Rockwell AutomationÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-09-25

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-14829£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ10£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-14827£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.3£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-14821£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ7.5£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


RSLinx Classic Versions <= 4.00.01


·ì϶¸ÅÊö


Rockwell Automation RSLinx ClassicÊÇÃÀ¹úÂÞ¿ËΤ¶û£¨Rockwell Automation£©¹«Ë¾µÄÒ»Ì×¹¤³§Í¨Ñ¶½â¾ö¹æ»® ¡£¸Ã¹æ»®Ö§³Öͨ¹ýAllen-Bradley¿É±à³Ì½ÚÔìÆ÷½Ó¼ûRockwell SoftwareºÍAllen-BradleyÀûÓ÷¨Ê½µÈ ¡£ Rockwell Automation RSLinx Classic 4.00.01¼°Ö®Ç°°æ±¾ÖдæÔÚ°²È«·ì϶ ¡£

CVE-2018-14829£º¹¥»÷Õß¿Éͨ¹ýÏò44818¶Ë¿Ú·¢ËÍ»ûÐεÄCIPÊý¾Ý°üÀûÓø÷ì϶Ôì³ÉÀûÓ÷¨Ê½ÖÕ³¡ÏìÓ¦£¬Ê¹Æä±ÀÀ£²¢¿ÉÄÜÖ´ÐÐËÁÒâ´úÂë ¡£

CVE-2018-14827£ºÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏò44818¶Ë¿Ú·¢ËÍ»ûÐεÄCIPÊý¾Ý°üÀûÓø÷ì϶Ôì³ÉRSLinx ClassicÀûÓ÷¨Ê½ÖÕ³¡·þÎñ ¡£

CVE-2018-14821£ºÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏò44818¶Ë¿Ú·¢ËÍÌØÔìµÄEthernet/IPÊý¾Ý°üÀûÓø÷ì϶Ôì³ÉÀûÓ÷¨Ê½ÖÕ³¡ÏìÓ¦²¢Ôì³ÉÆä±ÀÀ£ ¡£



·ì϶ÑéÖ¤


ÔÝÎÞPOC\EXP
·ì϶µÀÀí·ÖÎö²Î¿¼£º

https://www.tenable.com/security/research/tra-2018-26


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.rockwellautomation.com


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-263-02
https://www.securityweek.com/rockwell-automation-patches-severe-flaws-communications-software