AVEVAÁ½¸öÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-11-09

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17916£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-17914£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


InduSoft Web Studio versions  <=  1 SP2

InTouch Edge HMI (formerly InTouch Machine Edition) versions  <=  2017 SP2


·ì϶¸ÅÊö


½üÈÕ£¬AVEVA°ä²¼°²È«¹«¸æ³Æ½¨¸´ÁË2¸ö¹¤ÒµÈí¼þÖеĸßΣ·ì϶¡£
AVEVAÓ¢¹úÍÆËã»úÈí¼þÉÌ¡£ÎªÔì´¬ºÍº£Ñ󹤳̡¢Ê¯ÓͺÍÌìÈ»Æø¡¢ÔìÖ½¡¢µçÁ¦¡¢»¯¹¤ºÍÔìÒ©µÈ¹¤ÒµÁìÓòÌṩȫÐÔÃüÖÜÆÚ½â¾ö¹æ»®¼°·þÎñ¡£
CVE-2018-17916ÊÇÒ»¸öÕ»Òç¶Âí½Å£¬¹¥»÷ÕßÄܹ»·¢ËÍÒ»¸öÌØÔìµÄÊý¾Ý°üÀ´´¥·¢¸Ã·ì϶£¬µ¼ÖÂÔÚδÊÚȨµÄÇé¿öÏÂÔ¶³ÌÖ´ÐдúÂë¡£
CVE-2018-17914Ô´ÓÚÒ»¸öÅäÖÃÎļþÖеĿÕÃÜÂëÎÊÌ⣬һ¸öδÊÚȨµÄ¹¥»÷ÕßÄܹ»ÀûÓÃÊÜÓ°ÏìÈí¼þµÄÒ»ÑùȨÏÞÀ´Ô¶³ÌÖ´ÐдúÂë¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP


½¨¸´½¨Òé


AVEVA¹Ù·½ÒѾ­°ä²¼ÁËа汾½¨¸´ÁËÉÏÊö·ì϶£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì¸üнøÐзÀ»¤¡£
а汾ÏÂÔØµØÖ·ÈçÏ£º
InduSoft Web Studio v8.1 SP2
http://download.indusoft.com/81.2.0/IWS81.2.0.zip
InTouch Edge HMI (formerly InTouch Machine Edition)

https://softwaresupportsp.schneider-electric.com/#/producthub/details?id=5223


²Î¿¼Á´½Ó


https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec130.pdf