ÿÖÜÉý¼¶²¼¸æ-2022-08-23

°ä²¼¹¦·ò 2022-08-23
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Òç³ö¹¥»÷_GPON·ÓÉÆ÷_ÈÏÖ¤Õ»Òç³öCVE-2019-3921][CNNVD-201903-081]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_GPON_·ÓÉÆ÷_ÈÏÖ¤Õ»Òç¶Âí½Å¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¹¥»÷³É¹¦£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SonicWall_Global_Management_System_ËÁÒâ´úÂëÖ´ÐÐ[CVE-2018-9866][CNNVD-201808-124]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCVE-2018-9866·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£SonicWallGlobalManagementSystem£¨GMS£©ÊǼ±¾ç²¿ÊðºÍ¼¯ÖÐÖÎÀíDellSonicWALL·À»ðǽ¡¢·´À¬»øÓʼþ¡¢±¸·ÝºÍ¸´Ô­ÒÔ¼°°²È«Ô¶³Ì½Ó¼û½â¾ö¹æ»®µÄÒ»Ì×ÖÎÀíϵͳ¡£SonicWallGMS8.1¼°Ö®Ç°°æ±¾ÖдæÔÚ°²È«·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÑéÖ¤Óû§Ìá½»µÄÓÃÓÚXML-RPCŲÓõIJÎÊý¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

TCP_Òç³ö¹¥»÷_HelixServer_DESCRIBEÒªÇóÔ¶³Ì¶ÑÒç³ö[CVE-2006-6026]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHelixServerDESCRIBEÒªÇóÔ¶³Ì¶ÑÒç¶Âí½Å¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£HelixServerÊÇRMýÌåÁ÷·þÎñÆ÷REALµÄ¿ªÔ´°æ±¾£¬Ö§³ÖRTSPºÍ̸£¬Ö§³ÖRM¡¢MP3µÈÌåʽ¡£HelixServerÄܹ»¹¹½¨¸ß»úÄܵÄÁ÷ýÌå·þÎñÆ÷£¬Ö§³Ö¶àÌåʽ¡¢¿çƽ̨£¬Äܹ»½«¸ßÖÊÁ¿µÄ¶àýÌåÄÚÈÝ·¢µ½ÈκÎÍøÂç¿ÉÄÜ´¥¼°µÄ´¦Ëù¡£Ö§³ÖÒÆ¶¯´«Êä³ß¶È£¬Ô̺¬3GPPʵʱѹËõ£¬Âú×ãÓû§µÄ·ÖÆçµÄ·þÎñÐèÒª¡£RealNetworksHelixServerºÍHelixMobileServer11.1.3֮ǰµÄ°æ±¾£¬ÒÔ¼°HelixDNAServer11.0ºÍ11.1ÖдæÔÚ»ùÓڶѵĻº³åÇøÒç³ö£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÔ̺¬ÎÞЧLoadTestPassword×ֶεÄÃèÊöÒªÇóÔì³É»Ø¾ø·þÎñ£¨ÀûÓ÷¨Ê½±ÀÀ££©»òÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

TCP_ÆäËü×¢Èë_Courier_IMAP_4.0.1_XMAILDIR±äÁ¿Ô¶³ÌShellºÅÁî×¢Èë

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCourierIMAPXMAILDIR±äÁ¿Ô¶³ÌShellºÅÁî×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£Courier-IMAPÊÇCourierÓʼþϵͳÖеÄIMAP·þÎñ·¨Ê½¡£Courier-IMAP¶Ô±äÁ¿Êý¾ÝµÄ¹ýÂËÉÏ´æÔÚ·ì϶£¬Ô¶³Ì¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

TCP_Òç³ö¹¥»÷_CA_BrightStor_ARCserve_Backup·þÎñÔ¶³Ì»º³åÇøÒç³ö[CVE-2006-6076]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCABrightStorARCserveBackup·þÎñÔ¶³Ì»º³åÇøÒç¶Âí½Å¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£CABrightStorARCserveBackup11.5ÒÔ¼°¸üÔç°æ±¾ÖеÄTapeEngine´æÔÚ»º³åÇøÒç¶Âí½Å£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¶ÔTCP¶Ë¿Ú6502µÄijЩRPCÒªÇóÀ´Ö´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ÖÂÔ¶OA_E-Bridge_saveYZJFile_ËÁÒâÎļþ¶ÁÈ¡

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

δÊÚȨËÁÒâÎļþ¶ÁÈ¡,/wxjsapi/saveYZJFile½Ó¿Ú»ñÈ¡filepath,ÊäÈëÎļþõè¾¶->¶ÁÈ¡ÎļþÄÚÈÝ¡£·µ»ØÊý¾Ý°üÄÚ³öÏÖÁË·¨Ê½µÄ¾ø¶Ôõè¾¶,¹¥»÷ÕßÄܹ»Í¨¹ý·µ»ØÄÚÈݼø±ð·¨Ê½ÔËÐÐõè¾¶´Ó¶øÏÂÔØÊý¾Ý¿âÅäÖÃÎļþ¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_Free-IPA_XXE×¢Èë[CVE-2022-2414][CNNVD-202207-2780]

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º

FreeIPAÊÇÃâ·ÑµÄ¿ªÔ´Éí·ÝÖÎÀíϵͳ£¬Æäv11.2.0-beta3ǰµÄ°æ±¾´æÔÚXMLʵÌå×¢Èë·ì϶£¬¹¥»÷Õß¿ÉÄÜ¿ÉÄÜÀûÓø÷ì϶¶Áȡָ±ê·þÎñÆ÷Îļþ£¬¶Ë¿Ú̽²âµÈ²Ù×÷

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_±©Á¦²Â½â_HikvisionDVRDS-7204HGHI_±©Á¦²Â½â[CVE-2020-7057][CNNVD-202001-467]

°²È«ÀàÐÍ£º

Çî¾Ù̽²â

ÊÂÎñÃèÊö£º

HikvisionDVRDS-7204HGHIV4.0.1build°æ±¾´æÔÚÓû§Ã¶¾Ù·ì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ý·µ»Ø°üÅжÏÓû§ÊÇ·ñ´æÔÚ

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SonicWall-SSL-VPN_jarrewrite.sh_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

SonicWallSSL-VPN²úÆ·ÖÐʹÓÃÁ˼«ÎªÀϾɵÄLinuxÄں˺ÍHTTPCGI¿ÉÖ´Ðз¨Ê½£¬¸Ã·¨Ê½ÔÚ´¦ÖÃhttpÒªÇóʱ£¬ÎÞ·¨ÕýÈ·µÄ½âÎöhttpheader¡£¸Ã·ì϶µ¼ÖºÅÁî×¢È룬Զ³Ì¹¥»÷Õßͨ¹ý×¢ÈëºÅÁîÄܹ»ÇáËɵĻñµÃnobodyÓû§È¨Ï޵ĽÚÔìȨÏÞ¡£Í¬Ê±ÓÉÓÚÀϾÉÄں˵ÄÎÊÌâÒÔ¼°ÆäÖдæÔÚ·ì϶µÄ¿ÉÖ´Ðз¨Ê½£¬¹¥»÷ÕßÄܹ»µÈÏеÄÌáÉýȨÏÞ²¢ÆëÈ«ÊÕÊܸ÷þÎñÆ÷¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Webmin-Software-Package-Updates_ºÅÁîÖ´ÐÐ[CVE-2022-36446]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

WebminÊÇUnixϵͳÖÎÀíWeb½Ó¿Ú£¬Í¨¹ýÈÎÒ»ä¯ÀÀÆ÷¶¼¿ÉÉèÖÃÓû§ÕË»§¡¢Apache¡¢DNS¡¢DNS¡¢Îļþ¹²Ïí¼°ÆäËû¡£Webmin1.998ÒÔǰµÄ°æ±¾µÄ/package-updates/update.cgiÔÚ°²È«·ì϶£¬¿ÉÔÊÐíͨ¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÓû§Ö´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌºÅÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓÓ×®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâOGNL±í°×ʽ¡£·ì϶´æÔڵİ汾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷³É¹¦£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220823

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_Ô¶³Ì½ÚÔìÈí¼þ_·¢ÏÖToDeskʹÓÃ

°²È«ÀàÐÍ£º

°²È«Éó¼Æ

ÊÂÎñÃèÊö£º

¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÔÚʹÓÃToDesk¡£ToDeskÊÇÒ»¿î¶àƽ̨Զ³Ì½ÚÔì/Ô¶³ÌЭÖúÈí¼þ£¬Ö÷´òÁ÷³©ÒÔ¼°Ó×ÎÒÃâ·ÑµÄÌØµã¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

TCP_ľÂí_PSW.OnlineGames_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£Trojan.PSW.OnlineGamesÊÇÒ»¸öÍøÓεÁºÅľÂí£¬µÁÈ¡ÍøÓÎDNFµÄÕ˺ÅÃÜÂë·¢Ë͵½ºÚ¿Í·þÎñÆ÷¡£µÁÈ¡ÍøÓÎDNFµÄÕ˺ÅÃÜÂë¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_µÇ¼³É¹¦

°²È«ÀàÐÍ£º

´àÈõ¿ÚÁî

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPµØÖ·Ö÷»ú³É¹¦µÇ¼µ½Ö÷ÕÅIPµØÖ·Ö÷»úµÄÊÂÎñ¡£¸ÃÊÂÎñÊÇÕý³£µÄÍøÂçÐÐΪ£¬Í¨³£Ã»ÓзçÏÕ¡£

¸üй¦·ò£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌºÅÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓÓ×®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâOGNL±í°×ʽ¡£·ì϶´æÔڵİ汾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷³É¹¦£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220823