Î÷ÃÅ×ÓSICLOCKÉ豸°²È«·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-07-05·ì϶±àºÅºÍ¼¶±ð
CVE-2018-4852 ¸ßΣ ³§ÉÌ×ÔÆÀ£º7.4 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-4853 ÑϳÁ ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-4854 ÑϳÁ ³§ÉÌ×ÔÆÀ£º9.6 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-4855 ÖÐΣ ³§ÉÌ×ÔÆÀ£º5.3 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-4856 µÍΣ ³§ÉÌ×ÔÆÀ£º2.7 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·£º
SICLOCK TC400
·ì϶¸ÅÊö
½üÈÕ£¬Î÷ÃÅ×Ó·î¸æ¿Í»§£¬Æä²¿ÃÅSICLOCKÖÐÑ빤³§Ê±ÖÓÊܵ½¶à¸ö·ì϶µÄÓ°Ï죬ÆäÖÐÔ̺¬Èý¸ö±»ÆÀΪ¡°ÑϳÁ¡±¼¶´ËÍâ·ì϶¡£
Î÷ÃÅ×ÓSICLOCKÉ豸ÓÃÓÚͬ²½¹¤Òµ¹¤³§µÄ¹¦·ò¡£ÖÐÑ빤³§Ê±ÖÓÈ·±£ÔÚÖ÷¹¦·òÔ´³öÏÖ¹ÊÕÏ»òÃÔʧ½Ó¹ÜʱµÄ²»±äÐÔ¡£
SICLOCKϵͳ×ܹ²Êܵ½Áù¸ö·ì϶µÄÓ°Ïì¡£ÒÑΪ°²È«·ì϶·ÖÅäCVE±êʶ·ûCVE-2018-4851ÖÁCVE-2018-4856¡£
CVE-2018-4851
ÔÊÐí¹¥»÷Õß½Ó¼ûÍøÂ磬ͨ¹ý·¢ËÍÌØÔìÊý¾Ý°ü¶ÔÖ¸±êÉ豸½øÐлؾø·þÎñ£¨DoS£©¹¥»÷²¢¿ÉÄܳÁÐÂÆô¶¯¡£¸ÃÉ豸µÄÖ÷ÌâÖ°ÄÜ¿ÉÄÜ»áÊܵ½Ó°Ïì¡£µ±ÓëGPSÉ豸»òÆäËûNTP·þÎñÆ÷µÄ¹¦·òͬ²½ÊµÏÖʱ£¬¹¦·ò·þÎñÖ°Äܸ´Ô¡£¸Ã·ì϶¿ÉÄÜ»áÓ°ÏìÉ豸µÄ¿ÉÓÃÐÔ£¬²¢¿ÉÄÜÓ°ÏìÉ豸µÄ¹¦·ò·þÎñÖ°ÄܵįëÈ«ÐÔ¡£
CVE-2018-4852
CVE-2018-4853
CVE-2018-4854
CVE-2018-4855
CVE-2018-4856
´Ë·ì϶Ϊ¿ÉÓÉÓµÓÐÖÎÀíÔ±½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÀûÓõĵͼ¶±ð·ì϶£¬ÖÎÀí½Ó¿ÚËø¶¨ºÏ·¨Óû§¡£
Áù¸ö·ì϶ÖеÄËĸöÄܹ»ÔÚûÓÐÈκÎÓû§½»»¥µÄÇé¿öϱ»ÀûÓá£
ÊÜÓ°ÏìµÄ²úÆ·ÊÇרΪÓ×Ð͹¤³§ÉèµÄSICLOCK TC100£¬ºÍSICLOCK TC400¡£ÓÉÓÚÕâÁ½ÖÖ²úÆ·¶¼ÔÚÖ𲽲üõ£¬Òò¶øÎ÷ÃÅ×ÓÉÐδ°ä²¼Èκι̼þ¸üУ¬¶øÊǽ¨Òé¿Í»§ÀûÓÃһϵÁпɽµµÍ¹¥»÷·çÏյıäͨ²½Ö軺ºÍ½â´ëÊ©¡£
½¨¸´½¨Òé
Î÷ÃÅ×ÓÉÐδ°ä²¼Èκι̼þ¸üУ¬¶øÊǽ¨Òé¿Í»§ÀûÓÃһϵÁпɽµµÍ¹¥»÷·çÏյıäͨ²½Ö軺ºÍ½â´ëÊ©¡£»º½â´ëÊ©Ô̺¬×°ÖÃÈßÓ๦·òÔ´ÒÔ¼°¶Ô¹¤³§ÖеĹؼü½ÚÔìÆ÷½øÐкÏÀíÐԲ鳣¬ÒÔ¼°±£»¤¶ÔÊÜÓ°ÏìÉ豸µÄÍøÂç½Ó¼û¡£
²Î¿¼Á´½Ó
https://www.securityweek.com/flaws-expose-siemens-central-plant-clocks-attacks


¾©¹«Íø°²±¸11010802024551ºÅ