ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ14ÖÜ

Ðû²¼Ê±¼ä 2021-04-06

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê03ÔÂ29ÈÕÖÁ04ÔÂ04ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´56¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Azure SphereδǩÃû´úÂëÖ´ÐЩ¶´£»SAP Solution Manager User-Experience MonitoringÊÚȨ¼ì²éȱʧ©¶´£»Adobe Creative Cloud Desktop ApplicationÈÎÒâÎļþдÈ멶´£»F5 BIG-IP Advanced WAF/ASM»º³åÇøÒç³ö©¶´£»Schneider Electric Interactive Graphical SCADA System CGFÎļþ½âÎöÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇNPM¿âNetmask×é¼þ´æÔÚ©¶´£¬¿ÉÓ°ÏìÊýÍò¸öÓ¦Ó÷¨Ê½£»Ó¢¹ú¹«Ë¾FatFaceѬȾConti£¬Áè¼Ý200GBÊý¾Ýй¶£»PHP¹Ù·½Git´æ´¢¿âÔâµ½¹©Ó¦Á´¹¥»÷£¬´úÂë¿âÒѱ»¸Ä¶¯£»Õë¶ÔÓ¡¶ÈµÄAPT×éÖ¯RedEchoÒѹرÕÆäʹÓõĻù´¡ÉèÊ©£»VMwareÐÞ¸´vRealize OperationsÖеÄSSRFµÈ¶à¸ö©¶´¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Microsoft Azure SphereδǩÃû´úÂëÖ´ÐЩ¶´


Microsoft Azure Sphere´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27080


2.SAP Solution Manager User-Experience MonitoringÊÚȨ¼ì²éȱʧ©¶´


SAP Solution Manager User-Experience Monitoring´æÔÚÊÚȨ¼ì²éȷʵ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ¿ØÖÆϵͳ¡£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=571343107


3.Adobe Creative Cloud Desktop ApplicationÈÎÒâÎļþдÈ멶´


Adobe Creative Cloud Desktop Application´æÔÚÈÎÒâÎļþдÈ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£

https://helpx.adobe.com/security/products/creative-cloud/apsb21-18.html


4.F5 BIG-IP Advanced WAF/ASM»º³åÇøÒç³ö©¶´


F5 BIG-IP Advanced WAF/ASM´¦ÖöñÒâHTTPÏìÓ¦´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.auscert.org.au/bulletins/ESB-2021.0872


5.Schneider Electric Interactive Graphical SCADA System CGFÎļþ½âÎöÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´


Schneider Electric Interactive Graphical SCADA System CGFÎļþ½âÎö´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-070-01


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢NPM¿âNetmask×é¼þ´æÔÚ©¶´£¬¿ÉÓ°ÏìÊýÍò¸öÓ¦Ó÷¨Ê½


1.jpg


¸Ã×é¼þÿÖÜÏÂÔØÁ¿Áè¼Ý300Íò´Î£¬½ØÖÁÏÖÔÚÀÛ¼ÆÏÂÔØÁ¿ÒÑÁè¼Ý2.38ÒڴΣ¬Ô¼ÓÐ27.8Íò¸öGitHub´æ´¢¿âÒÀÀµÓÚnetmask¡£¸Ã©¶´±»×·×ÙΪCVE-2021-28918£¬Ê®½øÖÆIPv4µØÖ·°üÂÞÇ°µ¼Áãʱ£¬ÍøÂçÑÚÂë´¦ÖûìºÏ¸ñʽIPµØÖ·µÄ·½Ê½¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓ°ÏìÓ¦Ó÷¨Ê½½âÎöµÄIPµØÖ·£¬Ôò¸Ã©¶´¿ÉÄÜ»áÒýÆðÖÖÖÖ©¶´£¬ÀýÈçµ¼Ö·þÎñÆ÷¶ËÇëÇóαÔ죨SSRF£©ºÍµ½Ô¶³ÌÎļþ°üÂÞ£¨RFI£©¡£Ä¿Ç°£¬¸Ã©¶´Òѱ»ÐÞ¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-netmask-networking-bug-impacts-thousands-of-applications/


2¡¢Ó¢¹ú¹«Ë¾FatFaceѬȾConti£¬Áè¼Ý200GBÊý¾Ýй¶


2.jpg


Ó¢¹ú·þ×°¹«Ë¾FatFaceÔâµ½ContiÀÕË÷Èí¼þ¹¥»÷£¬Áè¼Ý200GBÊý¾Ýй¶¡£¹¥»÷·¢ÉúÔÚ2021Äê1ÔÂ17ÈÕ£¬¹¥»÷Õß·ÃÎÊÁËFatFaceµÄÍøÂçºÍϵͳ£¬²¢ÀÕË÷850ÍòÃÀÔª£¬×îÖÕ¾­Ì¸ÅÐÊê½ðÈ·¶¨Îª200ÍòÃÀÔª¡£´Ë´Îй¶µÄ¿Í»§ÐÅÏ¢°üÂÞÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÓʼĵØÖ·ºÍ²¿ÃÅÐÅÓÿ¨ÐÅÏ¢£¨×îºóËÄλÊý×ÖºÍÓÐЧÆÚ£©¡£´ËÍ⣬¸Ã¹«Ë¾ÔÚÊý¾Ýй¶֪ͨÓʼþÖÐÒªÇóÆäÊÕ¼þÈËÎñ±Ø¶Ô´ËÓʼþ¼°ÆäÖаüÂÞµÄÐÅÏ¢Ñϸñ±£ÃÜ£¬ÒÔ´ËÊÔͼÑÚ¸ÇÊý¾Ý鶵ÄÊÂʵ£¬´ËʼþÔÚÍøÉÏÒýÆðÐùÈ»´ó²¨¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fatface-sends-controversial-data-breach-email-after-ransomware-attack/


3¡¢PHP¹Ù·½Git´æ´¢¿âÔâµ½¹©Ó¦Á´¹¥»÷£¬´úÂë¿âÒѱ»¸Ä¶¯


3.jpg


ÉÏÖÜÈÕ£¬Î¬»¤ÈËÔ±Rasmus Lerdorf·¢Ïֺڿ͹¥»÷ÁË·þÎñÆ÷git.php.net£¬²¢Ôڸ÷þÎñÆ÷µÄ×ÔÍйÜphp-src´æ´¢¿âÖÐÉÏ´«ÁË2¸öδ¾­ÊÚȨµÄ¸üаü£¬ÆäÖеÄÔ´´úÂë±»²åÈëÁËÃØÃܺóÃÅ´úÂë¡£´ËÍ⣬ÕâЩ¶ñÒâ´úÂëÊÇÒÔPHP´´½¨ÕßRasmus LerdorfµÄÃûÒåÌá½»µÄ¡£Ñо¿ÈËÔ±ÍƲâ´Ë´ÎÊÇÃûΪÒÀÀµ»ìÏý£¨dependency confusion£©µÄÐÂÐ͹©Ó¦Á´¹¥»÷·½Ê½£¬ËüÀûÓÃÁËÒ»¸ö¿ÉÄÜ°üÂÞÀ´×Ô˽Óк͹«¹²À´Ô´µÄ»ìºÏÒÀÀµ¿âµÄÈí¼þ¡£×÷ΪԤ·À´ëÊ©£¬PHPά»¤ÈËÔ±ÒѾö¶¨½«¹Ù·½PHPÔ´´úÂë´æ´¢¿âǨÒƵ½GitHub¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/


4¡¢Õë¶ÔÓ¡¶ÈµÄAPT×éÖ¯RedEchoÒѹرÕÆäʹÓõĻù´¡ÉèÊ©


4.jpg


APT×éÖ¯RedEchoÔÚ2Ôµױ»Ñо¿ÈËÔ±Åû¶ºó£¬ÒѹرÕÆäʹÓõĻù´¡ÉèÊ©¡£Recorded FutureµÄÄþ¾²ÈËÔ±ÓÚ2Ô·¢ÏÖÁ˸ÃAPT×éÖ¯£¬³Æ¸ÃÍÅ»ï×Ô2020Äê³õ¹¥»÷ÁËÓ¡¶ÈµÄÖÁÉÙ10¸öµçÁ¦²¿ÃÅ£¬»¹½«Ä¿±êÃé×¼Á˸ßѹÊäµç±äµçÕ¾ºÍȼú»ðÁ¦·¢µç³§¡£Ôڸ÷¢ÏÖÐû²¼¼¸Öܺó£¬RedEchoÒѾ­¹Ø±ÕÁ˲¿ÃÅÓÃÓÚ¿ØÖÆ°²×°ÔÚÄ¿±êÍøÂçÖеÄShadowPadºóÃŵĻù´¡ÉèÊ©¡£Ñо¿ÈËÔ±ÍƲ⣬¸ÃAPT×éÖ¯ÔÚ±»·¢ÏÖºó¿ÉÄܽ«ÆäC2תÒƵ½ÁËÆäËûµØ·½¡£    


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116094/apt/redecho-apt-c2-shutdown.html


5¡¢VMwareÐÞ¸´vRealize OperationsÖеÄSSRFµÈ¶à¸ö©¶´


5.jpg


VMwareÐû²¼Äþ¾²¸üУ¬ÒÔÐÞ¸´VMware vRealize OperationsÖеĶà¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖصÄ©¶´ÊÇvRealize Operations Manager APIÖеķþÎñÆ÷¶ËÇëÇóαÔ쩶´£¨CVE-2021-21975£©£¬CVSSv3ÆÀ·ÖΪ8.6£¬Ô¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÎÞÐèÓëÓû§½»»¥¼´¿ÉÀûÓôË©¶´À´ÇÔÈ¡¹ÜÀíƾ¾Ý¡£´ËÍ⣬»¹ÐÞ¸´ÁËÈÎÒâÎļþдÈ멶´£¨CVE-2021-21983£©£¬CVSSv3ÆÀ·ÖΪ7.2£¬¹¥»÷Õß¿ÉÀûÓÃÆäÔڵײã¹â×Ó²Ù×÷ϵͳµÄÈÎÒâλÖÃдÈëÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116145/security/vmware-vrealize-operations-ssrf-flaw.html