ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ30ÖÜ
°ä²¼¹¦·ò 2019-08-05> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê7ÔÂ29ÈÕÖÁ8ÔÂ04ÈÕ¹²ÊÕ¼°²È«·ì϶50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAlcatel-Lucent Enterprise 8008 Cloud Edition Deskphone VoIPÃÜÂë¸ü¸ÄºÅÁî×¢Èë·ì϶£»Puppet Enterprise PE's express installĬÈÏÃÜÂë·ì϶£»Wind River Systems VxWorks IPÑ¡Ïî½âÎö»º³åÇøÒç¶Âí½Å£»Polycom UC SoftwareÉÏ´«Îļþ´úÂëÖ´Ðзì϶£»cPanel SQL×¢Èë·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇŦԼͨ¹ýÐÂÊý¾Ýй¶֪ͨ·¨°¸£¬Êý¾Ý¼à¹ÜÔÙ´ÎÉý¼¶£»Capital Oneй¶1.06ÒÚÓû§ÐÅÏ¢£¬ÏÓÒÉÈËÒѱ»²¶£»VxWorks½¨¸´11¸ö°²È«·ì϶£¬Ó°Ï쳬¹ý20ÒŲ́É豸£»Amcrest¼ÒÓÃÉãÏñÍ·ÑϳÁ·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÔ¶³Ì¼àÌýÓû§£»ÖÇÀû1430Íò¹«ÃñÐÅϢй¶£¬Õ¼È«¹ú×ÜÈ˶¡½ü80%¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1. Alcatel-Lucent Enterprise 8008 Cloud Edition Deskphone VoIPÃÜÂë¸ü¸ÄºÅÁî×¢Èë·ì϶
Alcatel-Lucent Enterprise 8008 Cloud Edition Deskphone VoIP ÃÜÂë¸ü¸Ä½çÃæ¸ü¸ÄÃÜÂë´¦ÖôæÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâOSºÅÁî¡£
https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_Alcatel_8008CloudEditionDeskPhone.pdf?_=15590263402. Puppet Enterprise PE's express installĬÈÏÃÜÂë·ì϶
https://puppet.com/security/cve/CVE-2019-10694
3. Wind River Systems VxWorks IPÑ¡Ïî½âÎö»º³åÇøÒç¶Âí½Å
https://www.us-cert.gov/ics/advisories/icsa-19-211-01
4. Polycom UC SoftwareÉÏ´«Îļþ´úÂëÖ´Ðзì϶
https://support.polycom.com/content/dam/polycom-support/global/documentation/remote-code-execution-vulnerability-in-ucs-software-v1-0.pdf
5. cPanel SQL×¢Èë·ì϶
https://documentation.cpanel.net/display/CL/58+Change+Log
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Å¦Ô¼Í¨¹ýÐÂÊý¾Ýй¶֪ͨ·¨°¸£¬Êý¾Ý¼à¹ÜÔÙ´ÎÉý¼¶
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-york-passes-law-to-update-data-breach-notification-requirements/
2¡¢Capital Oneй¶1.06ÒÚÓû§ÐÅÏ¢£¬ÏÓÒÉÈËÒѱ»²¶
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/capital-one-data-breach-affects-106-million-people-suspect-arrested/
3¡¢VxWorks½¨¸´11¸ö°²È«·ì϶£¬Ó°Ï쳬¹ý20ÒŲ́É豸
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/vxworks-rtos-vulnerability.html
4¡¢Amcrest¼ÒÓÃÉãÏñÍ·ÑϳÁ·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÔ¶³Ì¼àÌýÓû§
°²È«³§ÉÌTenable·¢ÏÖAmcrest IP2M-841B¼ÒÓÃÉãÏñÍ·´æÔÚÒ»¸öÑϳÁ·ì϶£¬¿ÉÔÊÐí¹¥»÷Õßͨ¹ýHTTPÔ¶³Ì¼àÌýÉãÏñÍ·µÄÒôƵÊäÈë¡£¸Ã·ì϶±»ÏóÕ÷ΪCVE-2019-3948£¬Ó°ÏìÁËÉãÏñÍ·¹Ì¼þ°æ±¾V2.520.AC00.18.R£¬²¢ÇÒÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÀûÓá£´Ë±í£¬¸Ã²úÆ·Ò²Ò×ÊÜÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2017-7927£©¹¥»÷¡£AmcrestÒѾ°ä²¼Óйؽ¨¸´²¹¶¡¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/iot-home-security-camera-allows-hackers-to-listen-in-over-http/
5¡¢ÖÇÀû1430Íò¹«ÃñÐÅϢй¶£¬Õ¼È«¹ú×ÜÈ˶¡½ü80%
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/voter-records-for-80-of-chiles-population-left-exposed-online/


¾©¹«Íø°²±¸11010802024551ºÅ