¶à¿îÎÞÏßͶӰϵͳÑϳÁ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-05-06·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-3930£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾¼°²úÆ·
Crestron AM-101 2.7.0.1
Barco wePresent WiPG-1000P 2.3.0.10
Barco wePresent WiPG-1600W before 2.4.1.19
Extron ShareLink 200/250 2.0.3.4
Teq AV IT WIPS710 1.1.0.7
InFocus LiteShow3 1.0.16
InFocus LiteShow4 2.0.0.7
Optoma WPS-Pro 1.0.0.5
Blackbox HD WPS 1.0.0.5
SHARP PN-L703WA 1.4.2.3
·ì϶¸ÅÊö
ÎÞÏßÑÝʾϵͳÔÊÐíÓû§Í¨¹ý×°ÖõÄÀûÓ÷¨Ê½»òWebä¯ÀÀÆ÷½«ÆäÉ豸Ïνӵ½ÏµÍ³£¬´Ó¶øÖ±½Ó´ÓÆä±Ê¼Ç±¾µçÄÔÏÔʾÆäÄÚÈÝ¡£
TenableµÄ×êÑÐÈËÔ±Åû¶ÁËÁ½¸ö·ì϶CVE-2019-3929ºÍCVE-2019-3930£¬Ó°ÏìÁËһϵÁÐÑÝʾƽ̨ϵͳ£ºÔ̺¬Crestron£¬Barco wePresent£¬Extron ShareLink£¬InFocus LiteShow£¬TEQ AV IT WIPS710£¬SHARP PN-L703WA£¬ Optoma WPS-Pro£¬Blackbox HD WPS¡£ÕâÊÇÓÉÓÚËùÓа˸öÆ·ÅÆ¹²ÏíÒ»ÑùµÄ»ù´¡´úÂë¡£
δ¾Éí·ÝÑéÖ¤µÄÔ¶³ÌºÅÁî×¢Èë·ì϶£¬Äܹ»Ê¹Ô¶³Ìδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòHTTP¶Ëµãfile_transfer.cgi·¢Ë;«ÐÄÉè¼ÆµÄÒªÇóÀ´Ö´ÐвÙ×÷ϵͳºÅÁî¡£
δ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì²Ö¿â»º³åÇøÒç¶Âí½Å£¬Ëü´æÔÚÓÚÃûΪPARSERtoCHARµÄÉ豸µÄÖ°ÄÜÖУ¬Í¨¹ýHTTP·¢ËͲ»»á¶ÔCGI¾ç±¾½øÐÐÉí·ÝÑéÖ¤¡£ÕâÒâζ×ÅÔ¶³Ìδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý¶Ôreturn.cgi¶ËµãµÄ¾«ÐÄÉè¼ÆÒªÇóÀ´ÀÄÓ÷ì϶À´Ö´ÐÐËÁÒâ´úÂë¡£
·ì϶ÑéÖ¤
EXP£ºhttps://www.exploit-db.com/exploits/46786¡£
½¨¸´½¨Òé
https://www.crestron.com/en-US/Security/Security_Advisories¡£
https://www.barco.com/en/support/software/R33050103?majorVersion=2&minorVersion=3&patchVersion=2&buildVersion=20
https://www.barco.com/en/support/software/R33050104?majorVersion=2&minorVersion=4&patchVersion=1&buildVersion=19
https://www.extron.com/download/software.aspx?filehandle=sharelink200&material=44&type=archive
https://threatpost.com/bugs-wireless-presentation-systems/144318/


¾©¹«Íø°²±¸11010802024551ºÅ