¸»Ê¿µç»úËÅ·þϵͳºÍÇý¶¯0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-09-30

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-14794£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-14788£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ5.3£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Alpha5 Smart Loader Versions 3.7¼°Ö®Ç°°æ±¾


·ì϶¸ÅÊö


ICS-CERT ºÍÇ÷Ïò¿Æ¼¼ ZDI ÍŶӱ¾ÖÜÅû¶³Æ£¬ÈÕ±¾¸»Ê¿µç»ú¹«Ë¾µÄËÅ·þϵͳºÍÇý¶¯ÖдæÔÚ¶à¸ö佨¸´µÄ·ì϶¡£×êÑÐÔ± Michael Flanders ÔÚ¸»Ê¿µç»úµÄ Alpha 5 ÖÇÄÜËÅ·þϵͳLoader Èí¼þÖз¢ÏÖÁËÁ½¸ö·ì϶¡£


ÊÜÓ°Ïì²úÆ·ÖØÒªÓÃÓÚÅ·ÖÞºÍÑÇÖÞµÄóÒ×ÉèÊ©ºÍ¹Ø¼üÔì×÷ÐÐÒµÖУ¬×÷ÓÃÊÇͨ¹ýµ÷Õû£¬Ê¹Çý¶¯¶àÖÖ»úеµÄµç¶¯»ú¿ÉÄÜÕýÈ·ÔËÐС£


ÆäÖÐÒ»¸ö·ì϶ÊÇÑϳÁµÄ¶Ñ»º³åÇøÒç³ö (CVE-2018-14794) ·ì϶£¬Äܵ¼ÖÂÔ¶³Ì¹¥»÷ÕßÓÕÆ­Ö¸±ê´ò¿ªÒ»¸ö³ö¸ñ»ú¹ØµÄ C5V Îļþ£¬´Ó¶øÖ´ÐÐËÁÒâ´úÂë¡£ZDI ÔÚ°²È«²¼¸æÖÐÖ¸³ö£¬¡°Õâ¸öÎÊÌâ²úÉúµÄÔ­ÒòÊÇÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´Ôìµ½Ò»¸ö³¤¶È¹Ì¶¨ÇÒ»ùÓڶѵĻº³å֮ǰ£¬²»×ã¶Ô¸ÃÊý¾ÝµÄÕýÈ·ÑéÖ¤¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâ¸ö·ì϶ÔÚÖÎÀíÔ±¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡±

Ó°ÏìËÅ·þϵͳµÄµÚ¶þ¸ö·ì϶ÊÇÒ»¸öÖÐΣµÄ»º³åÇøÒç¶Âí½Å£¬¿Éµ¼ÖÂÔÚ´¦ÖÃÌØÊâ»ú¹ØµÄ A5P Îļþʱ£¬Ãô¸ÐÐÅÏ¢Ôâ¶³ö¡£µ±½áºÏÆäËü·ì϶ʹÓÃʱ£¬¹¥»÷Õß¿ÉÄÜÒÔÖÎÀíԱȨÏÞÀûÓøà bug Ö´ÐÐËÁÒâ´úÂë¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC\EXP


½¨¸´½¨Òé


ZDI ´ÍÓ븻ʿµç»ú120ÌìµÄ¹¦·ò½¨¸´¸Ã·ì϶¡£¸»Ê¿µç»ú±¾Öܹ²°ä²¼5ƪ°²È«²¼¸æ£¬Ä¿Ç°ÓÉÓÚÉÐÎ´ÍÆ³ö²¹¶¡£¬Òò¶øËüÃǾùÊôÓÚ 0day ·ì϶״̬¡£


¸»Ê¿µç»ú¹«Ë¾°µÊ¾ÔÚÍÆ³ö²¹¶¡¹æ»®¡£ÔÚ´Ë֮ǰ£¬¸Ã¹«Ë¾½¨ÒéÓû§Ô¤·ÀÔÚÊÜÓ°ÏìÀûÓ÷¨Ê½Öв»ÊÜÐÅÀµµÄÎļþ¡£


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-270-02
https://www.securityweek.com/no-patches-critical-flaws-fuji-electric-servo-system-drives