºóÃÅÏàͬµÄC£¦CÓòÃû¡£¡£¡£¡£¡£¡£ESETûÓÐ͸¶ÐºóÃŵĹ¥»÷ÇéÐλòÄ¿µÄ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/91019/apt/stealth-falcon-backdoor-bits.html
4.ZDIÅû¶Red Lion¹«Ë¾HMI²úÆ·ÖеĶà¸öÇå¾²Îó²î
Ñо¿Ö°Ô±ÔÚÃÀ¹úRed Lion¹«Ë¾ÖÆÔìµÄÈË»ú½çÃæ£¨HMI£©±à³ÌÈí¼þÖз¢Ã÷¶à¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£Red LionÊÇSpectrisµÄ×Ó¹«Ë¾£¬£¬£¬Æ¾Ö¤ÃÀ¹úCISAµÄÐÅÏ¢£¬£¬£¬Red LionµÄ²úÆ·ÔÚÈ«Çò¹æÄ£ÄÚʹÓ㬣¬£¬Ö÷ÒªÓÃÓÚÒªº¦ÖÆÔìÁìÓò¡£¡£¡£¡£¡£¡£Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±·¢Ã÷Red LionµÄCrimson±à³ÌÈí¼þ£¬£¬£¬ÌØÊâÊÇ3.0¼°Ö®Ç°°æ±¾ºÍ3.112.00֮ǰµÄ3.1°æ±¾±£´æËĸöÎó²î£¬£¬£¬°üÀ¨CVE-2019-10996¡¢CVE-2019-10978¡¢CVE-2019-10984ºÍCVE-2019-10990¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÒ»¸öÎó²îÔÊÐí¹¥»÷Õßͨ¹ýÓÕʹĿµÄÓû§·¿ª¶ñÒâCD3Îļþ£¬£¬£¬ÔÚÄ¿½ñÀú³ÌµÄÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÎó²îÓëÓ²±àÂëµÄƾ֤Óйء£¡£¡£¡£¡£¡£Red LionÐû²¼ÁËCrimson 3.1°æ±¾3112.00ÒÔÐÞ²¹Îó²î£¬£¬£¬µ«¼û¸æ¿Í»§Ëü²»ÍýÏëÐû²¼Crimson 3.0µÄ¸üС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/several-vulnerabilities-found-red-lion-hmi-software
5.˼¿ÆTalosÅû¶NETGEARÎÞÏß·ÓÉÆ÷ÖеÄDoSÎó²î
˼¿ÆTalos·¢Ã÷NETGEAR N300ϵÁÐÎÞÏß·ÓÉÆ÷°üÀ¨Á½¸ö¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏò·ÓÉÆ÷µÄ²î±ð¹¦Ð§·¢ËͶñÒâSOAPºÍHTTPÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬´Ó¶øµ¼ÖÂÆäÍêÈ«Í߽⡣¡£¡£¡£¡£¡£µÚÒ»¸öÎó²îÊÇCVE-2019-5054£¬£¬£¬±£´æÓÚHTTPЧÀÍÆ÷µÄ»á»°´¦Öóͷ£¹¦Ð§ÖУ¬£¬£¬·¢Ë͵½Éí·ÝÑéÖ¤Ò³ÃæµÄ¿ÕUser-Agent×Ö·û´®HTTPÇëÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓ㬣¬£¬´Ó¶øµ¼ÖÂHTTPЧÀÍÍ߽⡣¡£¡£¡£¡£¡£µÚ¶þ¸öÎó²îCVE-2019-5055±£´æÓÚÖ÷ʱ»ú¼ûµãÊØ»¤³ÌÐò£¨hostapd£©ÖУ¬£¬£¬·¢Ë͵½<WFAWLANConfig£º1££PutMessage>ЧÀ͵ÄÎÞЧÐòÁÐSOAPÇëÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓ㬣¬£¬´Ó¶øµ¼ÖÂhostapdЧÀÍÍ߽⡣¡£¡£¡£¡£¡£TalosÈ·ÈÏN300 WNR2000v5·ÓÉÆ÷£¨¹Ì¼þ°æ±¾V1.0.0.70£©Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/09/vuln-spotlight-Netgear-N300-routers-DoS-sept-2019.html
6.΢ÈíÐû²¼9ÔÂÇå¾²¸üУ¬£¬£¬ÐÞ¸´Á½¸ö0day
΢ÈíÔÚ9ÔµÄWindowsÇå¾²¸üÐÂÖÐÐÞ¸´ÁË80¸öÎó²î£¬£¬£¬ÆäÖаüÀ¨17¸öÑÏÖØÎó²î¡£¡£¡£¡£¡£¡£ÓÐÁ½¸öÎó²îÊÇ0day£¬£¬£¬ÔÚ΢ÈíÐû²¼²¹¶¡Ö®Ç°ËüÃÇÒÑÔÚÒ°ÍⱻʹÓᣡ£¡£¡£¡£¡£ÕâÁ½¸öÎó²î»®·ÖÊÇWindowsͨÓÃÈÕÖ¾Îļþϵͳ£¨CLFS£©Çý¶¯³ÌÐòÖеÄEoP£¨CVE-2019-1214£©ºÍÓ°Ïìws2ifsl.sys£¨Winsock£©Ð§À͵ÄEoP£¨CVE-2019-1215£©£¬£¬£¬Î¢ÈíûÓÐÅû¶Îó²îÔÚÒ°ÍâʹÓõĸü¶àϸ½Ú¡£¡£¡£¡£¡£¡£±¾ÔÂ΢ÈíÒ²ÐÞ¸´ÁËÔ¶³Ì×ÀÃæÐÒéÖеÄÁ½¸öÎó²î£¬£¬£¬°üÀ¨CVE-2019-1290ºÍCVE-2019-1291¡£¡£¡£¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-patches-two-zero-days-in-massive-september-2019-patch-tuesday/


¾©¹«Íø°²±¸11010802024551ºÅ