去评论
dz插件网

知道创宇云监测—ScanV 更新:蓝凌OA(EKP)未授权远程代码执行等5个漏洞可检测

IT618发布
2023/08/05 14:35:56


鏈鏇存柊ScanV婕忔礊妫娴嬫彃浠剁壒寰佸簱鑷崇増鏈細20220817

鏂板婕忔礊妫娴嬫彃浠5涓

鏂板婕忔礊妫娴嬫彃浠讹細

1. Teleport 鍫″瀿鏈轰换鎰忔枃浠惰鍙栨紡娲烇紝鎻掍欢鏇存柊鏃堕棿锛2022骞08鏈17鏃

2. 钃濆噷OA锛圗KP锛夋湭鎺堟潈杩滅▼浠g爜鎵ц锛屾彃浠舵洿鏂版椂闂达細2022骞08鏈17鏃

3. 閫氳揪OA V11.8杩滅▼浠g爜鎵ц婕忔礊锛屾彃浠舵洿鏂版椂闂达細2022骞08鏈17鏃

4. Teleport 鍫″瀿鏈轰换鎰忕敤鎴风櫥褰曟紡娲烇紝鎻掍欢鏇存柊鏃堕棿锛2022骞08鏈17鏃

5. 鏌愬崗鍚屽姙鍏郴缁熶换鎰忔枃浠朵笂浼犳紡娲烇紝鎻掍欢鏇存柊鏃堕棿锛2022骞08鏈11鏃

婕忔礊鐩稿叧淇℃伅

1. Teleport 鍫″瀿鏈轰换鎰忔枃浠惰鍙栨紡娲

婕忔礊鎻掍欢鏇存柊鏃堕棿:

2022骞08鏈17鏃

婕忔礊绛夌骇:

楂樺嵄

婕忔礊鏉ユ簮锛

https://github.com/tp4a/teleport/issues/290

婕忔礊褰卞搷:

Teleport鏄竴娆剧畝鍗曟槗鐢ㄧ殑寮婧愬牎鍨掓満绯荤粺锛屽叿鏈夊皬宸с佹槗鐢ㄧ殑鐗圭偣锛屾敮鎸 RDP/SSH/SFTP/Telnet 鍗忚鐨勮繙绋嬭繛鎺ュ拰瀹¤绠$悊銆傜敱浜庣洿鎺ュ皢鐢ㄦ埛杈撳叆鍙傛暟鎷兼帴鍒版枃浠惰矾寰勶紝骞惰鍙栬繑鍥炵粰鐢ㄦ埛锛屽鑷翠换鎰忔枃浠惰鍙栨紡娲烇紝鏈粡鎺堟潈鐨勬敾鍑昏呭彲浠ュ埄鐢ㄨ婕忔礊璇诲彇鏈嶅姟鍣ㄤ笂鏁忔劅鏂囦欢銆

褰卞搷鑼冨洿锛

鏍规嵁ZoomEye缃戠粶绌洪棿鎼滅储寮曟搸鍏抽敭瀛梩itle:"鐧诲綍::TELEPORT"瀵规綔鍦ㄥ彲鑳界洰鏍囪繘琛屾悳绱紝鍏卞緱鍒256 鏉P鍘嗗彶璁板綍銆備富瑕佸垎甯冨湪涓浗銆佺編鍥界瓑鍥藉銆

锛圸oomEye鎼滅储閾炬帴锛歨ttps://www.zoomeye.org/searchResult?q=title%3A%22%E7%99%BB%E5%BD%95%3A%3ATELEPORT%22锛



鍏ㄧ悆鍒嗗竷:



寤鸿瑙e喅鏂规:

瀹樻柟宸插彂甯冭ˉ涓佷慨澶嶄簡璇ユ紡娲烇紝璇峰強鏃跺畨瑁呰ˉ涓侊紝琛ヤ竵涓嬭浇閾炬帴锛歨ttps://tp4a.com/download銆

鍙傝冮摼鎺:

https://github.com/tp4a/teleport/issues/290

2. 钃濆噷OA锛圗KP锛夋湭鎺堟潈杩滅▼浠g爜鎵ц

婕忔礊鎻掍欢鏇存柊鏃堕棿:

2022骞08鏈17鏃

婕忔礊绛夌骇:

楂樺嵄

婕忔礊褰卞搷:

钃濆噷杞欢鍏ㄧО娣卞湷甯傝摑鍑岃蒋浠惰偂浠芥湁闄愬叕鍙革紝浜2001骞村湪娣卞湷绉戞妧鍥垚绔嬨傝摑鍑屾槸鍥藉唴鐭ュ悕鐨勫ぇ骞冲彴OA鏈嶅姟鍟嗗拰鍥藉唴棰嗗厛鐨勭煡璇嗙鐞嗚В鍐虫柟妗堟彁渚涘晢锛屾槸涓撲笟浠庝簨缁勭粐鐨勭煡璇嗗寲鍜ㄨ銆佽蒋浠剁爺鍙戙佸疄鏂姐佹妧鏈湇鍔$殑鍥藉绾ч珮鏂版妧鏈紒涓氥傛繁鍦冲競钃濆噷杞欢鑲′唤鏈夐檺鍏徃鏁板瓧OA(EKP)瀛樺湪浠g爜鎵ц婕忔礊銆傛敾鍑昏呭彲鍒╃敤璇ユ紡娲為犳垚浠g爜鎵ц銆

褰卞搷鑼冨洿锛

鏍规嵁ZoomEye缃戠粶绌洪棿鎼滅储寮曟搸鍏抽敭瀛梐pp:"钃濆噷鏁板瓧OA"瀵规綔鍦ㄥ彲鑳界洰鏍囪繘琛屾悳绱紝鍏卞緱鍒4,596 鏉P鍘嗗彶璁板綍銆備富瑕佸垎甯冨湪涓浗銆佺編鍥界瓑鍥藉銆

锛圸oomEye鎼滅储閾炬帴锛歨ttps://www.zoomeye.org/searchResult?q=app%3A%22%E8%93%9D%E5%87%8C%E6%95%B0%E5%AD%97OA%22锛



鍏ㄧ悆鍒嗗竷锛



寤鸿瑙e喅鏂规:

瀹樻柟浠ュ彂甯冩渶鏂扮増鏈互淇璇ユ紡娲烇紝璇疯嚜琛岃闂紒涓氬畼缃戣幏鍙栨渶鏂扮増鏈細https://www.landray.com.cn/锛屾垨浣跨敤绗笁鏂归槻鎶ゅ钩鍙拌繘琛岄槻鎶わ紝濡傦細鍒涘畤鐩撅紙https://defense.yunaq.com/cyd/锛

3. 閫氳揪OA V11.8杩滅▼浠g爜鎵ц婕忔礊

婕忔礊鎻掍欢鏇存柊鏃堕棿:

2022骞08鏈17鏃

婕忔礊绛夌骇:

楂樺嵄

婕忔礊褰卞搷:

閫氳揪 OA 鏄敱鍖椾含閫氳揪淇$绉戞妧鏈夐檺鍏徃鑷富鐮斿彂鐨勫崗鍚屽姙鍏嚜鍔ㄥ寲杞欢锛屼负鍚勮涓氫笉鍚岃妯$殑浼楀鐢ㄦ埛鎻愪緵淇℃伅鍖栫鐞嗚兘鍔涳紝鍖呮嫭娴佺▼瀹℃壒銆佽鏀垮姙鍏佹棩甯镐簨鍔°佹暟鎹粺璁″垎鏋愩佸嵆鏃堕氳銆佺Щ鍔ㄥ姙鍏瓑锛屽府鍔╁箍澶х敤鎴烽檷浣庢矡閫氬拰绠$悊鎴愭湰锛屾彁鍗囩敓浜у拰鍐崇瓥鏁堢巼銆傜敱浜庣己涔忚繃婊ゅ瓨鍦ㄨ繙绋嬩唬鐮佹墽琛屾紡娲烇紝璇ユ紡娲炲厑璁告湭缁忔巿鏉冪殑鏀诲嚮鑰呰繙绋嬫墽琛屼换鎰忎唬鐮侊紝鑾峰彇鏈嶅姟鍣ㄦ潈闄愩

褰卞搷鑼冨洿锛

鏍规嵁ZoomEye缃戠粶绌洪棿鎼滅储寮曟搸鍏抽敭瀛梐pp:"Tongda OA"瀵规綔鍦ㄥ彲鑳界洰鏍囪繘琛屾悳绱紝鍏卞緱鍒72,132 鏉P鍘嗗彶璁板綍銆備富瑕佸垎甯冨湪涓浗銆佺編鍥界瓑鍥藉銆

锛圸oomEye鎼滅储閾炬帴锛歨ttps://www.zoomeye.org/searchResult/report?q=app%3A%22Tongda%20OA%22锛



鍏ㄧ悆鍒嗗竷锛



寤鸿瑙e喅鏂规:

鑱旂郴瀹樻柟鑾峰彇瑙e喅鏂规锛屼娇鐢ㄥ垱瀹囩浘鐨勭敤鎴烽粯璁ゅ嵆鍙槻寰¤婕忔礊銆

4. Teleport 鍫″瀿鏈轰换鎰忕敤鎴风櫥褰曟紡娲

婕忔礊鎻掍欢鏇存柊鏃堕棿:

2022骞08鏈17鏃

婕忔礊绛夌骇:

楂樺嵄

婕忔礊鏉ユ簮锛

https://github.com/tp4a/teleport/issues/289

婕忔礊褰卞搷:

Teleport鏄竴娆剧畝鍗曟槗鐢ㄧ殑寮婧愬牎鍨掓満绯荤粺锛屽叿鏈夊皬宸с佹槗鐢ㄧ殑鐗圭偣锛屾敮鎸 RDP/SSH/SFTP/Telnet 鍗忚鐨勮繙绋嬭繛鎺ュ拰瀹¤绠$悊銆傜櫥褰曟帴鍙e瓨鍦ㄩ昏緫婕忔礊瀵艰嚧鍙互缁曡繃鐧诲綍楠岃瘉锛屼娇鐢ㄤ换鎰忚处鍙风櫥褰曠郴缁燂紝鏀诲嚮鑰呭彲浠ュ埄鐢ㄨ婕忔礊鐧诲綍鍫″瀿鏈哄悗鍙般

褰卞搷鑼冨洿锛

鏍规嵁ZoomEye缃戠粶绌洪棿鎼滅储寮曟搸鍏抽敭瀛梩itle:"鐧诲綍::TELEPORT"瀵规綔鍦ㄥ彲鑳界洰鏍囪繘琛屾悳绱紝鍏卞緱鍒256 鏉P鍘嗗彶璁板綍銆備富瑕佸垎甯冨湪涓浗銆佺編鍥界瓑鍥藉銆

锛圸oomEye鎼滅储閾炬帴锛歨ttps://www.zoomeye.org/searchResult?q=title%3A%22%E7%99%BB%E5%BD%95%3A%3ATELEPORT%22锛



鍏ㄧ悆鍒嗗竷锛



寤鸿瑙e喅鏂规:

瀹樻柟宸插彂甯冭ˉ涓佷慨澶嶄簡璇ユ紡娲烇紝璇峰強鏃跺畨瑁呰ˉ涓侊紝琛ヤ竵涓嬭浇閾炬帴锛歨ttps://tp4a.com/download

鍙傝冮摼鎺:

https://github.com/tp4a/teleport/issues/289

5. 鏌愬崗鍚屽姙鍏郴缁熶换鎰忔枃浠朵笂浼犳紡娲

婕忔礊鎻掍欢鏇存柊鏃堕棿:

2022骞08鏈11鏃

婕忔礊绛夌骇:

楂樺嵄

婕忔礊褰卞搷:

鏌愬崗鍚屽姙鍏郴缁熷瓨鍦ㄤ换鎰忔枃浠朵笂浼犳紡娲烇紝鏈粡鎺堟潈鐨勬敾鍑昏呭彲浠ュ埄鐢ㄨ婕忔礊涓婁紶鎭舵剰鏂囦欢锛岃繙绋嬫墽琛屼换鎰忎唬鐮侊紝鑾峰彇鏈嶅姟鍣ㄦ潈闄愩

寤鸿瑙e喅鏂规:

瀹樻柟鏆傛湭淇璇ユ紡娲烇紝鍙仈绯诲巶鍟嗚幏鍙栬В鍐虫柟妗堬紝浣跨敤鍒涘畤鐩剧殑鐢ㄦ埛榛樿鍙嫤鎴婕忔礊銆

浠ヤ笂鎻掍欢鏇存柊銆佷紭鍖栨潵婧愪簬鍒涘畤瀹夊叏鏅鸿剳澶ф暟鎹垎鏋愬钩鍙帮紝瀵硅繎鏈熸紡娲炲埄鐢ㄦ儏鍐靛強鍒╃敤鏂瑰紡鍒嗘瀽鍚庡仛鍑虹殑浼樺寲鏇存柊锛屽悓鏃舵敮鎸乄ebSOC绯诲垪銆



濡傛湁鐩稿叧涓氬姟闇姹

璇锋壂鐮佽仈绯讳笓瀹跺挩璇

馃憞 鐐瑰嚮闃呰鍘熸枃

寮鍚 ScanV 澶氱淮搴︾珛浣撶洃娴