ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ15ÖÜ

°ä²¼¹¦·ò 2021-04-13

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê04ÔÂ05ÈÕÖÁ04ÔÂ11ÈÕ¹²ÊÕ¼°²È«·ì϶41¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414ËÁÒâ´úÂëÖ´Ðзì϶£»LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉý·ì϶£»OpenIAM Groovy Script´úÂëÖ´Ðзì϶£»SonicWall GMSÔ¶³ÌȨÏÞÌáÉý·ì϶£»Skyworth Digital Technology RN510»º³åÇøÒç¶Âí½Å¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇTIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯£»ÐÂ¼ÓÆÂ¹¤»áe2iÔâµ½´¹µö¹¥»÷£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢£»Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬ÊÂÎñÈÔÔÚµ÷²éÖУ»ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÒøÐÐľÂíJaneleiro¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


> ³ÁÒª°²È«·ì϶Áбí


1.Cisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414ËÁÒâ´úÂëÖ´Ðзì϶


CCisco RV345P Dual WAN Gigabit VPN Routers WEBÖÎÀí½Ó¿Ú´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÌáÉýȨÏÞ¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b


2.LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉý·ì϶


LiteSpeed Technologies OpenLiteSpeed web server´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÔÚÖ÷»úÉÏÖ´ÐÐËÁÒâºÅÁî¡£

https://github.com/litespeedtech/openlitespeed/issues/217


3.OpenIAM Groovy Script´úÂëÖ´Ðзì϶


OpenIAM Groovy Script´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md


4.SonicWall GMSÔ¶³ÌȨÏÞÌáÉý·ì϶


SonicWall GMS´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ROOTȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0009


5.Skyworth Digital Technology RN510»º³åÇøÒç¶Âí½Å


Skyworth Digital Technology RN510 /cgi-bin/app-staticIP.asp»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

https://s3curityb3ast.github.io/KSA-Dev-011.md


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day


1.jpg


CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרһÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬Éæ¼°É¢²¼Ê½ÍÆËã¡¢ÔÆÍÆËã¡¢DevOpsºÍÍÆËã»ú°²È«Èí¼þÒÔ¼°Òƶ¯É豸¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öзì϶¡£±ðÀëΪÌáȨ·ì϶£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ·ì϶£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤·ì϶£¨CVE-2021-28248£©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html


2¡¢KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯


2.jpg


KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½Äϵ±¾ÖºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬¿É½øÐÐÎļþϵͳ°Ñ³Ö¡¢¹ý³Ì°Ñ³Ö¡¢ÆÁÄ»½ØÍ¼²¶»ñºÍËÁÒâºÅÁîÖ´ÐС£´Ë±í£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚ¸´ÔÓÐÔ·½Ãæ»ñµÃÁ˳ÁÃͽøÈ¡£¬ÀýÈ磬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÖ¸±êºÍÔ´£©±»ÆëÈ«°þÀ룬ʣϵÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ£¬Õâ´ó´óÔö³¤ÁË×êÑÐÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄѶÈ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spy-operations-vietnam-rat/165243/


3¡¢ÐÂ¼ÓÆÂ¹¤»áe2iÔâµ½´¹µö¹¥»÷£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢


3.jpg


ÐÂ¼ÓÆÂÈ«¹ú¹¤»á´ú±í´ó»á¾ÍÒµÓë¾ÍÒµ×êÑÐËù£¨e2i£©ÔÚ±¾ÖÜÒ»£¨4ÔÂ5ÈÕ£©°ä²¼ÉêÃ÷³Æ£¬¹¥»÷Õß¿ÉÄÜÒѾ­½Ó¼ûÆäÓû§µÄÓ×ÎÒÐÅÏ¢¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Óû§µÄÐÕÃû¡¢½ÌÓý×ʸñºÍNRIC¡¢ÁªÏµ·½Ê½ºÍ¾Íҵϸ½ÚµÈ¡£ÊÂÎñ²úÉúÔÚ3ÔÂ12ÈÕ£¬ÆäµÚÈý·½¹©¸øÉÌ¡ª¡ªÁªÏµÖÐÐÄ·þÎñ¹«Ë¾i-vic InternationalÔ±¹¤µÄÓÊÏäÔâµ½´¹µö¹¥»÷£¬¸ÃÓÊÏäµÄÔÆ¶ËÔ̺¬ÁËÔ¼3Íò¸ö²ÎÓëÁËe2i»î¶¯µÄÓû§ÐÅÏ¢£¬µ«ÊǸûú¹¹»Ø¾øÐ¹Â©×ܹ²Óм¸¶àÈËÔøÊ¹Óùýe2iµÄ·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.straitstimes.com/tech/tech-news/personal-data-of-30000-people-who-use-ntucs-e2i-services-may-have-been-breached


4¡¢Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬ÊÂÎñÈÔÔÚµ÷²éÖÐ


4.jpg


Å·ÃËίԱ»á½²»°È˳Æ£¬Ô̺¬Î¯Ô±»áÔÚÄڵĶà¸öÅ·ÃË×éÖ¯ÔÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷¡£´Ë¿Ì¶Ô¸ÃÊÂÎñµÄȡ֤·ÖÎöÈÔ´¦ÓÚ³õÆÚ½×¶Î£¬ÉÐδ¼ì²âµ½´æÔÚÐÅϢй¶ÎÊÌâ¡£Åí²©É簵ʾ£¬Õâ´ÎÊÂÎñ±ÈÅ·ÃËÒÔÍùÔâµ½µÄ¹¥»÷¸üΪÑϳÁ£¬Å·ÃËij¹ÙÔ±»¹Ð¹Â©£¬Æä¹¤×÷ÈËÔ±½üÆÚÊÕµ½ÁËÓйØÕë¶ÔÅ·Ã˵Ĵ¹µö¹¥»÷Ô¤¾¯¡£Ä¿Ç°£¬Å·ÃËÈÔδ¹«¿ªÓйØÕâ´ÎÊÂÎñµÄÐÔÖÊ»òÆä±³ºóµÄ¹¥»÷ÕßÉí·ÝµÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-04-06/european-institutions-were-targeted-in-a-cyber-attack-last-week


5¡¢ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÒøÐÐľÂíJaneleiro


5.jpg


ESETµÄ×êÑÐÈËÔ±Åû¶ÁËÕë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÐÍÒøÐÐľÂíJaneleiro¡£¸ÃľÂíÖÁÉÙ´Ó2019ÄêÒÔÀ´¾ÍÆðÍ·Õë¶Ô°ÍÎ÷µÄÆóÒµ£¬Éæ¼°¹¤³Ì¡¢Ò½ÁƱ£½¡¡¢ÁãÊÛ¡¢Ôì×÷Òµ¡¢½ðÈÚ¡¢ÔËÊäºÍµ±¾ÖµÈ¸÷¸öÁìÓò¡£Janeleiroͨ¹ýαÔì´óÐÍÒøÐÐÍøÕ¾£¨SantanderºÍBanco do BrasilµÈ£©µÄµ¯´°À´ÒýÓÕÖ¸±ê£¬ÕâЩµ¯´°Ô̺¬ÐéαµÄ±í¸ñÀ´ÓÕʹָ±êÊäÈëÒøÐÐÆ¾Ö¤ºÍÓ×ÎÒÐÅÏ¢¡£´Ë±í£¬JaneleiroÊÇÓÉVisual Basic .NET±àдµÄ£¬ÕâÓë¸ÃµØÓòµÄºÚ¿ÍËùϲ»¶µÄDelphiÓкܴóµÄ³öÈë¡£    


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/experts-uncover-new-banking-trojan.html