Rockwell Automation»Ø¾ø·þÎñ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-12-11·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£º CVE-2018-17924£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.6£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
MicroLogix 1400 Controllers Series A£¨È«Êý°æ±¾£©£¬Series B 21.003¼°Ö®Ç°°æ±¾£¬Series C 21.003¼°Ö®Ç°°æ±¾£»1756-ENBT£¨È«Êý°æ±¾£©£¬1756-EWEB Series A£¨È«Êý°æ±¾£©£¬1756-EWEB Series B£¨È«Êý°æ±¾£©£¬1756-EN2F Series A£¨È«Êý°æ±¾£©£¬1756-EN2F Series B£¨È«Êý°æ±¾£©£¬1756-EN2F Series C 10.10¼°Ö®Ç°°æ±¾£¬1756-EN2T Series A£¨È«Êý°æ±¾£©£¬1756-EN2T Series B£¨È«Êý°æ±¾£©£¬1756-EN2T Series C£¨È«Êý°æ±¾£©£¬1756-EN2T 10.10¼°Ö®Ç°°æ±¾£¬1756-EN2TR Series A£¨È«Êý°æ±¾£©£¬1756-EN2TR Series B£¨È«Êý°æ±¾£©£¬Series C 10.10¼°Ö®Ç°°æ±¾£¬1756-EN3TR Series A£¨È«Êý°æ±¾£©£¬1756-EN3TR Series B 10.10¼°Ö®Ç°°æ±¾£¨1756 ControlLogix EtherNet/IPͨѶģ¿é£©¡£
·ì϶¸ÅÊö
ÉÏÖÜËÄ£¬ICS-CERT °ä²¼°²È«²¼¸æÏêÊö¸Ã·ì϶Çé¿ö£¬²»ÍâÂÞ¿ËΤ¶û×Ô¶¯»¯¹«Ë¾ÔÚÊýÖÜǰ¾Í֪ͨ¿Í»§ÓйØÇé¿ö£¬¶øÂÞ¿ËΤ¶û°²È«²¼¸æ½öÏò×¢²áÓû§¹«¿ª¡£
ÂÞ¿ËΤ¶û¹«Ë¾ºÍ ICS-CERT ¹«Ë¾°µÊ¾£¬¸Ã·ì϶ (CVE-2018-1792) µÄ CVSSv3ÆÀ·ÖΪ8.6£¬Ó°ÏìA¡¢B¡¢CϵÁÐµÄ MicroLogix 1400 ½ÚÔìÆ÷¡£Ëü»¹Ó°Ïì1756 ControlLogix ÒÔÌ«Íø/IP ͨѶģ¿éµÄ¶à¸ö°æ±¾£¬Ô̺¬A¡¢B¡¢CºÍDϵÁС£
ICS-CERT °µÊ¾ÊÜÓ°Ïì²úÆ·ÓÃÓÚÈ«Çò¸÷µØ¶à¸öÐÐÒµ£¬È罻ͨ¡¢¹Ø¼üÔì×÷Òµ¡¢Ê³Æ·ºÍũҵ¡¢ÒÔ¼°Ë®ºÍ·ÏË®ÐÐÒµ¡£
¸Ã·ì϶¿Éµ¼ÖÂÔ¶³Ìδ¾ÈÏÖ¤µÄ¹¥»÷Õßµ¼ÖÂÊÜÓ°ÏìÉ豸½øÈë DoS ǰÌá¡£ÂÞ¿ËΤ¶û¹«Ë¾Ú¹Êͳƣ¬Î´¾ÈÏÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÄÜÏòÊÜÓ°ÏìÉ豸·¢ËÍ CIP ÏνÓÒªÇó²¢Ôڳɹ¦ÏνӺóÏòÊÜÓ°ÏìÉ豸·¢ËÍÐ嵀 IP ÅäÏàÐÅÏ¢£¬¼´±ãϵͳÖеĽÚÔìÆ÷±»ÉèÖÃΪ¡°Hard Run¡±Ä£Ê½¡£µ±ÊÜÓ°ÏìÉ豸½ÓÊÜÁËÕâ¸öÐ嵀 IP ÅäÏàÐÅÏ¢ºó£¬É豸ºÍϵͳÆäËü²¿ÃÅÖ®¼ä¾ÍȱʧÁËͨѶ£¬ÔÒòÊÇϵÍÂä÷Á¿ÒÀÈ»ÔÚÊÔͼͨ¹ý±»¸²Ð´µÄ IP µØÖ·ºÍÉ豸ͨѶ¡£
ÂÞ¿ËΤ¶û¹«Ë¾ÒÑΪÊÜÓ°Ïì½ÚÔìÆ÷ºÍͨѶģ¿é°ä²¼¹Ì¼þ¸üУ¬µ«¶ÔÆäÖкöà½ö°ä²¼»º½â´ëÊ©¡£ÕâЩ´ëÊ©Ô̺¬Ê¹Ó÷À»ðǽ×èÖ¹Ô´×ÔԽȨÆðÔ´µÄÒÔÌ«Íø/IP ÐÅÏ¢¡¢Ê¹ÓÃÓ²¼þ°´¼ü¿ª¹ØÉèÖÃ×èÖ¹¶ÔÉ豸½øÐÐԽȨ¸ü¸Ä²¢½«½ÚÔìϵͳµÄÍøÂç¶³ö×îÓ×»¯¡£
DoS ·ì϶¿É¶Ô¹¤Òµ»·¾³´øÀ´ÑϳÁ·çÏÕ¡£¹¤¿Ø»·¾³¿É±»ÓÃÓÚ¶Ô³ö²úϵͳÔì³ÉÑϳÁÇÖº¦¡£ºÍ»úÃÜÐÔΪ×î³ÁÒªµÄ IT ÍøÂ粻ͨ£¬²Ù×÷¼¼Êõ (OT) ÍøÂçÔËÓªÈËÔ±×î´óµÄÓÇÓôÊÇ¿ÉÓÃÐÔÎÊÌâ¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
¹Ù·½ÒѾ°ä²¼ÁËа汾½¨¸´Á˸÷ì϶£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¸üУ¬ÐγɶԴ˷ì϶³Ö¾ÃÓÐЧµÄ·À»¤¡£
²Î¿¼Á´½Ó
https://ics-cert.us-cert.gov/advisories/ICSA-18-310-02
https://www.securityfocus.com/bid/106132/solution
https://www.securityweek.com/vulnerability-exposes-rockwell-controllers-dos-attacks


¾©¹«Íø°²±¸11010802024551ºÅ