ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ15ÖÜ

Ðû²¼Ê±¼ä 2021-04-13

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê04ÔÂ05ÈÕÖÁ04ÔÂ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î41¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉýÎó²î£»£»£»£»£»£»OpenIAM Groovy Script´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»SonicWall GMSÔ¶³ÌȨÏÞÌáÉýÎó²î£»£»£»£»£»£»Skyworth Digital Technology RN510»º³åÇøÒç³öÎó²î¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»£»£»£»£»£»KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂçÌØ¹¤»î¶¯£»£»£»£»£»£»ÐÂ¼ÓÆÂ¹¤»áe2iÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢£»£»£»£»£»£»Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬£¬£¬£¬ÊÂÎñÈÔÔÚÊÓ²ìÖУ»£»£»£»£»£»ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÒøÐÐľÂíJaneleiro¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Cisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414í§Òâ´úÂëÖ´ÐÐÎó²î


CCisco RV345P Dual WAN Gigabit VPN Routers WEBÖÎÀí½Ó¿Ú±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÌáÉýȨÏÞ¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b


2.LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉýÎó²î


LiteSpeed Technologies OpenLiteSpeed web server±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÔÚÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£

https://github.com/litespeedtech/openlitespeed/issues/217


3.OpenIAM Groovy Script´úÂëÖ´ÐÐÎó²î


OpenIAM Groovy Script±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£

https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md


4.SonicWall GMSÔ¶³ÌȨÏÞÌáÉýÎó²î


SonicWall GMS±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0009


5.Skyworth Digital Technology RN510»º³åÇøÒç³öÎó²î


Skyworth Digital Technology RN510 /cgi-bin/app-staticIP.asp»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£

https://s3curityb3ast.github.io/KSA-Dev-011.md


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day


1.jpg


CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרעÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬£¬£¬£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬£¬£¬£¬Éæ¼°ÂþÑÜʽÅÌËã¡¢ÔÆÅÌËã¡¢DevOpsºÍÅÌËã»úÇå¾²Èí¼þÒÔ¼°Òƶ¯×°±¸¡£¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öÐÂÎó²î¡£¡£»®·ÖΪÌáȨÎó²î£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾Îó²î£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨÎó²î£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤Îó²î£¨CVE-2021-28248£©¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html


2¡¢KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂçÌØ¹¤»î¶¯


2.jpg


KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½ÄÏÕþ¸®ºÍ¾üÊÂ×éÖ¯µÄÍøÂçÌØ¹¤»î¶¯¡£¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬¿É¾ÙÐÐÎļþϵͳʹÓá¢Àú³ÌʹÓá¢ÆÁÄ»½ØÍ¼²¶»ñºÍí§ÒâÏÂÁîÖ´ÐС£¡£±ðµÄ£¬£¬£¬£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚÖØ´óÐÔ·½ÃæÈ¡µÃÁËÖØ´óǰ½ø£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÄ¿µÄºÍÔ´£©±»ÍêÈ«°þÀ룬£¬£¬£¬Ê£ÏµÄÉÙÊý²¿·ÖµÄÖµÊDz»Á¬¹áµÄ£¬£¬£¬£¬Õâ´ó´óÔöÌíÁËÑо¿Ö°Ô±¶ÔÆä¾ÙÐÐÆÊÎöµÄÄѶȡ£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spy-operations-vietnam-rat/165243/


3¡¢ÐÂ¼ÓÆÂ¹¤»áe2iÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢


3.jpg


ÐÂ¼ÓÆÂÌìϹ¤»á´ú±í´ó»á¾ÍÒµÓë¾ÍÒµÑо¿Ëù£¨e2i£©ÔÚ±¾ÖÜÒ»£¨4ÔÂ5ÈÕ£©Ðû²¼ÉùÃ÷³Æ£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÒѾ­»á¼ûÆäÓû§µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨Óû§µÄÐÕÃû¡¢½ÌÓý×ʸñºÍNRIC¡¢ÁªÏµ·½·¨ºÍ¾Íҵϸ½ÚµÈ¡£¡£ÊÂÎñ±¬·¢ÔÚ3ÔÂ12ÈÕ£¬£¬£¬£¬ÆäµÚÈý·½¹©Ó¦ÉÌ¡ª¡ªÁªÂçÖÐÐÄÕÛÎñ¹«Ë¾i-vic InternationalÔ±¹¤µÄÓÊÏäÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬¸ÃÓÊÏäµÄÔÆ¶Ë°üÀ¨ÁËÔ¼3Íò¸ö¼ÓÈëÁËe2i»î¶¯µÄÓû§ÐÅÏ¢£¬£¬£¬£¬¿ÉÊǸûú¹¹¾Ü¾øÍ¸Â¶×ܹ²Óм¸¶àÈËÔøÊ¹Óùýe2iµÄЧÀÍ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.straitstimes.com/tech/tech-news/personal-data-of-30000-people-who-use-ntucs-e2i-services-may-have-been-breached


4¡¢Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬£¬£¬£¬ÊÂÎñÈÔÔÚÊÓ²ìÖÐ


4.jpg


Å·ÃËίԱ»á½²»°È˳ƣ¬£¬£¬£¬°üÀ¨Î¯Ô±»áÔÚÄڵĶà¸öÅ·ÃË×éÖ¯ÔÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷¡£¡£ÏÖÔÚ¶Ô¸ÃÊÂÎñµÄȡ֤ÆÊÎöÈÔ´¦ÓÚ³õÆÚ½×¶Î£¬£¬£¬£¬ÉÐδ¼ì²âµ½±£´æÐÅϢй¶ÎÊÌâ¡£¡£Åí²©ÉçÌåÏÖ£¬£¬£¬£¬´Ë´ÎÊÂÎñ±ÈÅ·ÃËÒÔÍùÔâµ½µÄ¹¥»÷¸üΪÑÏÖØ£¬£¬£¬£¬Å·ÃËij¹ÙÔ±»¹Í¸Â¶£¬£¬£¬£¬ÆäÊÂÇéÖ°Ô±½üÆÚÊÕµ½ÁËÓйØÕë¶ÔÅ·Ã˵Ĵ¹ÂÚ¹¥»÷Ô¤¾¯¡£¡£ÏÖÔÚ£¬£¬£¬£¬Å·ÃËÈÔδ¹ûÕæÓйش˴ÎÊÂÎñµÄÐÔ×Ó»òÆä±³ºóµÄ¹¥»÷ÕßÉí·ÝµÄÐÅÏ¢¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-04-06/european-institutions-were-targeted-in-a-cyber-attack-last-week


5¡¢ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÒøÐÐľÂíJaneleiro


5.jpg


ESETµÄÑо¿Ö°Ô±Åû¶ÁËÕë¶ÔÀ­¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÐÍÒøÐÐľÂíJaneleiro¡£¡£¸ÃľÂíÖÁÉÙ´Ó2019ÄêÒÔÀ´¾Í×îÏÈÕë¶Ô°ÍÎ÷µÄÆóÒµ£¬£¬£¬£¬Éæ¼°¹¤³Ì¡¢Ò½ÁƱ£½¡¡¢ÁãÊÛ¡¢ÖÆÔìÒµ¡¢½ðÈÚ¡¢ÔËÊäºÍÕþ¸®µÈ¸÷¸öÁìÓò¡£¡£Janeleiroͨ¹ýαÔì´óÐÍÒøÐÐÍøÕ¾£¨SantanderºÍBanco do BrasilµÈ£©µÄµ¯´°À´ÓÕ»óÄ¿µÄ£¬£¬£¬£¬ÕâЩµ¯´°°üÀ¨ÐéαµÄ±í¸ñÀ´ÓÕʹĿµÄÊäÈëÒøÐÐÆ¾Ö¤ºÍСÎÒ˽¼ÒÐÅÏ¢¡£¡£±ðµÄ£¬£¬£¬£¬JaneleiroÊÇÓÉVisual Basic .NET±àдµÄ£¬£¬£¬£¬ÕâÓë¸ÃµØÇøµÄºÚ¿ÍËùϲ»¶µÄDelphiÓкܴóµÄÊÕÖ§¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/experts-uncover-new-banking-trojan.html