Ê©Ä͵¹¤ÒµÈí¼þÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-04

·ì϶±àºÅ


CVE-2018-7784
CVE-2018-7785


·ì϶¼¶±ð


ÑϳÁ  ³§ÉÌ×ÔÆÀ£º10   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÑϳÁ  ³§ÉÌ×ÔÆÀ£º10   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£ºU.motion server 1.3.4¼°ÒÔÏ¡£


·ìϼûèÊö


Ê©Ä͵Â2018Äê5ÔÂ31ÈÕ°ä²¼°²È«²¼¸æÍ¨Öª¿Í»§£¬ÆìϲúÆ·U.motion builder´æÔÚÑϳÁµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶ӰÏ죬·ì϶±àºÅΪCVE-2018-7784¡¢CVE-2018-7785£¬Á½Ã¶·ì϶µÄÆÀ·Ö¾ùΪ10·Ö£¨Âú·Ö£©¡£½ØÖÁ´Ë¿Ì£¬Ê©Ä͵¹ٷ½ÒÑÍÆ³ö½¨¸´²¹¶¡¡£


U.motion ÊÇÒ»¿î×Ô¶¯»¯¹¹½¨½â¾ö¹æ»®£¬ÓÃÓÚÈ«ÇòóÒ×ÉèÊ©¡¢¹Ø¼üÔì×÷ÒµºÍÄÜÔ´ÐÐÒµ¡£U.motion Builder ¹¤¾ßÄÜÈÃÓû§Îª×Ô¼ºµÄ U.motion É豸´´½¨ÏîÄ¿¡£


·ì϶ϸ½Ú


1.CVE-2018-7784£º


·¨Ê½¶ÔÌá½»µÄÊý¾Ý¹ýÂ˲»ÑÏ£¬µ¼ÖÂÊäÈëµÄÊý¾Ý±»µ±×÷´úÂëÖ´ÐС£Í¨¹ýÕâ¸ö·ì϶£¬¹¥»÷ÕßÄܹ»ÔÚ´æÔÚ·ì϶µÄ»úеÉÏÔ¶³ÌÖ´ÐÐËÁÒâ´úÂ롢й¶ÐÅÏ¢»òÕßÒý·¢·¨Ê½±¨´í¡£


2.CVE-2018-7785£º


Ô¶³ÌºÅÁî×¢Èë·ì϶£¬¹¥»÷ÕßÄܹ»ÔÚÎÞÐèÈÏÖ¤µÄÇé¿öÏ£¬ÓÚ´æÔÚ·ì϶µÄÖ÷»úÖ´ÐÐËÁÒâÔ¶³ÌºÅÁî¡£

 

½â¾ö´ëÊ©


½¨ÒéÓйØÓû§¾¡¿ìµ½Ê©Ä͵¹ٷ½ÍøÕ¾ÏÂÔØ²¹¶¡½¨²¹·ì϶¡£


ÏÂÔØµØÖ·£º


https://www.schneider-electric.com/en/download/document/Umotion_Server_update/

 

²Î¿¼×ÊÁÏ


https://www.schneider-electric.com/en/download/document/Umotion_Server_update/