Î÷ÃÅ×Ó²úÆ·¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-08-15

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-11453£¬¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ7.8£¬¹Ù·½Î´ÆÀ¶¨

CVE-2018-11454£¬¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.6£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


SIMATIC STEP 7 and WinCC  (TIA Portal)  V10, V11,V12, V13 all versions
SIMATIC STEP 7 and WinCC (TIA Portal) V14 versions < V14 SP1 Update6

SIMATIC STEP 7 and WinCC (TIA Portal) V15 versions < V15 Update 2


·ì϶¸ÅÊö


Î÷ÃÅ×Ó°ä²¼¹Ù·½¹«¸æ³ÆÆäSIMATIC STEP7ºÍWinCC²úÆ·ÖÐʹÓõÄTIA Portal(Totally Integrated Automation Portal)Èí¼þ´æÔÚÁ½¸ö¸ßΣ·ì϶£¨CVE-2018-11453£¬CVE-2018-11454£©£¬Ó°Ïì¸Ã2¿î²úÆ·µÄ¶à¸ö°æ±¾¡£


CVE-2018-11453£¬ÔÚTIA PortalµÄĬÈÏ×°ÖÃÖУ¬²»ÕýÈ·µÄÎļþȨÏÞ¿ÉÄÜÔÊÐíÓµÓб¾µØÎļþϵͳ½Ó¼ûȨÏ޵Ĺ¥»÷Õß×¢Èë¶ñÒâµÄÎļþ£¬ÒÔ´Ë×èÖ¹TIA PortalÆô¶¯£¨»Ø¾ø·þÎñ£©»òµ¼Ö±¾µØ´úÂëÖ´ÐС£ ¸Ã·ì϶²»±ØÒªÌØÊâȨÏÞ£¬µ«Êܺ¦Õß±ØÒªÔÚ²Ù×÷ºó³¢ÊÔÆô¶¯TIA Portal¡£


CVE-2018-11453£¬ÔÚTIA PortalµÄĬÈÏ×°ÖÃÖУ¬²»ÕýÈ·µÄÎļþȨÏÞ¿ÉÄÜÔÊÐíÓµÓб¾µØÎļþϵͳ½Ó¼ûȨÏ޵Ĺ¥»÷Õ߰ѳֱ¾¸ÃÊÇÓÉÆäËûÓû§ÔÚÉ豸ÉÏÖ´ÐеÄ×ÊÔ´¡£¸Ã·ì϶²»±ØÒªÌØÊâȨÏÞ£¬µ«Êܺ¦Õß±ØÒª½«°Ñ³ÖµÄÎļþ´«Êäµ½É豸£¬×îÖÕÖ´ÐÐÊÇÔÚÖ¸±êÉ豸É϶ø²»ÊÇÔÚPGÉ豸ÉÏ¡£


½¨¸´½¨Òé


SIMATIC STEP 7 and WinCC (TIA Portal) V10¡¢11¡¢12¡¢13£¬Çë²ÉÈ¡ÒÔ϶ã±Ü´ëÊ©£º


1.È·±£½öÓÐÊÚȨµÄÈËÔ±Äܹ»½Ó´¥µ½²Ù×÷ϵͳ


2.ÑéÖ¤GCDÎļþµÄºÏ·¨ÐÔ²¢ÇÒ½ö´¦ÖÃÊÜÐÅÀµÆðÔ´µÄGSDÎļþ


SIMATIC STEP 7 and WinCC (TIA Portal) V14Óû§ÇëÉý¼¶ÖÁV14 SP1 Update 6½øÐзÀ»¤£¬ÏÂÔØµØÖ·£º

https://support.industry.siemens.com/cs/ww/en/view/109747387


SIMATIC STEP 7 and WinCC (TIA Portal) V15Óû§ÇëÉý¼¶ÖÁV15 Update 2»ò¸ü¸ß°æ±¾½øÐзÀ»¤£¬ÏÂÔØµØÖ·£º

https://support.industry.siemens.com/cs/ww/en/view/109755826


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-226-01