ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ43ÖÜ

Ðû²¼Ê±¼ä 2018-10-29

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2018Äê10ÔÂ22ÈÕÖÁ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î49¸ö£¬ £¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox ¶à¸öÄÚ´æÆÆËðí§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Eaton UPS 9PX 8000 SP CVE-2018-9279Óû§ÃÜÂëй¶Îó²î£»£»£»£»£»£»Citrix NetScaler SD-WAN OSÏÂÁî×¢ÈëÎó²î£»£»£»£»£»£»Moxa ThingsPro CVE-2018-18393ÃÜÂë¸ü¸ÄÎó²î£»£»£»£»£»£»Symantec Veritas NetBackup ApplianceÊäÈëÔ¶³Ì´úÂëÖ´ÐÐÎó²î; GEOVAP Reliance 4 SCADA/HMIÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǹúÌ©º½¿ÕÓοÍ×ÊÁÏÒÉÍâй£¬ £¬£¬£¬£¬ £¬²¨¼°Ô¼940ÍòÂÿͣ»£»£»£»£»£»Ò½Áưü¹Ü¹«Ë¾AnthemÔÞ³ÉΪÊý¾Ýй¶ÊÂÎñÅ⸶1600ÍòÃÀÔª£»£»£»£»£»£»ÃÀHealthCare.govÒ½ÁÆÏµÍ³ÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬£¬ £¬Ô¼7.5ÍòÓû§µÄÐÅÏ¢±»ÇÔ£»£»£»£»£»£»FacebookÒò½£ÇÅÆÊÎö³óÎű»Ó¢¹úICO·£¿£¿£¿£¿î50ÍòÓ¢°÷£»£»£»£»£»£»CyberXÐû²¼È«ÇòICSºÍIIoTΣº¦±¨¸æ£¨2019°æ£©¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£




¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1. Mozilla Firefox ¶à¸öÄÚ´æÆÆËðí§Òâ´úÂëÖ´ÐÐÎó²î


Mozilla Firefox±£´æÕûÊýÒç³öÎó²î£¬ £¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄWEBÒ³£¬ £¬£¬£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬ £¬£¬£¬£¬ £¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/



2. Eaton UPS 9PX 8000 SP CVE-2018-9279Óû§ÃÜÂëй¶Îó²î


Eaton UPS 9PX 8000 SPÍøÒ³ÖаüÀ¨Ã÷ÎÄÃÜÂ룬 £¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÓû§ÖÎÀíÃÜÂ룬 £¬£¬£¬£¬ £¬Î´ÊÚȨ»á¼û×°±¸¡£¡£¡£¡£¡£¡£¡£

https://powerquality.eaton.com/support/software-drivers/downloads/connectivity-firmware.asp


3. Citrix NetScaler SD-WAN OSÏÂÁî×¢ÈëÎó²î


Citrix NetScaler SD-WAN±£´æÊäÈëÑéÖ¤Îó²î£¬ £¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬ £¬¿ÉÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£¡£¡£¡£

https://support.citrix.com/article/CTX236992


4. Moxa ThingsPro CVE-2018-18393ÃÜÂë¸ü¸ÄÎó²î


Moxa ThingsPro±£´æÇå¾²Îó²î£¬ £¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬ £¬¸ü¸ÄÓû§ÃÜÂë¡£¡£¡£¡£¡£¡£¡£

https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/10/18/klcert-18-021-moxa-thingspro-iiot-gateway-and-device-management-software-solutions-password-management-issue/


5. Symantec Veritas NetBackup ApplianceÊäÈëÔ¶³Ì´úÂëÖ´ÐÐÎó²î


Symantec Veritas NetBackup£¨NBU£©Appliance±£´æÊäÈëÑéÖ¤Îó²î£¬ £¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬ £¬¿ÉÒÔrootÉí·ÝÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

https://www.veritas.com/content/support/en_US/security/VTS18-003.html



Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢¹úÌ©º½¿ÕÓοÍ×ÊÁÏÒÉÍâй£¬ £¬£¬£¬£¬ £¬²¨¼°Ô¼940ÍòÂÿÍ

welcome-°ÙÀÖ²©


¹úÌ©º½¿Õ23ÈÕÍíÐû²¼Í¨¸æ³Æ£¬ £¬£¬£¬£¬ £¬¸Ã¹«Ë¾¼°È«×Ê×Ó¹«Ë¾¸ÛÁúº½¿ÕÓÐÏÞ¹«Ë¾µÄÂÿÍ×ÊÁÏÔ⵽δÊÚȨ»á¼û£¬ £¬£¬£¬£¬ £¬Ô¼940ÍòÂÿÍ×ÊÁϱ»ÇÔÈ¡£¬ £¬£¬£¬£¬ £¬°üÀ¨Âÿ͵ÄÐÕÃû¡¢ÉúÈÕ¡¢µç»°¡¢µØµã¡¢Éí·ÝÖ¤¼°»¤ÕպŵÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬ £¬ÉÐÓÐ403ÕÅÒÑÓâÆÚµÄÐÅÓÿ¨ºÅÂëй¶¡£¡£¡£¡£¡£¡£¡£¹úÌ©º½¿Õ³ÆÊÜÓ°ÏìµÄÐÅϢϵͳÓ뺽°àÔË×÷ϵͳΪ×ÔÁ¦µÄϵͳ£¬ £¬£¬£¬£¬ £¬´Ë´ÎÊÂÎñ²»»á¶Ôº½°àÇå¾²×é³ÉÈκÎÓ°Ïì¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/mcafee-labs/android-timpdoor-turns-mobile-devices-into-hidden-proxies/


2¡¢Ò½Áưü¹Ü¹«Ë¾AnthemÔÞ³ÉΪÊý¾Ýй¶ÊÂÎñÅ⸶1600ÍòÃÀÔª


welcome-°ÙÀÖ²©


Ò½Áưü¹Ü¹«Ë¾AnthemÒÑÔÞ³ÉΪ2015ÄêµÄÖØ´óÊý¾Ýй¶ÊÂÎñÏòÃÀ¹úÕþ¸®Ö§¸¶´´¼Í¼µÄ1600ÍòÃÀԪϢÕù½ð¡£¡£¡£¡£¡£¡£¡£2015ÄêÔ¼7900ÍòAnthemÓû§µÄСÎÒ˽¼ÒÐÅϢй¶£¬ £¬£¬£¬£¬ £¬¹¥»÷Õßͨ¹ý´¹ÂÚÓʼþ»á¼ûÁ˸Ã×éÖ¯²¿·ÖÓû§µÄÐÕÃû¡¢Éç±£ºÅÂë¡¢Ò½ÁÆID¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþµØµãºÍ¾ÍÒµÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£AnthemÏÔȻδÄÜÆ¾Ö¤¿µ½¡°ü¹ÜÁ÷ͨÓëÔðÈη¨°¸£¨HIPAA£©µÄÒªÇóÍ×ÉÆ±£»£»£»£»£»£»¤Æä»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/anthem-in-record-16m-hipaa/


3¡¢ÃÀHealthCare.govÒ½ÁÆÏµÍ³ÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬£¬ £¬Ô¼7.5ÍòÓû§µÄÐÅÏ¢±»ÇÔ


welcome-°ÙÀÖ²©


ÉÏÖÜÎåÃÀ¹úÒ½Áưü¹ÜºÍÒ½ÁƽòÌùЧÀÍÖÐÐÄ£¨CMS£©Ðû²¼ÐÂÎųÆ£¬ £¬£¬£¬£¬ £¬ÓëHealthCare.govÏà¹ØµÄÒ»¸öÕþ¸®ÅÌËã»úϵͳÔâµ½ºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬£¬ £¬Ô¼7.5ÍòÃûÓû§µÄÃô¸ÐСÎÒ˽¼ÒÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£¡£CMSÌåÏÖÔÚ10ÔÂ16ÈÕÈ·ÈÏÁËÕâÒ»Êý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬£¬ £¬²¢½ûÓÃÁËÓëÒì³£»£»£»£»£»£»î¶¯Ïà¹ØµÄÓû§ÕË»§¡£¡£¡£¡£¡£¡£¡£CMSºÍFBIÕýÔÚÍýÏë֪ͨËùÓÐÊÜÓ°ÏìµÄÓû§£¬ £¬£¬£¬£¬ £¬²¢ÌṩÐÅÓñ£»£»£»£»£»£»¤µÈ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.apnews.com/212e1e36b10945968704bd7e86598a65


4¡¢FacebookÒò½£ÇÅÆÊÎö³óÎű»Ó¢¹úICO·£¿£¿£¿£¿î50ÍòÓ¢°÷


welcome-°ÙÀÖ²©


Ó¢¹úÐÅϢרԱ°ì¹«ÊÒICO×îÖÕÒò½£ÇÅÆÊÎö³óÎŶÔFacebook·£¿£¿£¿£¿î50ÍòÓ¢°÷¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ICO¶Ô¸Ã³óÎŵÄÊӲ죬 £¬£¬£¬£¬ £¬ÖÁÉÙÓÐ100ÍòÓ¢¹ú¹«ÃñµÄÊý¾ÝÔâµ½²»Õýµ±µÄ´¦Öóͷ££¬ £¬£¬£¬£¬ £¬²¢ÇÒFacebookûÓÐÄܹ»½ÓÄɺÏÊʵÄÊÖÒÕÊֶκͲ½·¥×èÖ¹ÕâÒ»Êý¾Ýй¶ÐÐΪ¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬ £¬£¬£¬£¬ £¬ÕâÒ»·£¿£¿£¿£¿îÊý¶î¹ØÓÚFacebook¶øÑÔ¾Åţһ룬 £¬£¬£¬£¬ £¬FacebookÈ¥ÄêµÄÈ«Çò×ÜÊÕÈë´ï315ÒÚÓ¢°÷¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÆ¾Ö¤×îеÄGDPR¹æÔò£¬ £¬£¬£¬£¬ £¬Facebook¿ÉÄÜÃæÁÙ×î¸ß12.6ÒÚÓ¢°÷µÄ·£¿£¿£¿£¿î£¬ £¬£¬£¬£¬ £¬µ«ÐÒÔ˵ÄÊÇGDPRÔڸóóÎű¬·¢Ö®ºó²Å×îÏÈÉúЧ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/10/facebook-cambridge-analytica.html


5¡¢CyberXÐû²¼È«ÇòICSºÍIIoTΣº¦±¨¸æ£¨2019°æ£©


welcome-°ÙÀÖ²©


ƾ֤CyberXµÄÈ«ÇòICSºÍIIoTΣº¦±¨¸æ£¨2019°æ£©£¬ £¬£¬£¬£¬ £¬ÓÉÓÚÔËÐйýʱµÄWindowsϵͳ£¬ £¬£¬£¬£¬ £¬Áè¼ÝÒ»°ëµÄÒªº¦»ù´¡ÉèʩϵͳÒ×ÊÜÕë¶ÔÐÔ¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÊÇ»ùÓÚ¶ÔÁù´óÖ޵Ķà¸ö¹¤ÒµÐÐÒµ£¨ÈçÖÆÔìÒµ¡¢»¯Ñ§Òµ¡¢¹«ÓÃÊÂÒµºÍÄÜÔ´ÒµµÈ£©µÄÁè¼Ý850¸öICS¼°SCADAÉú²úÍøÂç¾ÙÐÐÆÊÎöµÃÀ´¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚʹÓùýʱµÄÍøÂçͨѶЭÒ飨ÈçSNMPºÍFTP£©£¬ £¬£¬£¬£¬ £¬69%µÄICSÍøÂçʹÓÃÃ÷ÎÄ´«ÊäÃÜÂë¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://news.softpedia.com/news/53-percent-of-ics-networks-at-risk-because-of-legacy-windows-systems-523367.shtml


ÉùÃ÷£º±¾×ÊѶÓɰÙÀÖ²©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí