Schneider IGSS Ô¶³Ì·ì϶·ÖÎö

°ä²¼¹¦·ò 2022-04-15

Ò»¡¢Ã½½é


½üÆÚ£¬£¬£¬ £¬£¬£¬ £¬£¬8827Ì«Ñô¼¯ÍÅADLabÔÚ¹¤Òµ½ÚÔìϵͳ·ì϶¼à²âÖз¢ÏÖSchneider°ä²¼Á˽»»¥Ê½Í¼ÐÎSCADAϵͳ£¨Interactive Graphical SCADA System£¬£¬£¬ £¬£¬£¬ £¬£¬¼ò³ÆIGSS£©µÄ¸ßΣ·ì϶²¼¸æºÍ²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬ £¬£¬£¬ £¬£¬Ô̺¬Óлº³åÇøÒç³öºÍĿ¼´©Ô½µÈ£¬£¬£¬ £¬£¬£¬ £¬£¬NVDµÄÆÀ·Ö¸ß´ï9.8¡£¡£¡£¡£¡£¡£¡£¡£ADLab×êÑÐÔ±µÚÒ»¹¦·ò¶ÔÆäÖеĸßΣ·ì϶½øÐÐÁ˾ßÌå·ÖÎöºÍÏÖ³¢ÊÔÖ¤£¬£¬£¬ £¬£¬£¬ £¬£¬Í¬Ê±»¹·¢ÏÖÁËÒ»¸öеĸßΣ·ì϶²¢Ð­Öú³§É̽øÐÐÁ˽¨¸´¡£¡£¡£¡£¡£¡£¡£¡£


¶þ¡¢·ì϶¸ù»ùÐÅÏ¢



ƾ¾ÝSchneiderµÄ·ì϶²¼¸æ£¬£¬£¬ £¬£¬£¬ £¬£¬ÕâЩ·ì϶µÄ¸ù»ùÐÅÏ¢ÈçÏ£º



ÊÜÓ°ÏìµÄ²úÆ·£ºV15.0.0.22020 and prior

´æÔÚ·ì϶

  • CVE-2022-24312£¬£¬£¬ £¬£¬£¬ £¬£¬Ä¿Â¼´©Ô½
  • CVE-2022-24311£¬£¬£¬ £¬£¬£¬ £¬£¬Ä¿Â¼´©Ô½
  • CVE-2022-24310£¬£¬£¬ £¬£¬£¬ £¬£¬»º³åÇøÒç³ö


ÊÜÓ°ÏìµÄ²úÆ·£ºV15.0.0.22073 and prior

´æÔÚ·ì϶


  • CVE-2022-24324£¬£¬£¬ £¬£¬£¬ £¬£¬»º³åÇøÒç³ö



´¥·¢·½Ê½£ºÍøÂç
CVSS v3ÆÀ·Ö:  9.8

Èý¡¢·ì϶·ÖÎöÓëÑéÖ¤


3.1 CVE-2022-24311(24312)·ÖÎö


ÕâÁ½¸ö·ì϶´æÔÚÓÚIGSS V15.0.0.22020 and prior°æ±¾£¬£¬£¬ £¬£¬£¬ £¬£¬Æä·ìϼûèÊöΪ£º¡°´æÔÚ¶ÔÊÜÏÞ¶ÈĿ¼õè¾¼ûûµÄ²»µ±ÏÞ¶È£¬£¬£¬ £¬£¬£¬ £¬£¬¿Éµ¼ÖÂͨ¹ýÔÚÎļþĩβÔö³¤»òÔÚÊý¾Ý·þÎñÆ÷¸ßµÍÎÄÖд´½¨ÐÂÎļþÀ´Åú¸ÄÏÖÓÐÎļþ£¬£¬£¬ £¬£¬£¬ £¬£¬µ±¹¥»÷Õßͨ¹ýÍøÂç·¢ËÍÌØ¶¨Êý¾Ýʱ£¬£¬£¬ £¬£¬£¬ £¬£¬¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐÓ×±¡£¡£¡£¡£¡£¡£¡£¡£


ͨ¹ý¶ÈÎö£¬£¬£¬ £¬£¬£¬ £¬£¬ÎÒÃÇ·¢ÏÖÕâÁ½¸ö·ì϶λÓÚsub_49FF20º¯Êý£¬£¬£¬ £¬£¬£¬ £¬£¬¸Ãº¯ÊýµÄα´úÂëÈçÏ£º


ͼƬ1.png


¸ú½øsub_4A0C50º¯Êý£¬£¬£¬ £¬£¬£¬ £¬£¬Î±´úÂëÈçÏÂËùʾ£º


ͼƬ2.png



Äܹ»¿´³ö£¬£¬£¬ £¬£¬£¬ £¬£¬¸Ãº¯ÊýÄÚ²¿½øÐÐÁËһϵÁÐÎļþ²Ù×÷£¬£¬£¬ £¬£¬£¬ £¬£¬µ«¶Ô´«Èë¸Ãº¯ÊýµÄ²ÎÊýûÓÐ×öÓÐЧµÄ°²È«²é³­£¬£¬£¬ £¬£¬£¬ £¬£¬Òò¶øÄܹ»±»²Ù¿ØÀ´ÏòSCADA·þÎñÆ÷дÈëËÁÒâÎļþ¡£¡£¡£¡£¡£¡£¡£¡£


ͬÀí£¬£¬£¬ £¬£¬£¬ £¬£¬¸ú½øsub_4A0C50º¯Êý£¬£¬£¬ £¬£¬£¬ £¬£¬Î±´úÂëÈçÏÂËùʾ£º


ͼƬ3.png



Äܹ»¿´³ö£¬£¬£¬ £¬£¬£¬ £¬£¬¸Ãº¯ÊýµÄÄÚ²¿Í¬ÑùҲûÓжԴ«ÈëµÄ²ÎÊý½øÐа²È«²é³­£¬£¬£¬ £¬£¬£¬ £¬£¬Òò¶øÒ²Äܹ»±»²Ù¿ØÀ´ÏòSCADA·þÎñÆ÷дÈëËÁÒâÎļþ¡£¡£¡£¡£¡£¡£¡£¡£


ƾ¾ÝÉÏÊö·ÖÎöÎÒÃǽøÐÐÁËÑéÖ¤£¬£¬£¬ £¬£¬£¬ £¬£¬³É¹¦ÏòSCADA·þÎñÆ÷дÈëËÁÒâÄÚÈݵÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£


ͼƬ4.png


¶ÔÓÚÉÏÊöÁ½¸ö·ì϶£¬£¬£¬ £¬£¬£¬ £¬£¬Schneider¹Ù·½°ä²¼Á˲¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬ £¬£¬£¬ £¬£¬Æä½¨¸´·½Ê½ÈçÏ£º


ͼƬ5.png


¾ßÌåÀ´½²£¬£¬£¬ £¬£¬£¬ £¬£¬¡°Prepend file¡±ºÍ¡°Append file¡±·ÖÖ§ÔÚ½øÈë¾ßÌåÖ°Äܺ¯ÊýǰŲÓÃÁ˶î±íµÄsub_4A16F0º¯Êý¡£¡£¡£¡£¡£¡£¡£¡£¸Ãº¯Êý´«ÈëÁ˲ÎÊý v6+72£¬£¬£¬ £¬£¬£¬ £¬£¬´Ë²ÎÊý¶ÔÓ¦±»²Ù×÷ÎļþµÄÎļþõè¾¼ûû¡£¡£¡£¡£¡£¡£¡£¡£¸ú½ø¸Ãº¯Êý£¬£¬£¬ £¬£¬£¬ £¬£¬Æäα´úÂëÈçÏ£º


ͼƬ6.png


¸Ãº¯Êý¶ÔÎļþõè¾¼ûû½øÐÐÁËÏÞ¶È£º(1)ÏÞ¶È(v6+72)³¤¶È£¬£¬£¬ £¬£¬£¬ £¬£¬´óÓ×ÒªÂú×ã<=0x100£»£»£»£»£»(2)ÏÞ¶È(v6+72)ÄÚÈÝ£¬£¬£¬ £¬£¬£¬ £¬£¬²»ÄÜÓÐĿ¼´©Ô½µÄÌØµã·û¡£¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÕâÖÖÏÞ¶È£¬£¬£¬ £¬£¬£¬ £¬£¬²¹¶¡Ô¤·ÀÁ˶ñÒâÊý¾Ýµ¼ÖµÄÌø×ªÄ¿Â¼£¬£¬£¬ £¬£¬£¬ £¬£¬°ÑÎļþ²Ù×÷ÏÞ¶ÈÔÚµ±Ç°Ä¿Â¼Ï¡£¡£¡£¡£¡£¡£¡£¡£


3.2 CVE-2022-24310·ÖÎö


¸Ã·ì϶´æÔÚÓÚIGSS V15.0.0.22020 and prior°æ±¾£¬£¬£¬ £¬£¬£¬ £¬£¬·ì϶µÄÃèÊöΪ£º¡°´æÔÚÕûÊýÒç³ö£¬£¬£¬ £¬£¬£¬ £¬£¬µ±¹¥»÷Õß·¢ËͶàÌõ¾«ÐijﱸµÄÐÂÎÅʱ£¬£¬£¬ £¬£¬£¬ £¬£¬¸Ã·ì϶¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö£¬£¬£¬ £¬£¬£¬ £¬£¬µ¼Ö»ؾø·þÎñ²¢¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×±¡£¡£¡£¡£¡£¡£¡£¡£

ͨ¹ý¶ÈÎö£¬£¬£¬ £¬£¬£¬ £¬£¬ÎÒÃÇ·¢ÏÖÕâ¸ö·ì϶´æÔÚÓÚsub_49FA30º¯Êý£¬£¬£¬ £¬£¬£¬ £¬£¬¸Ãº¯ÊýµÄα´úÂëÈçÏ£º


ͼƬ7.png


´ÓÉÏͼÄܹ»¿´³ö£¬£¬£¬ £¬£¬£¬ £¬£¬¸Ãº¯ÊýµÄÖØÒªÂß¼­ÊÇ£ºÊ×ÏÈ£¬£¬£¬ £¬£¬£¬ £¬£¬Í¨¹ýrealloc¸ø*(this+48)µÄ¶ÑÔö³¤*(a1+0xBA)ÊýÖµµÄ´óÓ×£¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»¶øºó£¬£¬£¬ £¬£¬£¬ £¬£¬Ê¹ÓÃmemcpyÏò(*(v5 +52)+*(v5 + 48))¸³Öµ*(a2+0xBA)³¤¶ÈµÄ(a2+190)»º³åÇøÄÚÈÝ£¬£¬£¬ £¬£¬£¬ £¬£¬¼´Ìî³äreallocзÖÅä³öµÄÄÚ´æ¿Õ¼ä¡£¡£¡£¡£¡£¡£¡£¡£


¾­¹ý¶ÈÎö£¬£¬£¬ £¬£¬£¬ £¬£¬ÎÒÃÇ·¢ÏÖ£ºÔÚ*(a2+ 0xBA)+*(this + 52)µÄ¼Ó·¨²Ù×÷ÖУ¬£¬£¬ £¬£¬£¬ £¬£¬Á½¸ö²Ù×÷Êý¾ùΪÎÞ·ûºÅÀàÐÍ£¬£¬£¬ £¬£¬£¬ £¬£¬ÇÒ*(a2+0xBA)¿É¿Ø¡£¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬ £¬£¬£¬ £¬£¬Í¨¹ý½ÚÔì*(a2+0xBA)µÄÖµ£¬£¬£¬ £¬£¬£¬ £¬£¬¿ÉʹµÃ*(a2 + 0xBA)+*(this + 52)²úÉúÕûÊýÉÏÒ磬£¬£¬ £¬£¬£¬ £¬£¬´Ó¶øµ¼ÖÂreallocÐÂÉêÇëÄÚ´æµÄÈÝÁ¿Ó×ÓÚºóÐømemcpyµÄ²ÎÊý*(a2+0xBA)£¬£¬£¬ £¬£¬£¬ £¬£¬ºóÐøÖ´ÐÐmemcpyÄڴ濽±´²Ù×÷ʱ¾Í»á´¥·¢¶ÑÒç³ö¡£¡£¡£¡£¡£¡£¡£¡£


ƾ¾ÝÉÏÊö·ÖÎöÎÒÃǽøÐÐÁËÑéÖ¤£¬£¬£¬ £¬£¬£¬ £¬£¬³É¹¦´¥·¢ÁËSCADA·þÎñÆ÷µÄ¶Ñ·ÛËé¡£¡£¡£¡£¡£¡£¡£¡£


ͼƬ8.png

¶ÔÓڸ÷ì϶£¬£¬£¬ £¬£¬£¬ £¬£¬Schneider¹Ù·½°ä²¼Á˲¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬ £¬£¬£¬ £¬£¬Æä½¨¸´·½Ê½ÈçÏ£º


ͼƬ9.png


¾ßÌåÀ´½²£¬£¬£¬ £¬£¬£¬ £¬£¬ÔÚ½øÐÐrealloc²Ù×÷Ö´ÐÐǰ£¬£¬£¬ £¬£¬£¬ £¬£¬ÏÈÅжÏ*(a2+0xBA)µÄÖµÊÇ·ñÔÚ[0,0xF42]µÄÇø¼äÁìÓòÄÚ£¬£¬£¬ £¬£¬£¬ £¬£¬´Ó¶øÔ¤·ÀÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¡£¡£


3.3 CVE-2022-24324·ÖÎö


ÔÚ¶ÔIGSS V15.0.0.22073 and priorµÄ²¹¶¡·ÖÎöÖУ¬£¬£¬ £¬£¬£¬ £¬£¬ADLab×êÑÐÔ±»¹·¢ÏÖÁËÒ»¸öÐµĻº´æÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶Äܹ»Ô¶³ÌÎÞǰÌá´¥·¢£¬£¬£¬ £¬£¬£¬ £¬£¬ADLabʵʱ»ã±¨Á˳§É̲¢Ð­Öú³§É̽øÐÐÁ˽¨¸´£¬£¬£¬ £¬£¬£¬ £¬£¬³§É̶Ը÷ì϶µÄCVSS3ÆÀ·ÖΪÑϳÁ¡£¡£¡£¡£¡£¡£¡£¡£


ͼƬ11.png


SchneiderÒѾ­°ä²¼ÁËв¹¶¡À´½¨¸´Õâ¸ö¸ßΣ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Óйز¹¶¡ºÍ¸ü¶àµÄÄÚÈÝ¿ÉÔÚ¹Ù·½ÌṩµÄ²¼¸æÖвéÎÊ£º

https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-102-01_IGSS_Security_Notification.pdf&p_Doc_Ref=SEVD-2022-102-01


ËÄ¡¢½¨¸´½¨Òé


¾­¹ýADLab×êÑÐÔ±µÄ·ÖÎöºÍÑéÖ¤£¬£¬£¬ £¬£¬£¬ £¬£¬ÉÏÊö¸ßΣ·ì϶¶¼Äܹ»Í¨¹ýÍøÂç½øÐÐÎÞǰÌáµÄÔ¶³Ì´¥·¢£¬£¬£¬ £¬£¬£¬ £¬£¬ÓµÓкܴóµÄ·çÏÕÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°¹Ù·½ÒѾ­°ä²¼Á˲¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬ £¬£¬£¬ £¬£¬Ç¿ÁÒ½¨ÒéʹÓÃIGGSµÄ¹¤ÒµÓû§Á¢¼´Éý¼¶µ½×îа汾£º15.0.0.22074¡£¡£¡£¡£¡£¡£¡£¡£


Õë¶Ô¹¤Òµ½ÚÔìϵͳ£¬£¬£¬ £¬£¬£¬ £¬£¬CISAÌṩÁËÈçϵÄͨÓý¨Ò飺

  • ¾¡Á¿Ï÷¼õÔÚ¹«ÍøÂ¶³ö¹¤¿ØÉ豸»òÕßϵͳ£»£»£»£»£»
  • ½«½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬£¬£¬ £¬£¬£¬ £¬£¬²¢ºÍ°ì¹«ÍøÂç¸ôÀ룻£»£»£»£»
  • µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬£¬£¬ £¬£¬£¬ £¬£¬Ñ¡È¡ÀàËÆVPNµÄ°²È«½Ó¼û·½Ê½¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó£º

[1] SEVD-2022-102-01, IGSS Data Server (V15.0.0.22073 and prior)

https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-102-01 
[2] SEVD-2022-039-01, IGSS Data Server (V15.0.0.22020 and prior)
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-01