1MikroTik·ÓÉÆ÷´æÔÚȨÏÞÌáÉý©¶´³¬¹ý90Íǫ̀MikroTik·ÓÉÆ÷ÖдæÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´±»±ê¼ÇΪCVE-2023-30799£¬ÔÊÐíÓµÓÐÏÖÓйÜÀíÔ±ÕË»§µÄÔ¶³Ì¹¥»÷Õßͨ¹ýÉ豸µÄWinbox»òHTTP½Ó¿Ú½«ÆäȨÏÞÌáÉýΪ¡°³¬¼¶¹ÜÀíÔ±¡±¡£ÓÉÓÚMikroTik RouterOS´øÓÐÒ»¸öĬÈϵġ°admin¡±ÕË»§£¬Òò´Ë¹¥»÷ÕßÄܹ»Ê¹ÓùÜÀíÔ±ÕË»§ÀûÓøÃ©¶´¡£Ñо¿ÈËԱʹÓÃShodanÀ´È·¶¨¸Ã©¶´µÄÓ°Ï죬·¢ÏÖ47.4Íǫ̀É豸»ùÓÚÍøÂçµÄ¹ÜÀíÒ³ÃæÖдæÔÚ©¶´¡£È»¶ø£¬ÓÉÓڸé¶´Ò²¿Éͨ¹ýMikrotek¹ÜÀí¿Í»§¶ËWinbox½øÐÐÀûÓã¬ÓÐ92.6Íǫ̨̀É豸±©Â¶Á˸ùÜÀí¶Ë¿Ú£¬Òò´ËÓ°ÏìÒª´óµÃ¶à¡£https://www.bleepingcomputer.com/news/security/super-admin-elevation-bug-puts-900-000-mikrotik-devices-at-risk
2VMwareÐÞ¸´CVE-2023-20891©¶´VMwareÐÞ¸´ÁËVMware Tanzu Application Service for VM£¨TAS for VM£©ºÍIsolation SegmentÖеÄÒ»¸öÊý¾Ýй¶©¶´£¬¸Ã©¶´ÊÇÓÉϵͳÉóºËÈÕÖ¾¼Ç¼ºÍ±©Â¶µÄƾ¾ÝÒýÆðµÄ¡£¸Ã©¶´±»±ê¼ÇΪCVE-2023-20891£¬µÍȨÏÞµÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓøÃ©¶´ÔÚÊÜÓ°ÏìµÄϵͳÖзÃÎÊCloud Foundry API¹ÜÀíԱƾ¾Ý¡£VMware½¨ÒéÊÜCVE-2023-20891Ó°ÏìµÄTAS for VMÓû§¸ü»»CF API¹ÜÀíԱƾ¾Ý£¬ÒÔÈ·±£¹¥»÷ÕßÎÞ·¨Ê¹ÓÃй¶µÄƾ¾Ý½øÐй¥»÷¡£
²Î¿¼Á´½Ó£º
https://www.bleepingcomputer.com/news/security/vmware-fixes-bug-exposing-cf-api-admin-credentials-in-audit-logs3Æ»¹û·¢²¼»Æ½ð³Ç¹ÙÍø¸üÐÂÒÔÐÞ¸´ÄÚºËÖеÄÁãÈÕ©¶´Æ»¹û¹«Ë¾·¢²¼Á˻ƽð³Ç¹ÙÍø¸üУ¬ÒÔÐÞ¸´Õë¶ÔiPhone¡¢MacºÍiPadµÄ¹¥»÷ÖÐÀûÓõÄÁãÈÕ©¶´¡£¸Ã©¶´ÊÇÒ»¸öеÄÄں˩¶´£¬±»±ê¼ÇΪCVE-2023-38606£¬¹¥»÷Õß¿ÉÒÔÔÚÊÜÓ°ÏìµÄÉ豸ÖÐÀûÓÃËüÀ´ÐÞ¸ÄÄÚºË״̬£¬²¢ÇÒ±»ÓÃÓÚ¶ÔÔËÐоÉiOS°æ±¾µÄÉ豸½øÐй¥»÷¡£´ËǰÓлƽð³Ç¹ÙÍøÈËÔ±±íʾ£¬CVE-2023-38606ÊÇÓÃÓÚÔÚiPhoneÉϲ¿ÊðTriangulation¼äµýÈí¼þµÄÁãÈÕ©¶´¹¥»÷Á´ÖеÄÒ»²¿·Ö¡£
²Î¿¼Á´½Ó£º
https://www.bleepingcomputer.com/news/apple/apple-fixes-new-zero-day-used-in-attacks-against-iphones-macs4AtlassianÐÞ¸´Æä²úÆ·ÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´Atlassian·¢²¼»Æ½ð³Ç¹ÙÍø²¹¶¡£¬ÒÔ½â¾öConfluenceÊý¾ÝÖÐÐĺͷþÎñÆ÷ÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Â©¶´ÒÔ¼°BambooÊý¾ÝÖÐÐÄÖеÄÁíÒ»¸ö©¶´¡£ConfluenceÖеÄÁ½¸ö»Æ½ð³Ç¹ÙÍøÂ©¶´·Ö±ð±»±ê¼ÇΪCVE-2023-22508£¨CVSSÆÀ·Ö8.5£©¡¢CVE-2023-22505£¨CVSSÆÀ·Ö8.0£©£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâÁ½¸ö©¶´Ö´ÐÐÈÎÒâ´úÂë¡£ÀûÓôË©¶´²»ÐèÒªÓû§½»»¥£¬µ«¹¥»÷ÕßÐèÒª×÷ΪÓÐЧÓû§½øÐÐÉí·ÝÑéÖ¤¡£BambooÖеĻƽð³Ç¹ÙÍøÂ©¶´±»±ê¼ÇΪCVE-2023-22506£¬ÆäCVSSÆÀ·ÖΪ7.5¡£
²Î¿¼Á´½Ó£º
https://www.securityweek.com/atlassian-patches-remote-code-execution-vulnerabilities-in-confluence-bamboo/?web_view=true