ÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿ÔºÐû²¼Òþ˽¿ò¼Ü³õ¸å£»£»£»£»Verizon WirelessÎó²îµ¼ÖÂÔ¼200Íò¿Í»§µÄÌõԼй¶
Ðû²¼Ê±¼ä 2019-09-111.ÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿ÔºÐû²¼Òþ˽¿ò¼Ü³õ¸å
ÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿Ôº£¨NIST£©Ðû²¼ÁËÒ»¸öÒþ˽¿ò¼Ü³õ¸å£¬£¬£¬£¬£¬Ö¼ÔÚͨ¹ýÆóҵΣº¦ÖÎÀí×ÊÖúÆóÒµ¸ÄÉÆÐ¡ÎÒ˽¼ÒÒþ˽¡£¡£¡£¡£¡£NISTÌåÏÖ£¬£¬£¬£¬£¬Òþ˽¿ò¼ÜÖ¼ÔÚͨ¹ýÈý¸öÊÂÏî×ÊÖúÆóÒµ±£»£»£»£»¤Ð¡ÎÒ˽¼ÒÒþ˽£ºÍ¨¹ýÔÚЧÀͺͲúÆ·ÖÐÖ§³ÖÆ·µÂ¾öÒéÀ´½¨Éè¿Í»§ÐÅÈΣ»£»£»£»ÍÆÐкϹæÒåÎñ;ÒÔ¼°Ôö½øÓë¿Í»§ºÍî¿Ïµ»ú¹¹¾ÍÒþ˽ʵ¼ù¾ÙÐÐÏàͬ¡£¡£¡£¡£¡£¸ÃÕþ²ß×ñÕÕÍøÂçÇå¾²¿ò¼ÜµÄ½á¹¹£¬£¬£¬£¬£¬Óɽ¹µã¡¢¸Å¿öºÍʵÑé²ã×é³É¡£¡£¡£¡£¡£½¹µã²¿·ÖÖ¼ÔÚÔö½ø¹ØÓÚÒþ˽±£»£»£»£»¤ÔËÓªºÍÆÚÍûЧ¹ûµÄ¶Ô»°£¬£¬£¬£¬£¬¶ø¸Å¿ö²¿·ÖÔòÍÆ½øÖª×ã×é֯ʹÃüºÍÒþ˽¼ÛÖµµÄ»î¶¯ºÍЧ¹ûµÄÓÅÏÈÐò´Î¡£¡£¡£¡£¡£ÊµÑé²ãÔò¶Ô×éÖ¯´¦Öóͷ£Òþ˽Σº¦Á÷³ÌµÄ³ä·ÖÐÔ¾ÙÐÐÏàͬºÍ¾öÒéÌṩ֧³Ö¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.executivegov.com/2019/09/nist-issues-preliminary-draft-of-privacy-framework/
2.Verizon WirelessÎó²îµ¼ÖÂÔ¼200Íò¿Í»§µÄÌõԼй¶
Ó¢¹úÇå¾²Ñо¿Ô±Daley Bee·¢Ã÷Verizon WirelessϵͳµÄÒ»¸ö×ÓÓò±£´æ²»Çå¾²µÄÖ±½Ó¹¤¾ßÒýÓã¨IDOR£©Îó²î£¬£¬£¬£¬£¬¿ÉÄܱ»ºÚ¿ÍʹÓÃÀ´»ñÈ¡200Íò¿Í»§ÌõÔ¼¡£¡£¡£¡£¡£¸Ã×ÓÓòÃûÊÇtelestore.verizonwireless.com£¬£¬£¬£¬£¬Ëƺõ±»¹«Ë¾Ô±¹¤ÓÃÀ´»á¼ûÄÚ²¿PoS¹¤¾ßºÍÉó²é¿Í»§ÐÅÏ¢¡£¡£¡£¡£¡£½øÒ»²½ÆÊÎö·¢Ã÷ÁËÒ»¸öÖ¸ÏòPDFÃûÌõÄVerizon¿Í»§ÌõÔ¼µÄURL£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Í¨¹ýÐÞ¸ÄGET²ÎÊýÖµ¿É»á¼ûÔ¼200Íò¸öÌõÔ¼£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢×°±¸ÐͺźÍÐòÁкÅÒÔ¼°¿Í»§ÊðÃûµÈÄÚÈÝ¡£¡£¡£¡£¡£Verizon֤ʵÁËÕâÒ»Îó²î£¬£¬£¬£¬£¬²¢ÔÚ½Óµ½Í¨ÖªµÄÒ»¸öÔºóÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/vulnerabilities-exposed-2-million-verizon-customer-contracts
3.Stealth FalconкóÃÅʹÓÃWindows BITSЧÀÍÇÔÈ¡Êý¾Ý
ESETÑо¿Ö°Ô±·¢Ã÷APT×éÖ¯Stealth FalconµÄкóÃÅÀÄÓÃWindows BITSЧÀÍÀ´Òþ²ØÆäÓëÏÂÁîºÍ¿ØÖÆ£¨C£¦C£©Ð§ÀÍÆ÷µÄͨѶÁ÷Á¿¡£¡£¡£¡£¡£Windows BITSÊÇ΢ÈíÏòÈ«ÇòÓû§·¢ËÍWindows¸üеÄĬÈÏϵͳ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪ¸ÃºóÃÅÕâÑù×öÊÇΪÁËÈÆ¹ý·À»ðǽ£¬£¬£¬£¬£¬ÓÉÓÚÆóÒµÒÔΪBITSÁ÷Á¿ºÜ¿ÉÄܰüÀ¨Èí¼þ¸üжøÇãÏòÓÚºöÂÔËü¡£¡£¡£¡£¡£ESET½«¸ÃºóÃÅÃüÃûΪWin32/StealthFalcon£¬£¬£¬£¬£¬ËüÔÊÐí¹¥»÷ÕßÔÚÊÜѬȾµÄϵͳÉÏÏÂÔØºÍÔËÐÐÆäËü¶ñÒâ´úÂë»òÇÔÈ¡Êý¾Ý·¢Ë͵½Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¸ÃºóÃÅËÆºõÊÇ2015Ä꽨ÉèµÄ£¬£¬£¬£¬£¬Ê¹ÓÃÁËÓë2016ÄêCitizen Lab±¨¸æÖÐÏêÊöµÄPowershellºóÃÅÏàͬµÄC£¦CÓòÃû¡£¡£¡£¡£¡£ESETûÓÐ͸¶ÐºóÃŵĹ¥»÷ÇéÐλòÄ¿µÄ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/91019/apt/stealth-falcon-backdoor-bits.html
4.ZDIÅû¶Red Lion¹«Ë¾HMI²úÆ·ÖеĶà¸öÇå¾²Îó²î
Ñо¿Ö°Ô±ÔÚÃÀ¹úRed Lion¹«Ë¾ÖÆÔìµÄÈË»ú½çÃæ£¨HMI£©±à³ÌÈí¼þÖз¢Ã÷¶à¸öÇå¾²Îó²î¡£¡£¡£¡£¡£Red LionÊÇSpectrisµÄ×Ó¹«Ë¾£¬£¬£¬£¬£¬Æ¾Ö¤ÃÀ¹úCISAµÄÐÅÏ¢£¬£¬£¬£¬£¬Red LionµÄ²úÆ·ÔÚÈ«Çò¹æÄ£ÄÚʹÓ㬣¬£¬£¬£¬Ö÷ÒªÓÃÓÚÒªº¦ÖÆÔìÁìÓò¡£¡£¡£¡£¡£Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±·¢Ã÷Red LionµÄCrimson±à³ÌÈí¼þ£¬£¬£¬£¬£¬ÌØÊâÊÇ3.0¼°Ö®Ç°°æ±¾ºÍ3.112.00֮ǰµÄ3.1°æ±¾±£´æËĸöÎó²î£¬£¬£¬£¬£¬°üÀ¨CVE-2019-10996¡¢CVE-2019-10978¡¢CVE-2019-10984ºÍCVE-2019-10990¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÒ»¸öÎó²îÔÊÐí¹¥»÷Õßͨ¹ýÓÕʹĿµÄÓû§·¿ª¶ñÒâCD3Îļþ£¬£¬£¬£¬£¬ÔÚÄ¿½ñÀú³ÌµÄÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ÁíÒ»¸öÎó²îÓëÓ²±àÂëµÄƾ֤Óйء£¡£¡£¡£¡£Red LionÐû²¼ÁËCrimson 3.1°æ±¾3112.00ÒÔÐÞ²¹Îó²î£¬£¬£¬£¬£¬µ«¼û¸æ¿Í»§Ëü²»ÍýÏëÐû²¼Crimson 3.0µÄ¸üС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/several-vulnerabilities-found-red-lion-hmi-software
5.˼¿ÆTalosÅû¶NETGEARÎÞÏß·ÓÉÆ÷ÖеÄDoSÎó²î
˼¿ÆTalos·¢Ã÷NETGEAR N300ϵÁÐÎÞÏß·ÓÉÆ÷°üÀ¨Á½¸ö¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏò·ÓÉÆ÷µÄ²î±ð¹¦Ð§·¢ËͶñÒâSOAPºÍHTTPÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÆäÍêÈ«Í߽⡣¡£¡£¡£¡£µÚÒ»¸öÎó²îÊÇCVE-2019-5054£¬£¬£¬£¬£¬±£´æÓÚHTTPЧÀÍÆ÷µÄ»á»°´¦Öóͷ£¹¦Ð§ÖУ¬£¬£¬£¬£¬·¢Ë͵½Éí·ÝÑéÖ¤Ò³ÃæµÄ¿ÕUser-Agent×Ö·û´®HTTPÇëÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓ㬣¬£¬£¬£¬´Ó¶øµ¼ÖÂHTTPЧÀÍÍ߽⡣¡£¡£¡£¡£µÚ¶þ¸öÎó²îCVE-2019-5055±£´æÓÚÖ÷ʱ»ú¼ûµãÊØ»¤³ÌÐò£¨hostapd£©ÖУ¬£¬£¬£¬£¬·¢Ë͵½<WFAWLANConfig£º1££PutMessage>ЧÀ͵ÄÎÞЧÐòÁÐSOAPÇëÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓ㬣¬£¬£¬£¬´Ó¶øµ¼ÖÂhostapdЧÀÍÍ߽⡣¡£¡£¡£¡£TalosÈ·ÈÏN300 WNR2000v5·ÓÉÆ÷£¨¹Ì¼þ°æ±¾V1.0.0.70£©Êܵ½Ó°Ïì¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/09/vuln-spotlight-Netgear-N300-routers-DoS-sept-2019.html
6.΢ÈíÐû²¼9ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Á½¸ö0day
΢ÈíÔÚ9ÔµÄWindowsÇå¾²¸üÐÂÖÐÐÞ¸´ÁË80¸öÎó²î£¬£¬£¬£¬£¬ÆäÖаüÀ¨17¸öÑÏÖØÎó²î¡£¡£¡£¡£¡£ÓÐÁ½¸öÎó²îÊÇ0day£¬£¬£¬£¬£¬ÔÚ΢ÈíÐû²¼²¹¶¡Ö®Ç°ËüÃÇÒÑÔÚÒ°ÍⱻʹÓᣡ£¡£¡£¡£ÕâÁ½¸öÎó²î»®·ÖÊÇWindowsͨÓÃÈÕÖ¾Îļþϵͳ£¨CLFS£©Çý¶¯³ÌÐòÖеÄEoP£¨CVE-2019-1214£©ºÍÓ°Ïìws2ifsl.sys£¨Winsock£©Ð§À͵ÄEoP£¨CVE-2019-1215£©£¬£¬£¬£¬£¬Î¢ÈíûÓÐÅû¶Îó²îÔÚÒ°ÍâʹÓõĸü¶àϸ½Ú¡£¡£¡£¡£¡£±¾ÔÂ΢ÈíÒ²ÐÞ¸´ÁËÔ¶³Ì×ÀÃæÐÒéÖеÄÁ½¸öÎó²î£¬£¬£¬£¬£¬°üÀ¨CVE-2019-1290ºÍCVE-2019-1291¡£¡£¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-patches-two-zero-days-in-massive-september-2019-patch-tuesday/


¾©¹«Íø°²±¸11010802024551ºÅ