ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ04ÖÜ

Ðû²¼Ê±¼ä 2020-02-04

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê01ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Çå¾²Îó²î42¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Webex Video Mesh WEB½Ó¿Úí§ÒâÏÂÁîÖ´ÐÐÎó²î; Ruckus Wireless Unleashed emfdí§ÒâOSÏÂÁîÖ´ÐÐÎó²î£»£»£»£»£» £»Trustwave ModSecurity Transaction::addRequestHeader¾Ü¾øÐ§ÀÍÎó²î£»£»£»£»£» £»Honeywell Maxpro VMS & NVR·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»£»£»£»£» £»Philips Hue Bridge ZCL¶ÑÒç³öÎó²î¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÃÀ¹ú¹ú¼Ò±ê×¼ÊÖÒÕÑо¿ÔºÐû²¼Òþ˽Σº¦ÖÎÀí¿ò¼Ü1.0°æ£»£»£»£»£» £»GDPRî¿Ïµ»ú¹¹Æù½ñΪֹÒÑ·£¿£¿£¿£¿£¿î1.26ÒÚÃÀÔª£»£»£»£»£» £»Î¢Èíй¶2.5ÒÚÌõºô½ÐÖÐÐļͼ£¬£¬£¬£¬£¬£¬£¬£¬¿Í»§ÓÊÏä¼°IPµØµã̻¶£»£»£»£»£» £»Ñо¿Ö°Ô±Åû¶FortiSIEMÖеÄÓ²±àÂëSSHÃÜÔ¿Îó²î£»£»£»£»£» £»Æ»¹ûÐû²¼Í¸Ã÷¶È±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬Åû¶¸÷¹úÕþ¸®ÇëÇ󯻹ûÓû§Êý¾ÝÇéÐΡ£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Cisco Webex Video Mesh WEB½Ó¿Úí§ÒâÏÂÁîÖ´ÐÐÎó²î


Cisco Webex Video Mesh WEB½Ó¿Ú±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200108-webex-video


2. Ruckus Wireless Unleashed emfdí§ÒâOSÏÂÁîÖ´ÐÐÎó²î


Ruckus Wireless Unleashed emfd admin/_cmdstat.jsp²»×¼È·´¦Öóͷ£xcmd=import-categoryÊôÐÔ£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄPOSTÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£¡£¡£¡£


https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.html


3. Trustwave ModSecurity Transaction::addRequestHeader¾Ü¾øÐ§ÀÍÎó²î


Trustwave ModSecurity Transaction::addRequestHeader±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£¡£¡£¡£


https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-denial-of-service-details-cve-2019-19886/


4. Honeywell Maxpro VMS & NVR·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î


Honeywell Maxpro VMS & NVR´¦Öóͷ£WEBÇëÇó±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


https://www.us-cert.gov/ics/advisories/icsa-20-021-01


5. Philips Hue Bridge ZCL¶ÑÒç³öÎó²î


Philips Hue Bridge´¦Öóͷ£³¬³¤ZCL×Ö·û´®±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


https://www2.meethue.com/en-us/support/release-notes/bridge


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÃÀ¹ú¹ú¼Ò±ê×¼ÊÖÒÕÑо¿ÔºÐû²¼Òþ˽Σº¦ÖÎÀí¿ò¼Ü1.0°æ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÃÀ¹ú¹ú¼Ò±ê×¼ÊÖÒÕÑо¿Ôº£¨NIST£©ÉÏÖÜÐû²¼ÁËÒþ˽¿ò¼Ü1.0°æ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¤¾ßÖ¼ÔÚ×ÊÖú×éÖ¯ÖÎÀíÒþ˽Σº¦¡£¡£¡£¡£¡£¡£¡£NISTÓÚ2019Äê9ÔÂÐû²¼ÁËÒþ˽¿ò¼Ü³õ¸å²¢ÍøÂ繫ÖÚÒâ¼û£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»ú¹¹×î³õÏ£ÍûÔÚ2019Äêµ×֮ǰÐû²¼1.0°æ£¬£¬£¬£¬£¬£¬£¬£¬µ«Ö±µ½1ÔÂ16ÈÕ²ÅÕýʽÐû²¼¡£¡£¡£¡£¡£¡£¡£NISTÒþ˽¿ò¼ÜÖ¼ÔÚͨ¹ý¹Ø×¢Èý¸öÖ÷Òª·½ÃæÀ´×ÊÖúÖÖÖÖ¹æÄ£ºÍ¸÷¸ö²¿·ÖµÄ×éÖ¯ÖÎÀíÒþ˽Σº¦£ºÔÚ¿ª·¢²úÆ·»òЧÀÍʱҪ˼Á¿µ½Òþ˽¡¢½»Á÷Òþ˽ÀÏÀýÒÔ¼°¿ç×éÖ¯µÄЭ×÷¡£¡£¡£¡£¡£¡£¡£¸Ã¿ò¼Ü°üÀ¨Èý¸öÖ÷Òª²¿·Ö£º½¹µã¡¢ÌáÒªºÍʵÏֲ㡣¡£¡£¡£¡£¡£¡£½¹µãÌṩһ×éϸ»¯µÄ»î¶¯ºÍЧ¹û£¬£¬£¬£¬£¬£¬£¬£¬ÆäÄ¿µÄÊÇʵÏÖÄÚ²¿Ïàͬ¡£¡£¡£¡£¡£¡£¡£ÌáÒª²ãÌåÏÖ×éÖ¯ÒÑÈ·¶¨½¹µãÖ°ÄÜ¡¢ÖÖ±ðºÍ×ÓÀà±ðµÄÓÅÏȼ¶±ð¡£¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬£¬£¬ÊµÑé²ã¿É×ÊÖú×éÖ¯ÓÅ»¯ÊµÏÖÌáÒª²ãËùÐèµÄ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/nist-releases-framework-privacy-risk-management


2¡¢GDPRî¿Ïµ»ú¹¹Æù½ñΪֹÒÑ·£¿£¿£¿£¿£¿î1.26ÒÚÃÀÔª


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Ò»ÏîеÄÊӲ췢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬Æù½ñΪֹî¿Ïµ»ú¹¹ÒѶÔÊý¾Ýй¶ºÍÆäËûGDPRÇÖȨÐÐΪ´¦ÒÔÁ˼ÛÖµ1.26ÒÚÃÀÔªµÄ·£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤DLA PiperµÄGDPRÊý¾ÝÎ¥¹æÊӲ죬£¬£¬£¬£¬£¬£¬£¬Êý¾Ý±£»£»£»£»£» £»¤î¿Ïµ»ú¹¹ÔÚ2018Äê5ÔÂ25ÈÕÖÁ2020Äê1ÔÂ27ÈÕʱ´ú¶ÔGDPRÏà¹ØµÄ·£¿£¿£¿£¿£¿îΪ1.14ÒÚÅ·Ôª£¨Ô¼ºÏ1.26ÒÚÃÀÔª/ 9,700ÍòÓ¢°÷£©¡£¡£¡£¡£¡£¡£¡£Õâ¼Ò¹ú¼Ê״ʦÊÂÎñËùÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬·¨¹ú¡¢µÂ¹úºÍ°ÂµØÀûµÄ·£¿£¿£¿£¿£¿î×ܶî×î¸ß£¬£¬£¬£¬£¬£¬£¬£¬»®·ÖΪ5100ÍòÅ·Ôª£¬£¬£¬£¬£¬£¬£¬£¬2450ÍòÅ·ÔªºÍ1800ÍòÅ·Ôª¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ²¢Î´º­¸ÇÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¶ÔÓ¢¹úº½¿Õ¹«Ë¾£¨British Airways£©´¦ÒÔ1.83ÒÚÓ¢°÷µÄGDPR·£¿£¿£¿£¿£¿î¼°¶ÔÍòºÀ¹ú¼Ê¹«Ë¾£¨Marriott International£©¾ÙÐÐ9990ÍòÓ¢°÷µÄGDPR·£¿£¿£¿£¿£¿î£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ×èÖ¹±¨¸æÍê³ÉʱICOÉÐδ×îÖÕÈ·¶¨´¦ÒÔ·£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/gdpr-regulators-have-imposed-126m-in-fines-thus-far-finds-survey/


3¡¢Î¢Èíй¶2.5ÒÚÌõºô½ÐÖÐÐļͼ£¬£¬£¬£¬£¬£¬£¬£¬¿Í»§ÓÊÏä¼°IPµØµã̻¶


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


È¥ÄêÄêµ×£¬£¬£¬£¬£¬£¬£¬£¬ComparitechµÄÇå¾²Ñо¿ÍŶӷ¢Ã÷Á˼¸Ì¨Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Ã¿Ì¨Ð§ÀÍÆ÷¶¼°üÀ¨ÓëMicrosoftÖ§³ÖÊðÀíºÍ¿Í»§ÏàͬµÄ2.5ÒÚºô½ÐÖÐÐļͼ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¼Í¼ËùÁýÕÖµÄʱ¼ä¶ÎΪ2005ÄêÖÁ2019Äê12Ô£¬£¬£¬£¬£¬£¬£¬£¬Æä²¢Ã»ÓÐʹÓÃÃÜÂë±£»£»£»£»£» £»¤»ò¼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒ²Òâζ×Å£¬£¬£¬£¬£¬£¬£¬£¬ÈκοÉÒÔ»á¼û»¥ÁªÍøµÄÈ˶¼¿ÉÒÔ¶ÔÆä¾ÙÐлá¼û¡£¡£¡£¡£¡£¡£¡£´ó´ó¶¼Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢ÒѴӼͼÖÐɾ³ý¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬£¬ÈÔÈ»±£´æ´ó×ÚÒÔ´¿Îı¾ÃûÌô洢µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨£º¿Í»§µç×ÓÓʼþµØµã¡¢IPµØµã¡¢Î»Öá¢CSSÉùÃ÷ºÍ°¸ÀýµÄÐÎò¡¢MicrosoftÖ§³ÖÊðÀíµç×ÓÓʼþ¡¢°¸Àý±àºÅ¡¢°¸Àý½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬£¬£¬°¸Àý±¸×¢ºÍ±ê¼ÇΪ¡°ÉñÃØ¡±µÄÄÚ²¿×¢ÊÍ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/microsoft-exposes-250-million-call/


4¡¢Ñо¿Ö°Ô±Åû¶FortiSIEMÖеÄÓ²±àÂëSSHÃÜÔ¿Îó²î


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


CyberaµÄÇ徲ר¼ÒAndrew Klaus·¢Ã÷FortinetÇå¾²ÐÅÏ¢ºÍÊÂÎñÖÎÀíÆ÷ FortiSIEMÖеÄÓ²±àÂëSSH¹«Ô¿Îó²î£¬£¬£¬£¬£¬£¬£¬£¬¿É±»ÀÄÓÃÓÚ»á¼ûFortiSIEM Supervisor¡£¡£¡£¡£¡£¡£¡£¸ÃÓ²±àÂëSSHÃÜÔ¿ÊôÓÚÓû§¡°tunneluser¡±¡£¡£¡£¡£¡£¡£¡£ÔÚËùÓÐ×°ÖÃÖ®¼ä¶¼Ïàͬ¡£¡£¡£¡£¡£¡£¡£Ê¹ÓôËÃÜÔ¿µÄ¹¥»÷Õß¿ÉÒÔÒÔ¸ÃÓû§Éí·ÝÀÖ³Éͨ¹ýFortiSIEM Supervisor¾ÙÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£ËäÈ»¸ÃÓû§µÄshell½öÏÞÓÚÔËÐо籾/opt/phoenix/phscripts/bin/tunnelshell£¬£¬£¬£¬£¬£¬£¬£¬SSHÈÏÖ¤ÈÔÈ»ÊÇÀֳɵÄ¡£¡£¡£¡£¡£¡£¡£FortinetÐû²¼Ç徲ͨ¸æ³Æ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄ±àºÅÊÇ CVE-2019-17659£¬£¬£¬£¬£¬£¬£¬£¬Ëü¿Éµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/96649/security/hardcoded-ssh-key-fortinet.html


5¡¢Æ»¹ûÐû²¼Í¸Ã÷¶È±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬Åû¶¸÷¹úÕþ¸®ÇëÇ󯻹ûÓû§Êý¾ÝÇéÐÎ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


1ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Æ»¹ûÖÜÎåÐû²¼Á˰ëÄê¶È͸Ã÷¶È±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬Åû¶Á˸÷¹úÕþ¸®ÔÚÈ«Çò¹æÄ£ÄÚÏòÆäË÷È¡Óû§Êý¾ÝµÄ´ÎÊý¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Æ»¹ûÐû²¼µÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ2019Äê1ÔÂ1ÈÕÖÁ6ÔÂ30ÈÕÖ®¼ä£¬£¬£¬£¬£¬£¬£¬£¬¸÷¹úÕþ¸®Ìá³öÁË31778´Î×°±¸ÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬±È2018ÄêÉϰëÄêÔöÌíÁËÔ¼500´Î¡£¡£¡£¡£¡£¡£¡£ÕâÀàÐÅÏ¢°üÀ¨ÄÄЩÓû§ÓëÄÄЩװ±¸Ïà¹ØÁª£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°¹ºÖᢿͻ§Ð§ÀͺÍάÐÞÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Æ»¹ûÔÚÆäÖÐ82%µÄʱ¼äÖª×ãÁ˶Է½µÄÒªÇ󡣡£¡£¡£¡£¡£¡£µÂ¹úÌá³ö×°±¸ÒªÇóÔÙ´Îλ¾Ó°ñÊ×£¬£¬£¬£¬£¬£¬£¬£¬µÖ´ï13558´Î£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÔÚ6¸öÔÂÄÚÌá³öÁË4796´Î×°±¸ÇëÇ󡣡£¡£¡£¡£¡£¡£ÕÊ»§ÇëÇó£¨ÀýÈ磬£¬£¬£¬£¬£¬£¬£¬ÓйØiCloudºÍiTunesÕÊ»§µÄÏêϸÐÅÏ¢£©ÔÚ6¸öÔÂÄÚµÖ´ïÁË6480´Î¡£¡£¡£¡£¡£¡£¡£Æ»¹ûÔÚ85£¥µÄÇéÐÎ϶¼»áÌṩÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´ó²¿·ÖÕ˺ÅÇëÇóÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬£¬µÖ´ï3619´Î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.apple.com/legal/transparency/pdf/requests-2019-H1-en.pdf