Î÷ÃÅ×ÓSICLOCKÉ豸°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-07-05

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-4851  ÑϳÁ ³§ÉÌ×ÔÆÀ£º9.1  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-4852  ¸ßΣ ³§ÉÌ×ÔÆÀ£º7.4  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-4853  ÑϳÁ ³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-4854  ÑϳÁ ³§ÉÌ×ÔÆÀ£º9.6  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-4855  ÖÐΣ ³§ÉÌ×ÔÆÀ£º5.3  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-4856  µÍΣ ³§ÉÌ×ÔÆÀ£º2.7  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°ÏìµÄ²úÆ·£º


SICLOCK TC100

SICLOCK TC400


·ì϶¸ÅÊö


½üÈÕ £¬£¬£¬£¬£¬£¬£¬Î÷ÃÅ×Ó·î¸æ¿Í»§ £¬£¬£¬£¬£¬£¬£¬Æä²¿ÃÅSICLOCKÖÐÑ빤³§Ê±ÖÓÊܵ½¶à¸ö·ì϶µÄÓ°Ïì £¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Èý¸ö±»ÆÀΪ¡°ÑϳÁ¡±¼¶´ËÍâ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£


Î÷ÃÅ×ÓSICLOCKÉ豸ÓÃÓÚͬ²½¹¤Òµ¹¤³§µÄ¹¦·ò¡£¡£¡£¡£¡£¡£¡£¡£ÖÐÑ빤³§Ê±ÖÓÈ·±£ÔÚÖ÷¹¦·òÔ´³öÏÖ¹ÊÕÏ»òÃÔʧ½Ó¹ÜʱµÄ²»±äÐÔ¡£¡£¡£¡£¡£¡£¡£¡£


SICLOCKϵͳ×ܹ²Êܵ½Áù¸ö·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£ÒÑΪ°²È«·ì϶·ÖÅäCVE±êʶ·ûCVE-2018-4851ÖÁCVE-2018-4856¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2018-4851


ÔÊÐí¹¥»÷Õß½Ó¼ûÍøÂç £¬£¬£¬£¬£¬£¬£¬Í¨¹ý·¢ËÍÌØÔìÊý¾Ý°ü¶ÔÖ¸±êÉ豸½øÐлؾø·þÎñ£¨DoS£©¹¥»÷²¢¿ÉÄܳÁÐÂÆô¶¯¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÉ豸µÄÖ÷ÌâÖ°ÄÜ¿ÉÄÜ»áÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£µ±ÓëGPSÉ豸»òÆäËûNTP·þÎñÆ÷µÄ¹¦·òͬ²½ÊµÏÖʱ £¬£¬£¬£¬£¬£¬£¬¹¦·ò·þÎñÖ°Äܸ´Ô­¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄÜ»áÓ°ÏìÉ豸µÄ¿ÉÓÃÐÔ £¬£¬£¬£¬£¬£¬£¬²¢¿ÉÄÜÓ°ÏìÉ豸µÄ¹¦·ò·þÎñÖ°ÄܵįëÈ«ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2018-4852


´Ë·ì϶¿ÉÄÜÔÊÐíÍøÂç¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤ £¬£¬£¬£¬£¬£¬£¬µ«ÀûÓ÷ì϶±ØÒª¹¥»÷Õß»ñÈ¡ÓйØÖ¸±êÉ豸µÄÌØ¶¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2018-4853


¹¥»÷ÕßÀûÓôËÑϳÁ·ì϶Äܹ»Í¨¹ý½Ó¼ûUDP¶Ë¿Ú69µÄÀ´Åú¸ÄÖ¸±êSICLOCKÉ豸ÉϵĹ̼þ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2018-4854


ÁíÒ»¸öÑϳÁ·ì϶ͨ¹ýÒ»ÑùµÄ¶Ë¿ÚUDP 69 £¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÅú¸Ä´æ´¢ÔÚÉ豸ÉϵÄÖÎÀí¿Í»§¶Ë²¢Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2018-4855


´Ë·ì϶ΪÖеȼ¶´ËÍâ·ì϶ £¬£¬£¬£¬£¬£¬£¬ÔÊÐíÖÐÑëÈË£¨MitM£©¹¥»÷ÕßÀ¹½Ø´æ´¢ÔÚ¿Í»§¶ËÅäÖÃÎļþÖеÄδ¼ÓÃÜÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2018-4856


´Ë·ì϶Ϊ¿ÉÓÉÓµÓÐÖÎÀíÔ±½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÀûÓõĵͼ¶±ð·ì϶ £¬£¬£¬£¬£¬£¬£¬ÖÎÀí½Ó¿ÚËø¶¨ºÏ·¨Óû§¡£¡£¡£¡£¡£¡£¡£¡£


Áù¸ö·ì϶ÖеÄËĸöÄܹ»ÔÚûÓÐÈκÎÓû§½»»¥µÄÇé¿öϱ»ÀûÓᣡ£¡£¡£¡£¡£¡£¡£


ÊÜÓ°ÏìµÄ²úÆ·ÊÇרΪÓ×Ð͹¤³§ÉèµÄSICLOCK TC100 £¬£¬£¬£¬£¬£¬£¬ºÍSICLOCK TC400¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÁ½ÖÖ²úÆ·¶¼ÔÚÖ𲽲üõ £¬£¬£¬£¬£¬£¬£¬Òò¶øÎ÷ÃÅ×ÓÉÐδ°ä²¼Èκι̼þ¸üР£¬£¬£¬£¬£¬£¬£¬¶øÊǽ¨Òé¿Í»§ÀûÓÃһϵÁпɽµµÍ¹¥»÷·çÏյıäͨ²½Ö軺ºÍ½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Î÷ÃÅ×ÓÉÐδ°ä²¼Èκι̼þ¸üР£¬£¬£¬£¬£¬£¬£¬¶øÊǽ¨Òé¿Í»§ÀûÓÃһϵÁпɽµµÍ¹¥»÷·çÏյıäͨ²½Ö軺ºÍ½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£»£» £»£»£»£»º½â´ëÊ©Ô̺¬×°ÖÃÈßÓ๦·òÔ´ÒÔ¼°¶Ô¹¤³§ÖеĹؼü½ÚÔìÆ÷½øÐкÏÀíÐԲ鳭 £¬£¬£¬£¬£¬£¬£¬ÒÔ¼°±£»£» £»£»£»£»¤¶ÔÊÜÓ°ÏìÉ豸µÄÍøÂç½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.securityweek.com/flaws-expose-siemens-central-plant-clocks-attacks


https://cert-portal.siemens.com/productcert/pdf/ssa-197012.pdf