Rockwell Automation | ¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-270x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
Rockwell Automation EDS Subsystem |
CVE-2020-12034 |
SI |
¸ßΣ |
ÊÇ |
FactoryTalk Linx software:6.00,6.10,6.11 RSLinx Classic <= 4.11.00 RSNetWorx software <= 28.00.00 Studio 5000 Logix Designer software <= 32 |
|
CVE-2020-12038 |
B0 |
ÖÐΣ |
·ñ |
0x01 ·ì϶ÏêÇé
ÂÞ¿ËΤ¶û×Ô¶¯»¯ÓÐÏÞ¹«Ë¾ÊÇÈ«Çò×î´óµÄÖÂÁ¦ÓÚ¹¤Òµ×Ô¶¯»¯ÓëÐÅÏ¢µÄ¹«Ë¾Ö®Ò»£¬£¬£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÔ®ÊÖ¿Í»§ÌáÓâÔ½²úÁ¦£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÊÀ½ç¿É³ÖÐø·¢Õ¹¡£¡£¡£¡£¡£¡£¡£¡£
½üÈÕ£¬£¬£¬£¬£¬£¬£¬¹¤ÒµÍøÂ簲ȫ¹«Ë¾ClarotyµÄ×êÑÐÈËÔ±·¢ÏÖÁËÂÞ¿ËΤ¶û²úƷʹÓõĵç×ÓÊý¾Ý±í£¨EDS£©×ÓϵͳÖеÄÁ½¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬·ì϶ÓëEDS×Óϵͳ½âÎöEDSÎļþÄÚÈݵķ½Ê½Óйء£¡£¡£¡£¡£¡£¡£¡£EDSÎļþÔ̺¬É豸µÄÅäÖÃÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÍøÂçÖÎÀí¹¤¾ß½«ÆäÓÃÓÚ±êʶºÍµ÷ÊÔ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»´´½¨Ò»¸ö¶ñÒâµÄEDSÎļþ£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãÔÚ±»ÂÞ¿ËΤ¶ûµÄÈí¼þ½âÎöºó£¬£¬£¬£¬£¬£¬£¬½«WindowsÅú´¦ÖÃÎļþдÈëËÁÒâõè¾¶£¬£¬£¬£¬£¬£¬£¬Ô̺¬Æô¶¯Ä¿Â¼£¬£¬£¬£¬£¬£¬£¬ÕâÄܹ»µ¼Ö³ÁÐÂÆô¶¯ºóÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-12034ÊÇRockwell Automation EDS Subsystem SQL×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚEDS×ÓϵͳûÓжÔÓû§ÊäÈë½øÐгä·ÖµÄÑéÖ¤£¬£¬£¬£¬£¬£¬£¬Ê¹¹¥»÷ÕßÄܹ»´´½¨¶ñÒâµÄEDSÎļþ½øÐÐSQL×¢È룬£¬£¬£¬£¬£¬£¬µ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-12038ÊÇRockwell Automation EDS Subsystem »º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»´´½¨¶ñÒâµÄEDSÎļþʹEDSParser COM¶ÔÏó±ÀÀ££¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬²Î¿¼Á´½Ó£º
https://www.rockwellautomation.com/
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1125928£¨±ØÒª×¢²á£©
ǶÈëʽ²úÆ·µÄ·ì϶»º½â´ëÊ©£º
? ÔÚ·À»ðǽ/UTMÉ豸Éϼල»òÏÞ¶ÈTCP 2222¡¢7153¶Ë¿ÚºÍUDP 44818¶Ë¿Ú¡£¡£¡£¡£¡£¡£¡£¡£
ͨ³£»º½â´ëÊ©£º
? ¶¨Î»·À»ðǽ·À»¤µÄ½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀ룻£»£»£»£»£»
? Ô¶³Ì½Ó¼ûʱ£¬£¬£¬£¬£¬£¬£¬½¨ÒéʹÓÃÐ鹹רÓÃÍøÂ磨VPN£©£¬£¬£¬£¬£¬£¬£¬²¢È·ÈÏVPN¿ÉÄÜ´æÔڵķì϶£¬£¬£¬£¬£¬£¬£¬Ð轫VPN¸üе½×îа汾¡£¡£¡£¡£¡£¡£¡£¡£
0x03 ÓйØÐÂÎÅ
https://www.securityweek.com/hackers-can-target-rockwell-industrial-software-malicious-eds-files
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-140-01
0x05 ¹¦·òÏß
2020-05-27 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ