¶à¿îÎÞÏßͶӰϵͳÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-05-06

Îó²î±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-3929 £¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2019-3930 £¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º9.8 



Ó°Ïì°æ±¾¼°²úÆ·



Crestron AM-100 1.6.0.2
Crestron AM-101 2.7.0.1
Barco wePresent WiPG-1000P 2.3.0.10
Barco wePresent WiPG-1600W before 2.4.1.19 
Extron ShareLink 200/250 2.0.3.4 
Teq AV IT WIPS710 1.1.0.7 
InFocus LiteShow3 1.0.16 
InFocus LiteShow4 2.0.0.7 
Optoma WPS-Pro 1.0.0.5 
Blackbox HD WPS 1.0.0.5

SHARP PN-L703WA 1.4.2.3



Îó²î¸ÅÊö



ÎÞÏßÑÝʾϵͳÔÊÐíÓû§Í¨¹ý×°ÖõÄÓ¦ÓóÌÐò»òWebä¯ÀÀÆ÷½«Æä×°±¸ÅþÁ¬µ½ÏµÍ³ £¬£¬£¬£¬ £¬£¬£¬´Ó¶øÖ±½Ó´ÓÆäÌõ¼Ç±¾µçÄÔÏÔʾÆäÄÚÈÝ¡£¡£ ¡£¡£¡£¡£ ¡£


TenableµÄÑо¿Ö°Ô±Åû¶ÁËÁ½¸öÎó²îCVE-2019-3929ºÍCVE-2019-3930 £¬£¬£¬£¬ £¬£¬£¬Ó°ÏìÁËһϵÁÐÑÝʾƽ̨ϵͳ£º°üÀ¨Crestron £¬£¬£¬£¬ £¬£¬£¬Barco wePresent £¬£¬£¬£¬ £¬£¬£¬Extron ShareLink £¬£¬£¬£¬ £¬£¬£¬InFocus LiteShow £¬£¬£¬£¬ £¬£¬£¬TEQ AV IT WIPS710 £¬£¬£¬£¬ £¬£¬£¬SHARP PN-L703WA £¬£¬£¬£¬ £¬£¬£¬ Optoma WPS-Pro £¬£¬£¬£¬ £¬£¬£¬Blackbox HD WPS¡£¡£ ¡£¡£¡£¡£ ¡£ÕâÊÇÓÉÓÚËùÓа˸öÆ·ÅÆ¹²ÏíÏàͬµÄ»ù´¡´úÂë¡£¡£ ¡£¡£¡£¡£ ¡£


CVE-2019-3929

δ¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÏÂÁî×¢ÈëÎó²î £¬£¬£¬£¬ £¬£¬£¬¿ÉÒÔʹԶ³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòHTTP¶Ëµãfile_transfer.cgi·¢ËÍÈ«ÐÄÉè¼ÆµÄÇëÇóÀ´Ö´ÐвÙ×÷ϵͳÏÂÁî¡£¡£ ¡£¡£¡£¡£ ¡£


CVE-2019-3930

δ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¿ÍÕ»»º³åÇøÒç³öÎó²î £¬£¬£¬£¬ £¬£¬£¬Ëü±£´æÓÚÃûΪPARSERtoCHARµÄ×°±¸µÄ¹¦Ð§ÖÐ £¬£¬£¬£¬ £¬£¬£¬Í¨¹ýHTTP·¢ËͲ»»á¶ÔCGI¾ç±¾¾ÙÐÐÉí·ÝÑéÖ¤¡£¡£ ¡£¡£¡£¡£ ¡£ÕâÒâζ×ÅÔ¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý¶Ôreturn.cgi¶ËµãµÄÈ«ÐÄÉè¼ÆÇëÇóÀ´ÀÄÓÃÎó²îÀ´Ö´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£ ¡£



Îó²îÑéÖ¤



EXP£ºhttps://www.exploit-db.com/exploits/46786¡£¡£ ¡£¡£¡£¡£ ¡£



ÐÞ¸´½¨Òé



CrestronÐû²¼ÁËÎó²îÐÞ¸´³ÌÐò£º

https://www.crestron.com/en-US/Security/Security_Advisories¡£¡£ ¡£¡£¡£¡£ ¡£


Barco¸üй̼þ£º
https://www.barco.com/en/support/software/R33050103?majorVersion=2&minorVersion=3&patchVersion=2&buildVersion=20

https://www.barco.com/en/support/software/R33050104?majorVersion=2&minorVersion=4&patchVersion=1&buildVersion=19


Extron¸üй̼þ£º

https://www.extron.com/download/software.aspx?filehandle=sharelink200&material=44&type=archive



²Î¿¼Á´½Ó
https://threatpost.com/bugs-wireless-presentation-systems/144318/