ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ¿ò¼Ü³õ¸å£»£»£»£»£»Verizon Wireless·ì϶µ¼ÖÂÔ¼200Íò¿Í»§µÄºÏͬй¶
°ä²¼¹¦·ò 2019-09-111.ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ¿ò¼Ü³õ¸å
ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº£¨NIST£©°ä²¼ÁËÒ»¸öÒþÖÔ¿ò¼Ü³õ¸å£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚͨ¹ýÆóÒµ·çÏÕÖÎÀíÔ®ÊÔìóÒµ¸ÄÉÆÓ×ÎÒÒþÖÔ¡£¡£¡£¡£¡£¡£NIST°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÒþÖÔ¿ò¼ÜÖ¼ÔÚͨ¹ýÈý¸öÊÂÏîÔ®ÊÔìóÒµ±£»£»£»£»£»¤Ó×ÎÒÒþÖÔ£ºÍ¨¹ýÔÚ·þÎñºÍ²úÆ·ÖÐÖ§³Ö·µÂ¾ö²ßÀ´³ÉÁ¢¿Í»§ÐÅÀµ£»£»£»£»£»ÍƹãºÏ¹æÊ¹Ãü;ÒÔ¼°ÍƽøÓë¿Í»§ºÍ¼à¹Ü»ú¹¹¾ÍÒþÖÔʵ¼Ê½øÐйµÍ¨¡£¡£¡£¡£¡£¡£¸ÃÕþ²ß×ñÑÍøÂ簲ȫ¿ò¼ÜµÄ½á¹¹£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÖ÷Ìâ¡¢¸Å¿öºÍÖ´Ðвã×é³É¡£¡£¡£¡£¡£¡£Ö÷ÌⲿÃÅÖ¼ÔÚÍÆ½ø¹ØÓÚÒþÖÔ±£»£»£»£»£»¤ÔËÓªºÍ½øÕ¹Á˾ֵĶԻ°£¬£¬£¬£¬£¬£¬£¬£¬¶ø¸Å¿ö²¿ÃÅÔòÍÆ¶¯Âú×ã×é֯ʹÃüºÍÒþÖÔ¼ÛÖµµÄ»î¶¯ºÍÁ˾ֵÄÓÅÏÈÖÈÐò¡£¡£¡£¡£¡£¡£Ö´ÐвãÔò¶Ô×éÖ¯´¦ÖÃÒþÖÔ·çÏÕÁ÷³ÌµÄ³ä·ÖÐÔ½øÐйµÍ¨ºÍ¾ö²ßÌṩ֧³Ö¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.executivegov.com/2019/09/nist-issues-preliminary-draft-of-privacy-framework/
2.Verizon Wireless·ì϶µ¼ÖÂÔ¼200Íò¿Í»§µÄºÏͬй¶
Ó¢¹ú°²È«×êÑÐÔ±Daley Bee·¢ÏÖVerizon WirelessϵͳµÄÒ»¸ö×ÓÓò´æÔÚ²»°²È«µÄÖ±½Ó¶ÔÏóÒýÓã¨IDOR£©·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܱ»ºÚ¿ÍÀûÓÃÀ´»ñÈ¡200Íò¿Í»§ºÏͬ¡£¡£¡£¡£¡£¡£¸Ã×ÓÓòÃûÊÇtelestore.verizonwireless.com£¬£¬£¬£¬£¬£¬£¬£¬Ëƺõ±»¹«Ë¾Ô±¹¤ÓÃÀ´½Ó¼ûÄÚ²¿PoS¹¤¾ßºÍ²é¿´¿Í»§ÐÅÏ¢¡£¡£¡£¡£¡£¡£½øÒ»²½·ÖÎö·¢ÏÖÁËÒ»¸öÖ¸ÏòPDFÌåʽµÄVerizon¿Í»§ºÏͬµÄURL£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËԱͨ¹ýÅú¸ÄGET²ÎÊýÖµ¿É½Ó¼ûÔ¼200Íò¸öºÏͬ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢É豸ÐͺźÍÐòÁкÅÒÔ¼°¿Í»§ÊðÃûµÈÄÚÈÝ¡£¡£¡£¡£¡£¡£Verizon֤ʵÁËÕâÒ»·ì϶£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ½Óµ½Í¨ÖªµÄÒ»¸öÔº󽨸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/vulnerabilities-exposed-2-million-verizon-customer-contracts
3.Stealth FalconкóÃÅÀûÓÃWindows BITS·þÎñÇÔÈ¡Êý¾Ý
ESET×êÑÐÈËÔ±·¢ÏÖAPT×éÖ¯Stealth FalconµÄкóÃÅÀÄÓÃWindows BITS·þÎñÀ´°µ²ØÆäÓëºÅÁîºÍ½ÚÔ죨C£¦C£©·þÎñÆ÷µÄͨѶÁ÷Á¿¡£¡£¡£¡£¡£¡£Windows BITSÊÇ΢ÈíÏòÈ«ÇòÓû§·¢ËÍWindows¸üеÄĬÈÏϵͳ£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒÔΪ¸ÃºóÃÅÕâÑù×öÊÇΪÁËÈÆ¹ý·À»ðǽ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÆóÒµÒÔΪBITSÁ÷Á¿ºÜ¿ÉÄÜÔ̺¬Èí¼þ¸üжøÆ«²îÓÚºöÂÔËü¡£¡£¡£¡£¡£¡£ESET½«¸ÃºóÃŶ¨ÃûΪWin32/StealthFalcon£¬£¬£¬£¬£¬£¬£¬£¬ËüÔÊÐí¹¥»÷ÕßÔÚÊÜϰȾµÄϵͳ¸ßµÍÔØºÍÔËÐÐÆäËü¶ñÒâ´úÂë»òÇÔÈ¡Êý¾Ý·¢Ë͵½Ô¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¸ÃºóÃÅËÆºõÊÇ2015Äê´´½¨µÄ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËÓë2016ÄêCitizen Lab»ã±¨ÖÐÏêÊöµÄPowershellºóÃÅÒ»ÑùµÄC£¦CÓòÃû¡£¡£¡£¡£¡£¡£ESETûÓÐй©ÐºóÃŵĹ¥»÷Çé¿ö»òÖ¸±ê¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/91019/apt/stealth-falcon-backdoor-bits.html
4.ZDIÅû¶Red Lion¹«Ë¾HMI²úÆ·ÖеĶà¸ö°²È«·ì϶
×êÑÐÈËÔ±ÔÚÃÀ¹úRed Lion¹«Ë¾Ôì×÷µÄÈË»ú½çÃæ£¨HMI£©±à³ÌÈí¼þÖз¢ÏÖ¶à¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£Red LionÊÇSpectrisµÄ×Ó¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬Æ¾¾ÝÃÀ¹úCISAµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Red LionµÄ²úÆ·ÔÚÈ«ÇòÁìÓòÄÚʹÓ㬣¬£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓڹؼüÔì×÷ÁìÓò¡£¡£¡£¡£¡£¡£Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±·¢ÏÖRed LionµÄCrimson±à³ÌÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬³ö¸ñÊÇ3.0¼°Ö®Ç°°æ±¾ºÍ3.112.00֮ǰµÄ3.1°æ±¾´æÔÚËĸö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬CVE-2019-10996¡¢CVE-2019-10978¡¢CVE-2019-10984ºÍCVE-2019-10990¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄÒ»¸ö·ì϶ÔÊÐí¹¥»÷Õßͨ¹ýÓÕʹָ±êÓû§´ò¿ª¶ñÒâCD3Îļþ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚµ±Ç°¹ý³ÌµÄ¸ßµÍÎÄÖÐÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ÁíÒ»¸ö·ì϶ÓëÓ²±àÂëµÄÍ´´¦Óйء£¡£¡£¡£¡£¡£Red Lion°ä²¼ÁËCrimson 3.1°æ±¾3112.00ÒÔ½¨²¹·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ«·î¸æ¿Í»§Ëü²»³ïËã°ä²¼Crimson 3.0µÄ¸üС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/several-vulnerabilities-found-red-lion-hmi-software
5.˼¿ÆTalosÅû¶NETGEARÎÞÏß·ÓÉÆ÷ÖеÄDoS·ì϶
˼¿ÆTalos·¢ÏÖNETGEAR N300ϵÁÐÎÞÏß·ÓÉÆ÷Ô̺¬Á½¸ö»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÏò·ÓÉÆ÷µÄ·ÖÆçÖ°ÄÜ·¢ËͶñÒâSOAPºÍHTTPÒªÇóÀ´ÀûÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÆäÆëÈ«±ÀÀ£¡£¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶ÊÇCVE-2019-5054£¬£¬£¬£¬£¬£¬£¬£¬´æÔÚÓÚHTTP·þÎñÆ÷µÄ»á»°´¦ÖÃÖ°ÄÜÖУ¬£¬£¬£¬£¬£¬£¬£¬·¢Ë͵½Éí·ÝÑéÖ¤Ò³ÃæµÄ¿ÕUser-Agent×Ö·û´®HTTPÒªÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓ㬣¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂHTTP·þÎñ±ÀÀ£¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶CVE-2019-5055´æÔÚÓÚÖ÷»ú½Ó¼ûµãÊØ»¤·¨Ê½£¨hostapd£©ÖУ¬£¬£¬£¬£¬£¬£¬£¬·¢Ë͵½<WFAWLANConfig£º1££PutMessage>·þÎñµÄÎÞЧÐòÁÐSOAPÒªÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓ㬣¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂhostapd·þÎñ±ÀÀ£¡£¡£¡£¡£¡£¡£TalosÈ·ÈÏN300 WNR2000v5·ÓÉÆ÷£¨¹Ì¼þ°æ±¾V1.0.0.70£©Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/09/vuln-spotlight-Netgear-N300-routers-DoS-sept-2019.html
6.΢Èí°ä²¼9Ô°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Á½¸ö0day
΢ÈíÔÚ9ÔµÄWindows°²È«¸üÐÂÖн¨¸´ÁË80¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬17¸öÑϳÁ·ì϶¡£¡£¡£¡£¡£¡£ÓÐÁ½¸ö·ì϶ÊÇ0day£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ΢Èí°ä²¼²¹¶¡Ö®Ç°ËüÃÇÒÑÔÚÒ°±í±»ÀûÓᣡ£¡£¡£¡£¡£ÕâÁ½¸ö·ì϶±ðÀëÊÇWindowsͨÓÃÈÕÖ¾Îļþϵͳ£¨CLFS£©Çý¶¯·¨Ê½ÖеÄEoP£¨CVE-2019-1214£©ºÍÓ°Ïìws2ifsl.sys£¨Winsock£©·þÎñµÄEoP£¨CVE-2019-1215£©£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíûÓÐÅû¶·ì϶ÔÚÒ°±íÀûÓõĸü¶àϸ½Ú¡£¡£¡£¡£¡£¡£±¾ÔÂ΢ÈíÒ²½¨¸´ÁËÔ¶³Ì×ÀÃæºÍ̸ÖеÄÁ½¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬CVE-2019-1290ºÍCVE-2019-1291¡£¡£¡£¡£¡£¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-patches-two-zero-days-in-massive-september-2019-patch-tuesday/


¾©¹«Íø°²±¸11010802024551ºÅ