Rockwell Automation»Ø¾ø·þÎñ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-12-11

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£º CVE-2018-17924 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.6 £¬¹Ù·½Î´ÆÀ¶¨



Ó°Ïì°æ±¾



MicroLogix 1400 Controllers Series A£¨È«Êý°æ±¾£© £¬Series B 21.003¼°Ö®Ç°°æ±¾ £¬Series C 21.003¼°Ö®Ç°°æ±¾£»1756-ENBT£¨È«Êý°æ±¾£© £¬1756-EWEB Series A£¨È«Êý°æ±¾£© £¬1756-EWEB Series B£¨È«Êý°æ±¾£© £¬1756-EN2F Series A£¨È«Êý°æ±¾£© £¬1756-EN2F Series B£¨È«Êý°æ±¾£© £¬1756-EN2F Series C 10.10¼°Ö®Ç°°æ±¾ £¬1756-EN2T Series A£¨È«Êý°æ±¾£© £¬1756-EN2T Series B£¨È«Êý°æ±¾£© £¬1756-EN2T Series C£¨È«Êý°æ±¾£© £¬1756-EN2T 10.10¼°Ö®Ç°°æ±¾ £¬1756-EN2TR Series A£¨È«Êý°æ±¾£© £¬1756-EN2TR Series B£¨È«Êý°æ±¾£© £¬Series C 10.10¼°Ö®Ç°°æ±¾ £¬1756-EN3TR Series A£¨È«Êý°æ±¾£© £¬1756-EN3TR Series B 10.10¼°Ö®Ç°°æ±¾£¨1756 ControlLogix EtherNet/IPͨѶÄ £¿é£©¡£



·ì϶¸ÅÊö



ÉÏÖÜËÄ £¬ICS-CERT °ä²¼°²È«²¼¸æÏêÊö¸Ã·ì϶Çé¿ö £¬²»ÍâÂÞ¿ËΤ¶û×Ô¶¯»¯¹«Ë¾ÔÚÊýÖÜǰ¾Í֪ͨ¿Í»§ÓйØÇé¿ö £¬¶øÂÞ¿ËΤ¶û°²È«²¼¸æ½öÏò×¢²áÓû§¹«¿ª¡£



ÂÞ¿ËΤ¶û¹«Ë¾ºÍ ICS-CERT ¹«Ë¾°µÊ¾ £¬¸Ã·ì϶ (CVE-2018-1792) µÄ CVSSv3ÆÀ·ÖΪ8.6 £¬Ó°ÏìA¡¢B¡¢CϵÁÐµÄ MicroLogix 1400 ½ÚÔìÆ÷¡£Ëü»¹Ó°Ïì1756 ControlLogix ÒÔÌ«Íø/IP ͨѶÄ £¿éµÄ¶à¸ö°æ±¾ £¬Ô̺¬A¡¢B¡¢CºÍDϵÁС£



ICS-CERT °µÊ¾ÊÜÓ°Ïì²úÆ·ÓÃÓÚÈ«Çò¸÷µØ¶à¸öÐÐÒµ £¬È罻ͨ¡¢¹Ø¼üÔì×÷Òµ¡¢Ê³Æ·ºÍũҵ¡¢ÒÔ¼°Ë®ºÍ·ÏË®ÐÐÒµ¡£



¸Ã·ì϶¿Éµ¼ÖÂÔ¶³Ìδ¾­ÈÏÖ¤µÄ¹¥»÷Õßµ¼ÖÂÊÜÓ°ÏìÉ豸½øÈë DoS ǰÌá¡£ÂÞ¿ËΤ¶û¹«Ë¾Ú¹ÊͳÆ £¬Î´¾­ÈÏÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÄÜÏòÊÜÓ°ÏìÉ豸·¢ËÍ CIP ÏνÓÒªÇó²¢Ôڳɹ¦ÏνӺóÏòÊÜÓ°ÏìÉ豸·¢ËÍÐ嵀 IP ÅäÏàÐÅÏ¢ £¬¼´±ãϵͳÖеĽÚÔìÆ÷±»ÉèÖÃΪ¡°Hard Run¡±Ä£Ê½¡£µ±ÊÜÓ°ÏìÉ豸½ÓÊÜÁËÕâ¸öÐ嵀 IP ÅäÏàÐÅÏ¢ºó £¬É豸ºÍϵͳÆäËü²¿ÃÅÖ®¼ä¾ÍȱʧÁËͨѶ £¬Ô­ÒòÊÇϵÍÂä÷Á¿ÒÀÈ»ÔÚÊÔͼͨ¹ý±»¸²Ð´µÄ IP µØÖ·ºÍÉ豸ͨѶ¡£



ÂÞ¿ËΤ¶û¹«Ë¾ÒÑΪÊÜÓ°Ïì½ÚÔìÆ÷ºÍͨѶÄ £¿é°ä²¼¹Ì¼þ¸üР£¬µ«¶ÔÆäÖкöà½ö°ä²¼»º½â´ëÊ©¡£ÕâЩ´ëÊ©Ô̺¬Ê¹Ó÷À»ðǽ×èÖ¹Ô´×ÔԽȨÆðÔ´µÄÒÔÌ«Íø/IP ÐÅÏ¢¡¢Ê¹ÓÃÓ²¼þ°´¼ü¿ª¹ØÉèÖÃ×èÖ¹¶ÔÉ豸½øÐÐԽȨ¸ü¸Ä²¢½«½ÚÔìϵͳµÄÍøÂç¶³ö×îÓ×»¯¡£



DoS ·ì϶¿É¶Ô¹¤Òµ»·¾³´øÀ´ÑϳÁ·çÏÕ¡£¹¤¿Ø»·¾³¿É±»ÓÃÓÚ¶Ô³ö²úϵͳÔì³ÉÑϳÁÇÖº¦¡£ºÍ»úÃÜÐÔΪ×î³ÁÒªµÄ IT ÍøÂ粻ͨ £¬²Ù×÷¼¼Êõ (OT) ÍøÂçÔËÓªÈËÔ±×î´óµÄÓÇÓôÊÇ¿ÉÓÃÐÔÎÊÌâ¡£



·ì϶ÑéÖ¤



ÔÝÎÞPOC/EXP¡£



½¨¸´½¨Òé



¹Ù·½ÒѾ­°ä²¼ÁËа汾½¨¸´Á˸÷ì϶ £¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¸üР£¬ÐγɶԴ˷ì϶³Ö¾ÃÓÐЧµÄ·À»¤¡£



²Î¿¼Á´½Ó



https://ics-cert.us-cert.gov/advisories/ICSA-18-310-02

https://www.securityfocus.com/bid/106132/solution

https://www.securityweek.com/vulnerability-exposes-rockwell-controllers-dos-attacks