×êÑÐÍŶÓÅû¶Ëĸö¿ªÔ´TCP/IP¿âÖеÄ33¸ö·ì϶Amnesia:33£»£»£»£»£»Å·ÃËEMAÔâµ½¹¥»÷£¬£¬£¬£¬ £¬£¬COVID-19ÒßÃçÓйصÄÎļþ±»µÁ

°ä²¼¹¦·ò 2020-12-10
1.×êÑÐÍŶÓÅû¶Ëĸö¿ªÔ´TCP/IP¿âÖеÄ33¸ö·ì϶Amnesia:33


1.png


ForescoutµÄ×êÑÐÍŶÓÅû¶ÁËËĸö¿ªÔ´TCP/IP¿âÖеÄ33¸ö·ì϶£¬£¬£¬£¬ £¬£¬²¢½«ËüÃǶ¨ÃûΪAmnesia:33¡£¡£¡£¡£¡£¡£ÕâËĸö¿ªÔ´¿â±ðÀëΪuIP¡¢FNET¡¢picoTCPºÍNut/Net£¬£¬£¬£¬ £¬£¬Ó°ÏìÁË150¶à¼Ò¹©¸øÉ̵IJúÆ·¡£¡£¡£¡£¡£¡£Forescout°µÊ¾£¬£¬£¬£¬ £¬£¬ºÚ¿Í¿ÉÀûÓÃÕâ33¸ö·ì϶ÌáÒéÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷ÒÔ½ÚÔìÖ¸±êÉ豸£¬£¬£¬£¬ £¬£¬»Ø¾ø·þÎñ£¨DoS£©¹¥»÷ÒÔÓ°Ï칫˾ҵÎñÔËÓª£¬£¬£¬£¬ £¬£¬ÐÅϢй©£¨infoleak£©¹¥»÷ÒÔ»ñȡDZÔÚµÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬ £¬£¬DNS»º´æÖж¾¹¥»÷ÒÔ½«É豸ָÏò¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/amnesia33-vulnerabilities-impact-millions-of-smart-and-industrial-devices/


2.Google°²È«¸üУ¬£¬£¬£¬ £¬£¬½¨¸´Android OSÖеÄ10¸ö·ì϶


2.png


Google°ä²¼°²È«¸üУ¬£¬£¬£¬ £¬£¬½¨¸´Android OSÖеÄ10¸öÑϳÁµÄ·ì϶¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄ·ì϶Ϊ´úÂëÖ´Ðзì϶£¬£¬£¬£¬ £¬£¬±»×·×ÙΪCVE-2020-0458£¬£¬£¬£¬ £¬£¬ÓëAndroidýÌå¿ò¼Ü×é¼þÓйأ¬£¬£¬£¬ £¬£¬¿ÉÈù¥»÷ÕßÔ¶³Ì½ÚÔìÒ×Êܹ¥»÷µÄÊÖ»ú¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬ÆäËûµÄ¾Å¸ö·ì϶¾ùÓë¸ßͨ£¨Qualcomm)µÄµ×²ãоƬ×éºÍÅäÌ׹̼þÓйأ¬£¬£¬£¬ £¬£¬ÔÚ´óÎÞÊýAndroidÊÖ»úÉ϶¼ºÜ³£¼û¡£¡£¡£¡£¡£¡£ÀýÈç±»×·×ÙΪCVE-2020-11225µÄ·ì϶£¬£¬£¬£¬ £¬£¬Óë¸ßͨÎÞÏßµç̨µÄWLANÖ÷»úͨѶ×é¼þÓйء£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/google-patches-critical-wi-fi-and-audio-bugs-in-android-handsets/162060/


3.GE HealthcareÉϰٿîÐͺŵÄÉ豸´æÔÚMDHexRay·ì϶


3.png


°²È«¹«Ë¾CyberMDX·¢ÏÖ£¬£¬£¬£¬ £¬£¬GE HealthcareÉϰٿîÐͺŵÄÉ豸´æÔÚMDHexRay·ì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-25179£¬£¬£¬£¬ £¬£¬ÑϳÁˮƽΪ9.8·Ö£¬£¬£¬£¬ £¬£¬Ó°ÏìÁ˸ù«Ë¾Ê®¼¸Ìõ²úÆ·ÏßµÄ100¶à¸öCT¡¢x¹â¡¢MRIÉ豸ÐͺŵÄÉ豸¡£¡£¡£¡£¡£¡£MDHexRay·ì϶´æÔÚµÄÔ­ÒòÊÇÈí¼þÔÚÿ´Î×°ÖÃÖж¼Ê¹ÓÃĬÈÏÍ´´¦£¬£¬£¬£¬ £¬£¬ÒÔÏòGEµÄ·þÎñÆ÷½øÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬ £¬£¬µ«Í´´¦Êǹ«¿ª¿ÉÓõ쬣¬£¬£¬ £¬£¬ºÚ¿Í¿ÉÄÜ»áÀÄÓÃÕâЩÕÊ»§À´»ñȡҽԺºÍÕïËùÄÚ²¿µÄÒ½ÁÆÉ豸¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/account-with-default-creds-found-in-100-ge-medical-device-models/


4.Microsoft°ä²¼Óйػº½âDNSºýŪ¹¥»÷µÄÖ¸ÄÏ


4.png


Microsoft°ä²¼Óйػº½âDNSºýŪ¹¥»÷µÄÖ¸ÄÏ¡£¡£¡£¡£¡£¡£¸Ã·ì϶ΪѰַºýŪ·ì϶£¬£¬£¬£¬ £¬£¬±»¸ú×ÙΪCVE-2020-25705£¬£¬£¬£¬ £¬£¬Î»ÓÚÓëWindows´«Êä½ÚÔìºÍ̸/»¥ÁªÍøºÍ̸(TCP/IP)Õ»°ó¸¿ÔÚһ·µÄWindows DNS½âÎöÆ÷Èí¼þ×é¼þÖÓ×£¡£¡£¡£¡£¡£¹¥»÷Õ߳ɹ¦ÀûÓô˷ì϶Äܹ»ºýŪDNSÊý¾Ý°ü¡¢DNSת·¢Æ÷»òDNS½âÎöÆ÷¡£¡£¡£¡£¡£¡£ÎªÁË»º½â´Ë·ì϶£¬£¬£¬£¬ £¬£¬Microsoft°ä²¼¸ÃÖ¸ÄÏ£¬£¬£¬£¬ £¬£¬½¨ÒéWindowsÖÎÀíÔ±¸ü¸Ä×¢²á±í£¬£¬£¬£¬ £¬£¬½«×î´óUDPÊý¾Ý°ü´óÓ׸ü¸ÄΪ1221×Ö½Ú£¬£¬£¬£¬ £¬£¬¼´¿É×èÖ¹ÀûÓø÷ì϶µÄDNSºýŪ¹¥»÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-issues-guidance-for-dns-cache-poisoning-vulnerability/


5.NetgainÔâµ½ÀÕË÷Èí¼þµÄ¹¥»÷£¬£¬£¬£¬ £¬£¬Êý¾ÝÖÐÐı»ÆÈ¹Ø¹Ø


5.png


ÔÆÍйܺÍIT·þÎñÌṩÉÌNetgainÔâµ½ÀÕË÷Èí¼þµÄ¹¥»÷£¬£¬£¬£¬ £¬£¬Êý¾ÝÖÐÐı»ÆÈ¹Ø¹Ø¡£¡£¡£¡£¡£¡£NetgainΪҽÁƱ£½¡ºÍ¹ÜÕÊÐÐÒµµÄ¹«Ë¾ÌṩÍйܺÍÔÆIT½â¾ö¹æ»®£¬£¬£¬£¬ £¬£¬Ô̺¬ÍйÜIT·þÎñºÍ×ÀÃæ·þÎñ»·¾³¡£¡£¡£¡£¡£¡£12ÔÂ4ÈÕ£¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾ÏòÆä¿Í»§°ä²¼Óʼþ³ÆÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬ £¬£¬²¢ÓÚµÚ¶þÌì±»ÆÈ¹Ø¹ØÊý¾ÝÖÐÐÄÒÔ¸ôÀë²¢¶ôÔìÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬ £¬£¬NetgainÊýǧ̨·þÎñÆ÷Êܵ½ÁËÓ°Ï죬£¬£¬£¬ £¬£¬ÉÐδȷ¶¨¸´Ô­¹¦·ò£¬£¬£¬£¬ £¬£¬Ò²²»Ã÷ÏÔÊǺÎÀÕË÷Èí¼þÍŻ﹥»÷ÁËNetgain¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-forces-hosting-provider-netgain-to-take-down-data-centers/


6.Å·ÃËEMAÔâµ½¹¥»÷£¬£¬£¬£¬ £¬£¬COVID-19ÒßÃçÓйصÄÎļþ±»µÁ


6.png


Å·Ã˼à¹Ü»ú¹¹Å·ÖÞÒ©Æ·ÖÎÀí¾Ö£¨EMA£©³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬ £¬£¬ÓëCOVID-19ÒßÃçµÄÓйØÎļþ±»µÁ¡£¡£¡£¡£¡£¡£EMAÊÇÅ·Ã˵ÄÈ¨ÊÆÏ·Żú¹¹£¬£¬£¬£¬ £¬£¬ÕÆ¹ÜÆÀ¹À¡¢¼à¶½ºÍ¼à¶½ÒýÈëÅ·Ã˵ÄÐÂÒ©¡£¡£¡£¡£¡£¡£EMAĿǰÔÚÉó²éÁ½ÖÖCOVID-19ÒßÃçµÄÉêÇ룬£¬£¬£¬ £¬£¬ Ò»ÖÖÀ´×ÔÃÀ¹úÔìÒ©¹«Ë¾Moderna£¬£¬£¬£¬ £¬£¬ÁíÒ»ÖÖÊÇBioNTechÓëPfizer¹«Ë¾ºÏ×÷¿ª·¢µÄ¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬ £¬£¬BioNTechÓëPfizer°ä²¼½áºÏÉêÃ÷£¬£¬£¬£¬ £¬£¬°µÊ¾ºÚ¿ÍÒÑÔÚEMAµÄÍøÂç¹¥»÷ÆÚ¼ä½Ó¼ûÁËËûÃÇÌá½»µÄCOVID-19ÒßÃçÓйصÄÎļþ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/pfizer-covid-19-vaccine-documents-accessed-in-ema-cyberattack/