ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ15ÖÜ

Ðû²¼Ê±¼ä 2021-04-13

> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö


2021Äê04ÔÂ05ÈÕÖÁ04ÔÂ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î41¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414í§Òâ´úÂëÖ´ÐÐÎó²î£»LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉýÎó²î£»OpenIAM Groovy Script´úÂëÖ´ÐÐÎó²î£»SonicWall GMSÔ¶³ÌȨÏÞÌáÉýÎó²î£»Skyworth Digital Technology RN510»º³åÇøÒç³öÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂçÌع¤Ô˶¯£»Ð¼Óƹ¤»áe2iÔâµ½´¹ÂÚ¹¥»÷£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢£»Å·Ã˳ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬ÊÂÎñÈÔÔÚÊÓ²ìÖУ»ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÒøÐÐľÂíJaneleiro¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Cisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414í§Òâ´úÂëÖ´ÐÐÎó²î


CCisco RV345P Dual WAN Gigabit VPN Routers WEBÖÎÀí½Ó¿Ú±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÌáÉýȨÏÞ¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b


2.LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉýÎó²î


LiteSpeed Technologies OpenLiteSpeed web server±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÔÚÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁî¡£

https://github.com/litespeedtech/openlitespeed/issues/217


3.OpenIAM Groovy Script´úÂëÖ´ÐÐÎó²î


OpenIAM Groovy Script±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md


4.SonicWall GMSÔ¶³ÌȨÏÞÌáÉýÎó²î


SonicWall GMS±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0009


5.Skyworth Digital Technology RN510»º³åÇøÒç³öÎó²î


Skyworth Digital Technology RN510 /cgi-bin/app-staticIP.asp»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£

https://s3curityb3ast.github.io/KSA-Dev-011.md


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day


1.jpg


CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרעÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬Éæ¼°ÂþÑÜʽÅÌËã¡¢ÔÆÅÌËã¡¢DevOpsºÍÅÌËã»úÇå¾²Èí¼þÒÔ¼°Òƶ¯×°±¸¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öÐÂÎó²î¡£»®·ÖΪÌáȨÎó²î£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾Îó²î£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨÎó²î£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤Îó²î£¨CVE-2021-28248£©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html


2¡¢KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂçÌع¤Ô˶¯


2.jpg


KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½ÄÏÕþ¸®ºÍ¾üÊÂ×éÖ¯µÄÍøÂçÌع¤Ô˶¯¡£¸ÃÔ˶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬¿É¾ÙÐÐÎļþϵͳʹÓá¢Àú³ÌʹÓá¢ÆÁÄ»½Øͼ²¶»ñºÍí§ÒâÏÂÁîÖ´ÐС£±ðµÄ£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚÖØ´óÐÔ·½ÃæÈ¡µÃÁËÖØ´óÇ°½ø£¬ÀýÈ磬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÄ¿µÄºÍÔ´£©±»ÍêÈ«°þÀ룬ʣϵÄÉÙÊý²¿·ÖµÄÖµÊDz»Á¬¹áµÄ£¬Õâ´ó´óÔöÌíÁËÑо¿Ö°Ô±¶ÔÆä¾ÙÐÐÆÊÎöµÄÄѶÈ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spy-operations-vietnam-rat/165243/


3¡¢Ð¼Óƹ¤»áe2iÔâµ½´¹ÂÚ¹¥»÷£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢


3.jpg


мÓÆÂÌìϹ¤»á´ú±í´ó»á¾ÍÒµÓë¾ÍÒµÑо¿Ëù£¨e2i£©ÔÚ±¾ÖÜÒ»£¨4ÔÂ5ÈÕ£©Ðû²¼ÉùÃ÷³Æ£¬¹¥»÷Õß¿ÉÄÜÒѾ­»á¼ûÆäÓû§µÄСÎÒ˽¼ÒÐÅÏ¢¡£´Ë´Î鶵ÄÐÅÏ¢°üÀ¨Óû§µÄÐÕÃû¡¢½ÌÓý×ʸñºÍNRIC¡¢ÁªÏµ·½·¨ºÍ¾Íҵϸ½ÚµÈ¡£ÊÂÎñ±¬·¢ÔÚ3ÔÂ12ÈÕ£¬ÆäµÚÈý·½¹©Ó¦ÉÌ¡ª¡ªÁªÂçÖÐÐÄÕÛÎñ¹«Ë¾i-vic InternationalÔ±¹¤µÄÓÊÏäÔâµ½´¹ÂÚ¹¥»÷£¬¸ÃÓÊÏäµÄÔƶ˰üÀ¨ÁËÔ¼3Íò¸ö¼ÓÈëÁËe2iÔ˶¯µÄÓû§ÐÅÏ¢£¬¿ÉÊǸûú¹¹¾Ü¾ø͸¶×ܹ²Óм¸¶àÈËÔøʹÓùýe2iµÄ·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.straitstimes.com/tech/tech-news/personal-data-of-30000-people-who-use-ntucs-e2i-services-may-have-been-breached


4¡¢Å·Ã˳ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬ÊÂÎñÈÔÔÚÊÓ²ìÖÐ


4.jpg


Å·ÃËίԱ»á½²»°È˳Æ£¬°üÀ¨Î¯Ô±»áÔÚÄڵĶà¸öÅ·ÃË×éÖ¯ÔÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷¡£ÏÖÔÚ¶Ô¸ÃÊÂÎñµÄÈ¡Ö¤ÆÊÎöÈÔ´¦ÓÚ³õÆڽ׶Σ¬ÉÐδ¼ì²âµ½±£´æÐÅϢй¶ÎÊÌâ¡£Åí²©ÉçÌåÏÖ£¬´Ë´ÎÊÂÎñ±ÈÅ·ÃËÒÔÍùÔâµ½µÄ¹¥»÷¸üΪÑÏÖØ£¬Å·ÃËij¹ÙÔ±»¹Í¸Â¶£¬ÆäÊÂÇéÖ°Ô±½üÆÚÊÕµ½ÁËÓйØÕë¶ÔÅ·Ã˵Ĵ¹ÂÚ¹¥»÷Ô¤¾¯¡£ÏÖÔÚ£¬Å·ÃËÈÔδ¹ûÕæÓйش˴ÎÊÂÎñµÄÐÔ×Ó»òÆä±³ºóµÄ¹¥»÷ÕßÉí·ÝµÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-04-06/european-institutions-were-targeted-in-a-cyber-attack-last-week


5¡¢ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÒøÐÐľÂíJaneleiro


5.jpg


ESETµÄÑо¿Ö°Ô±Åû¶ÁËÕë¶ÔÀ­¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÐÍÒøÐÐľÂíJaneleiro¡£¸ÃľÂíÖÁÉÙ´Ó2019ÄêÒÔÀ´¾Í×îÏÈÕë¶Ô°ÍÎ÷µÄÆóÒµ£¬Éæ¼°¹¤³Ì¡¢Ò½ÁƱ£½¡¡¢ÁãÊÛ¡¢ÖÆÔìÒµ¡¢½ðÈÚ¡¢ÔËÊäºÍÕþ¸®µÈ¸÷¸öÁìÓò¡£Janeleiroͨ¹ýαÔì´óÐÍÒøÐÐÍøÕ¾£¨SantanderºÍBanco do BrasilµÈ£©µÄµ¯´°À´ÓÕ»óÄ¿µÄ£¬ÕâЩµ¯´°°üÀ¨ÐéαµÄ±í¸ñÀ´ÓÕʹĿµÄÊäÈëÒøÐÐƾ֤ºÍСÎÒ˽¼ÒÐÅÏ¢¡£±ðµÄ£¬JaneleiroÊÇÓÉVisual Basic .NET±àдµÄ£¬ÕâÓë¸ÃµØÇøµÄºÚ¿ÍËùϲ»¶µÄDelphiÓкܴóµÄÊÕÖ§¡£    


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/experts-uncover-new-banking-trojan.html