ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ04ÖÜ
°ä²¼¹¦·ò 2020-02-04> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê01ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼°²È«·ì϶42¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Webex Video Mesh WEB½Ó¿ÚËÁÒâºÅÁîÖ´Ðзì϶; Ruckus Wireless Unleashed emfdËÁÒâOSºÅÁîÖ´Ðзì϶£»Trustwave ModSecurity Transaction::addRequestHeader»Ø¾ø·þÎñ·ì϶£»Honeywell Maxpro VMS & NVR·´ÐòÁл¯´úÂëÖ´Ðзì϶£»Philips Hue Bridge ZCL¶ÑÒç¶Âí½Å¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÃÀ¹ú¹ú¶È³ß¶È¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ·çÏÕÖÎÀí¿ò¼Ü1.0°æ£»GDPR¼à¹Ü»ú¹¹Æù½ñΪֹÒÑ·£¿î1.26ÒÚÃÀÔª£»Î¢Èíй¶2.5ÒÚÌõºô½ÐÖÐÐļͼ£¬¿Í»§ÓÊÏä¼°IPµØÖ·Â¶³ö£»×êÑÐÈËÔ±Åû¶FortiSIEMÖеÄÓ²±àÂëSSHÃÜÔ¿·ì϶£»Æ»¹û°ä²¼Í¨Ã÷¶È»ã±¨£¬Åû¶Áйúµ±¾ÖÒªÇ󯻹ûÓû§Êý¾ÝÇé¿ö¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
>³ÁÒª°²È«·ì϶Áбí
1. Cisco Webex Video Mesh WEB½Ó¿ÚËÁÒâºÅÁîÖ´Ðзì϶
Cisco Webex Video Mesh WEB½Ó¿Ú´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»rootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200108-webex-video
2. Ruckus Wireless Unleashed emfdËÁÒâOSºÅÁîÖ´Ðзì϶
Ruckus Wireless Unleashed emfd admin/_cmdstat.jsp²»ÕýÈ·´¦ÖÃxcmd=import-categoryÊôÐÔ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄPOSTÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£
https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.html
3. Trustwave ModSecurity Transaction::addRequestHeader»Ø¾ø·þÎñ·ì϶
Trustwave ModSecurity Transaction::addRequestHeader´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɽøÐлؾø·þÎñ¹¥»÷¡£
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-denial-of-service-details-cve-2019-19886/
4. Honeywell Maxpro VMS & NVR·´ÐòÁл¯´úÂëÖ´Ðзì϶
Honeywell Maxpro VMS & NVR´¦ÖÃWEBÒªÇó´æÔÚ·´ÐòÁл¯·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://www.us-cert.gov/ics/advisories/icsa-20-021-01
5. Philips Hue Bridge ZCL¶ÑÒç¶Âí½Å
Philips Hue Bridge´¦Ö󬳤ZCL×Ö·û´®´æÔÚ¶ÑÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www2.meethue.com/en-us/support/release-notes/bridge
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÃÀ¹ú¹ú¶È³ß¶È¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ·çÏÕÖÎÀí¿ò¼Ü1.0°æ
ÃÀ¹ú¹ú¶È³ß¶È¼¼Êõ×êÑÐÔº£¨NIST£©ÉÏÖܰ䲼ÁËÒþÖÔ¿ò¼Ü1.0°æ£¬¸Ã¹¤¾ßÖ¼ÔÚÔ®ÊÖ×éÖ¯ÖÎÀíÒþÖÔ·çÏÕ¡£NISTÓÚ2019Äê9Ô°䲼ÁËÒþÖÔ¿ò¼Ü³õ¸å²¢ÍøÂ繫¼Ò¶¨¼û£¬¸Ã»ú¹¹×î³õµ«Ô¸ÔÚ2019Äêµ×֮ǰ°ä²¼1.0°æ£¬µ«Ö±µ½1ÔÂ16ÈÕ²ÅÕýʽ°ä²¼¡£NISTÒþÖÔ¿ò¼ÜÖ¼ÔÚͨ¹ý¹Ø×¢Èý¸öÖØÒª·½ÃæÀ´Ô®ÊÖ¸÷Àà¹æÄ£ºÍ¸÷¸ö²¿ÃŵÄ×éÖ¯ÖÎÀíÒþÖÔ·çÏÕ£ºÔÚ¿ª·¢²úÆ·»ò·þÎñʱҪ˼¿¼µ½ÒþÖÔ¡¢»¥»»ÒþÖÔͨÀýÒÔ¼°¿ç×éÖ¯µÄºÏ×÷¡£¸Ã¿ò¼ÜÔ̺¬Èý¸öÖØÒª²¿ÃÅ£ºÖ÷Ìâ¡¢¸ÅÒªºÍʵÏֲ㡣Ö÷ÌâÌṩһ×éϸ»¯µÄ»î¶¯ºÍÁ˾֣¬ÆäÖ÷ÕÅÊÇʵÏÖÄÚ²¿¹µÍ¨¡£¸ÅÒª²ã°µÊ¾×éÖ¯ÒÑÈ·¶¨Ö÷ÌâÖ°ÄÜ¡¢Àà±ðºÍ×ÓÀà´ËÍâÓÅÏȼ¶±ð¡£×îºó£¬Ö´Ðвã¿ÉÔ®ÊÖ×éÖ¯ÓÅ»¯ÊµÏÖ¸ÅÒª²ãËùÐèµÄ×ÊÔ´¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/nist-releases-framework-privacy-risk-management
2¡¢GDPR¼à¹Ü»ú¹¹Æù½ñΪֹÒÑ·£¿î1.26ÒÚÃÀÔª
Ò»Ïîеĵ÷²é·¢ÏÖ£¬Æù½ñΪֹ¼à¹Ü»ú¹¹ÒѶÔÊý¾Ýй¶ºÍÆäËûGDPRÇÖȨÐÐΪ´¦ÒÔÁ˼ÛÖµ1.26ÒÚÃÀÔªµÄ·£¿î¡£Æ¾¾ÝDLA PiperµÄGDPRÊý¾ÝÎ¥¹æµ÷²é£¬Êý¾Ý±£»¤¼à¹Ü»ú¹¹ÔÚ2018Äê5ÔÂ25ÈÕÖÁ2020Äê1ÔÂ27ÈÕÆÚ¼ä¶ÔGDPRÓйصķ£¿îΪ1.14ÒÚÅ·Ôª£¨Ô¼ºÏ1.26ÒÚÃÀÔª/ 9,700ÍòÓ¢°÷£©¡£Õâ¼Ò¹ú¼ÊÂÉʦÊÂÎñËùÖ¸³ö£¬·¨¹ú¡¢µÂ¹úºÍ°ÂµØÀûµÄ·£¿î×ܶî×î¸ß£¬±ðÀëΪ5100ÍòÅ·Ôª£¬2450ÍòÅ·ÔªºÍ1800ÍòÅ·Ôª¡£¸Ã»ã±¨²¢Î´º¸ÇÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¶ÔÓ¢¹úº½¿Õ¹«Ë¾£¨British Airways£©´¦ÒÔ1.83ÒÚÓ¢°÷µÄGDPR·£¿î¼°¶ÔÍòºÀ¹ú¼Ê¹«Ë¾£¨Marriott International£©½øÐÐ9990ÍòÓ¢°÷µÄGDPR·£¿î£¬ÓÉÓÚ½ØÖÁ»ã±¨ÊµÏÖʱICOÉÐδ×îÖÕÈ·¶¨´¦ÒÔ·£¿î¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/gdpr-regulators-have-imposed-126m-in-fines-thus-far-finds-survey/
3¡¢Î¢Èíй¶2.5ÒÚÌõºô½ÐÖÐÐļͼ£¬¿Í»§ÓÊÏä¼°IPµØÖ·Â¶³ö
È¥ÄêÄêµ×£¬ComparitechµÄ°²È«×êÑÐÍŶӷ¢ÏÖÁ˼¸Ì¨·þÎñÆ÷£¬Ã¿Ì¨·þÎñÆ÷¶¼Ô̺¬ÓëMicrosoftÖ§³Ö´úÀíºÍ¿Í»§Ò»ÑùµÄ2.5ÒÚºô½ÐÖÐÐļͼ¡£ÕâЩ¼Í¼Ëù¸²¸ÇµÄ¹¦·ò¶ÎΪ2005ÄêÖÁ2019Äê12Ô£¬Æä²¢Ã»ÓÐʹÓÃÃÜÂë±£»¤»ò¼ÓÃÜ£¬ÕâÒ²Òâζ×Å£¬ÈκÎÄܹ»½Ó¼û»¥ÁªÍøµÄÈ˶¼Äܹ»¶ÔÆä½øÐнӼû¡£´óÎÞÊýÓ×ÎÒÉí·ÝÐÅÏ¢ÒѴӼͼÖÐɾ³ý¡£µ«ÊÇ£¬ÒÀÈ»´æÔÚ´óÁ¿ÒÔ´¿Îı¾Ìåʽ´æ´¢µÄÐÅÏ¢£¬Ô̺¬£º¿Í»§µç×ÓÓʼþµØÖ·¡¢IPµØÖ·¡¢µØÎ»¡¢CSSÉêÃ÷ºÍ°¸ÀýµÄÃèÊö¡¢MicrosoftÖ§³Ö´úÀíµç×ÓÓʼþ¡¢°¸Àý±àºÅ¡¢°¸Àý½â¾ö¹æ»®£¬°¸Àý±¸×¢ºÍÏóÕ÷Ϊ¡°»úÃÜ¡±µÄÄÚ²¿×¢½â¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/microsoft-exposes-250-million-call/
4¡¢×êÑÐÈËÔ±Åû¶FortiSIEMÖеÄÓ²±àÂëSSHÃÜÔ¿·ì϶
CyberaµÄ°²È«×¨¼ÒAndrew Klaus·¢ÏÖFortinet°²È«ÐÅÏ¢ºÍÊÂÎñÖÎÀíÆ÷ FortiSIEMÖеÄÓ²±àÂëSSH¹«Ô¿·ì϶£¬¿É±»ÀÄÓÃÓÚ½Ó¼ûFortiSIEM Supervisor¡£¸ÃÓ²±àÂëSSHÃÜÔ¿ÊôÓÚÓû§¡°tunneluser¡±¡£ÔÚËùÓÐ×°ÖÃÖ®¼ä¶¼Ò»Ñù¡£Ê¹ÓôËÃÜÔ¿µÄ¹¥»÷ÕßÄܹ»ÒÔ¸ÃÓû§Éí·Ý³É¹¦Í¨¹ýFortiSIEM Supervisor½øÐÐÉí·ÝÑéÖ¤¡£¹ÌÈ»¸ÃÓû§µÄshell½öÏÞÓÚÔËÐо籾/opt/phoenix/phscripts/bin/tunnelshell£¬SSHÈÏÖ¤ÒÀÈ»Êdzɹ¦µÄ¡£Fortinet°ä²¼°²È«²¼¸æ³Æ£¬¸Ã·ì϶µÄ±àºÅÊÇ CVE-2019-17659£¬Ëü¿Éµ¼Ö»ؾø·þÎñ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/96649/security/hardcoded-ssh-key-fortinet.html
5¡¢Æ»¹û°ä²¼Í¨Ã÷¶È»ã±¨£¬Åû¶Áйúµ±¾ÖÒªÇ󯻹ûÓû§Êý¾ÝÇé¿ö
1ÔÂ18ÈÕ£¬Æ»¹ûÖÜÎå°ä²¼Á˰ëÄê¶ÈͨÃ÷¶È»ã±¨£¬Åû¶ÁËÁйúµ±¾ÖÔÚÈ«ÇòÁìÓòÄÚÏòÆäË÷È¡Óû§Êý¾ÝµÄ´ÎÊý¡£Æ¾¾ÝÆ»¹û°ä²¼µÄ»ã±¨£¬ÔÚ2019Äê1ÔÂ1ÈÕÖÁ6ÔÂ30ÈÕÖ®¼ä£¬Áйúµ±¾ÖÌá³öÁË31778´ÎÉ豸ҪÇ󣬱È2018ÄêÉϰëÄêÔö³¤ÁËÔ¼500´Î¡£ÕâÀàÐÅÏ¢Ô̺¬ÄÄЩÓû§ÓëÄÄЩÉ豸ÓйØÁª£¬ÒÔ¼°²É°ì¡¢¿Í»§·þÎñºÍά½¨ÐÅÏ¢¡£Æ»¹ûÔÚÆäÖÐ82%µÄʱ³½Âú×ãÁ˶Է½µÄÒªÇ󡣵¹úÌá³öÉ豸ҪÇóÔÙ´Îλ¾Ó°ñÊ×£¬´ïµ½13558´Î£¬ÃÀ¹úÔÚ6¸öÔÂÄÚÌá³öÁË4796´ÎÉ豸ҪÇó¡£ÕÊ»§ÒªÇó£¨ÀýÈ磬ÓйØiCloudºÍiTunesÕÊ»§µÄ¾ßÌåÐÅÏ¢£©ÔÚ6¸öÔÂÄÚ´ïµ½ÁË6480´Î¡£Æ»¹ûÔÚ85£¥µÄÇé¿öϳÇÊÐÌṩ¾ßÌåÐÅÏ¢¡£´ó²¿ÃÅÕ˺ÅÒªÇóÀ´×ÔÃÀ¹ú£¬´ïµ½3619´Î¡£
ÔÎÄÁ´½Ó£º
https://www.apple.com/legal/transparency/pdf/requests-2019-H1-en.pdf


¾©¹«Íø°²±¸11010802024551ºÅ