Î÷ÃÅ×ÓSPPA-T3000¶à¸ö·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2019-12-16·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-18283£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18315£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18316£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18314£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18313£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
É¢²¼Ê½½ÚÔìϵͳSPPA-T3000
·ì϶¸ÅÊö
Î÷ÃÅ×Ó¹¤ÒµÉ豸Öб»ÆØ´æÔÚ¶à¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ ÊÜÓ°Ïì²úÆ·ÊÇÉ¢²¼Ê½½ÚÔìϵͳSPPA-T3000£¬£¬£¬£¬£¬£¬£¬£¬±é²¼ÓÚÃÀ¹ú¡¢µÂ¹ú¡¢¶íÂÞ˹ºÍÆäËü¹ú¶ÈµÄÖØÒª·¢µç³§ÖУ¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚкÍг¼à¶½·¢µç¡£¡£¡£¡£¡£
ÀûÓÃÆäÖеÄһЩ·ì϶¿ÉÔÚÀûÓ÷¨Ê½·þÎñÆ÷ÉÏÔËÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø½ÚÔì²Ù×÷²¢Ö´ÐзÛËé¡£¡£¡£¡£¡£ÕâÑù×ö¿ÉÄÜ×èÖ¹×°ÖÃÒ×Êܹ¥»÷ϵͳµÄ·¢µç³§·¢µç²¢Òý·¢¹ÊÕÏ¡£¡£¡£¡£¡£
ÕâЩ·ì϶´æÔÚÓÚ¸ÃÆ½Ì¨µÄÁ½¸ö¾ßÌå×é¼þÖУºÀûÓ÷¨Ê½·þÎñÆ÷»ººÍ½â·þÎñÆ÷¡£¡£¡£¡£¡£
ÆäÖÐ×îÑϳÁµÄ·ì϶¿É´¥·¢ÀûÓ÷¨Ê½ÉϵÄÔ¶³Ì´úÂëÖ´ÐÐÎÊÌâ¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬£¬Ò»¸öÑϳÁµÄ²»ÊÜÐÅÀµµÄÊý¾Ý·´ÐòÁл¯·ì϶ CVE-2019-18283¿Éµ¼Ö¹¥»÷Õßͨ¹ýÏòÆäÖÐÒ»¸öº¯Êý·¢ËÍÌØÊâ»ú¹Ø¶ÔÏóµÄ²½Öè»ñȡԶ³Ì´úÂëÖ´ÐÐȨÏÞ¡£¡£¡£¡£¡£
Áí±íÁ½¸öÑϳÁ·ì϶CVE-2019-18315 ºÍ CVE-2019-18316 ¿Éµ¼ÖÂÕ¼ÓÐÀûÓ÷¨Ê½·þÎñÆ÷ÍøÂç½Ó¼ûȨÏ޵Ĺ¥»÷Õßͨ¹ý¶È±ðÏò 8888/TCP ºÍ1099/TCP ¶Ë¿Ú·¢ËÍÌØÊâ»ú¹ØÊý¾Ý°üµÄ·½Ê½»ñȡԶ³Ì´úÂë½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£
Áí±íÒ»¸öÑϳÁµÄÈÏÖ¤²»µ±È±µã CVE-2019-18314 ¿Éµ¼ÖÂÕâÀ๥»÷Õßͨ¹ý Remote Method Invocation (RMI) ·¢ËÍÌØÊâ»ú¹ØµÄ¶ÔÏó»ñȡԶ³Ì´úÂëÖ´ÐÐȨÏÞ¡£¡£¡£¡£¡£
MS-3000 »º½â·þÎñÆ÷ÖдæÔÚÆäËü¶à¸ö·ì϶¡£¡£¡£¡£¡£ÆäÖÐÁ½¸ö¿Éµ¼ÖÂÔ¶³Ì¶ÁÈ¡ºÍдÈëËÁÒâÎļþ¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄܶÁÈ¡ /etc/shadow£¬£¬£¬£¬£¬£¬£¬£¬¶øºóÕßÔ̺¬¿É±»ÓÃÓÚ±©Á¦ÆÆ½âÓû§ÃÜÂëµÄ¹þÏ£¡£¡£¡£¡£¡£Áí±í»¹·¢ÏÖ¶à¸ö¶ÑÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÓÚÕë¶Ô»º½â·þÎñÆ÷·¢Æð»Ø¾ø·þÎñ¹¥»÷µÈ¡£¡£¡£¡£¡£
ÆäÖÐÒ»¸öÖµÍ×ÌùÐĵķì϶ÊÇCVE-2019-18313£¬£¬£¬£¬£¬£¬£¬£¬ËüÊÇÒ»¸öÑϳÁµÄ²»ÊÜÏÞÉÏ´«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÎÞÐèÈÏÖ¤¼´¿É¶³ö±¾ÎªÖÎÀíÔ±Éè¼ÆµÄÔ¶³Ì·¨Ê½Å²Óà (RPCs)¡£¡£¡£¡£¡£Ëü¿Éµ¼ÖÂÓµÓÐ MS-3000 ·þÎñÆ÷×é¼þÍøÂç½Ó¼ûȨÏ޵Ĺ¥»÷Õßͨ¹ýÏòÆäÖÐÒ»ÖÖ RPC ·þÎñ·¢ËÍÌØÊâ»ú¹ØµÄ¶ÔÏ󡣡£¡£¡£¡£
Î÷ÃÅ×Ó¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÆäÖÐÈκÎÒ»ÖÖ·ì϶¾ùÐè»ñÈ¡¶Ô Application »ò Automation Highway£¨ÏνÓ×é¼þµÄÍøÂ磩µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£ÈôÊÇÒÀÕÕÎ÷ÃÅ×ӵIJÙ×÷Ö¸ÄÏÉèÖû·¾³µÄ»°²»»á¶³öÕâÐ©ÍøÂç¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Î÷ÃÅ×Ó°µÊ¾ÔÚÍÆ³ö¸üУ¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Ö¸³öµçÁ¦³§Ó¦¸ÃÏ޶ȶÔʹÓà SPPA-T3000 ·À»ðǽµÄ Application Highway µÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Ó¦¸ÃûÓÐÔÚ Application »òAutomation highwaysÉÏÇÅ½Ó±í²¿ÍøÂç¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://threatpost.com/critical-remote-code-execution-global-power-plants/151087/


¾©¹«Íø°²±¸11010802024551ºÅ