ºáºÓµç»úSTARDOM½ÚÔìÆ÷ÑϳÁ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-06-05·ì϶±àºÅ
CVE-2018-10592
·ì϶¼¶±ð
ÑϳÁ ICS-CERTÆÀ·Ö£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
¸Ã·ì϶ӰÏìÈÕ±¾ºáºÓµç»úµÄSTARDOM¶à¿î½ÚÔìÆ÷£¬£¬£¬£¬£¬£¬¹Ù·½°ä²¼µÄÊÜÓ°Ïì½ÚÔìÆ÷ÓÐFCJ (R4.02 and prior)¡¢FCN-100 (R4.02 and prior)¡¢FCN-RTU (R4.02 and prior)¡¢FCN-500 (R4.02 and prior)¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚSTARDOM½ÚÔìÆ÷ÀûÓü«¶È¿í·º£¬£¬£¬£¬£¬£¬Éæ¼°ÄÜÔ´¡¢¹Ø¼üÔì×÷¡¢Ê³Æ·ºÍũҵµÈÐÐÒµ£¬£¬£¬£¬£¬£¬¿ÉÔì³ÉÑϳÁ·çÏÕ£¬£¬£¬£¬£¬£¬ÓйØÓû§¼°³§ÉÌÓ¦ÒýÆð¸ß¶ÈÆ÷³Á¡£¡£¡£¡£¡£¡£¡£
·ìϼûèÊö
2018Äê5ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬ÈÕ±¾ºáºÓµç»ú°ä²¼5Ô·ݰ²È«²¼¸æ£¬£¬£¬£¬£¬£¬²¼¸æÖн¨¸´ÁËÒ»¸ö¸ßΣ·ì϶¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓø÷ì϶Äܹ»¶ÔSTARDOM½ÚÔìÆ÷ÌáÒéÔ¶³Ì¹¥»÷£¬£¬£¬£¬£¬£¬²¢Ö´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬£¬»ñÈ¡½ÚÔìÆ÷ËùÓÐȨÏÞ¡£¡£¡£¡£¡£¡£¡£
2018Äê5ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬ICS-CERTÕýʽ°ä²¼¸Ã·ì϶°²È«²¼¸æ£¬£¬£¬£¬£¬£¬²¢ÎªÆäÊÚÓè±àºÅCVE-2018-10592£¬£¬£¬£¬£¬£¬È϶¨·ì϶µÈ¼¶ÎªÑϳÁ£¬£¬£¬£¬£¬£¬CVSS V3ÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£
CVE-2018-10592·ì϶ÊǶ«·½µçÆø-8827Ì«Ñô¼¯Íʤ¿ØÐÅÏ¢°²È«½áºÏ³¢ÊÔÊÒ£¨VDLab£©ÔÚ2017Äê8Ô·¢ÏÖ²¢Éϱ¨¹ú¶ÈÓйØÖ÷¹Ü»ú¹¹¡¢CVEºÍÓÐ¹ØÆóÒµ¡£¡£¡£¡£¡£¡£¡£ÈÕ±¾ºáºÓµç»úÈ·Èϸ÷ì϶ºó£¬£¬£¬£¬£¬£¬Ñ¸ËÙ·¢Õ¹½¨¸´¹¤×÷£¬£¬£¬£¬£¬£¬²¢ÊµÊ±ÏòVDLabÌṩÁ˽¨²¹´ëÊ©¡£¡£¡£¡£¡£¡£¡£VDLabÔÚ»ñµÃ²¹¶¡ºóµÄµÚÒ»¹¦·ò£¬£¬£¬£¬£¬£¬ÐͬÓÐ¹ØÆóÒµ½øÐÐÁËÄÚ²¿²âÊÔ£¬£¬£¬£¬£¬£¬²¢¶ÔÓйؽÚÔìϵͳ½øÐÐÁËÏÖ³¡Éý¼¶£¬£¬£¬£¬£¬£¬ÒÔ±£ÏÕµçÁ¦»ù´¡ÉèÊ©ÍøÂ簲ȫ¡£¡£¡£¡£¡£¡£¡£
ʱ¸ô°ëÄê¶à£¬£¬£¬£¬£¬£¬³§É̽«¸Ã·ì϶½øÐй«¿ª£¬£¬£¬£¬£¬£¬ÔÚ´ËÌáÐÑʹÓøÃϵÁнÚÔìÆ÷µÄÓû§£¬£¬£¬£¬£¬£¬ÉÐδʵÏÖ½¨²¹¹¤×÷µÄ£¬£¬£¬£¬£¬£¬Ð辡¿ì¶Ôϵͳ½øÐÐÉý¼¶¡£¡£¡£¡£¡£¡£¡£
½â¾ö´ëÊ©
ºáºÓµç»ú¹Ù·½ÒÑÓÚ5ÔÂ21ÈÕ¶Ô±íÕýʽ°ä²¼Õë¶Ô¸Ã·ì϶µÄ²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬¿É¸üйٷ½×îеIJ¹¶¡¡£¡£¡£¡£¡£¡£¡£Óû§Ò²¿É×·ÇóºáºÓµç»úµÄ¼¼ÊõÖ§³ÖÈËÔ±¶ÔÉ豸½øÐÐÉý¼¶¸üС£¡£¡£¡£¡£¡£¡£
²Î¿¼×ÊÁÏ
https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03
https://mp.weixin.qq.com/s/Wxr8Mk6WxTVBe6iHMgjN5w


¾©¹«Íø°²±¸11010802024551ºÅ