ABB PLCÑϳÁ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-12-19·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-18995£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18997£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 7.1£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
GATE-E1 (EOL 2013)
GATE-E2 (EOL OCT 2018)
·ì϶¸ÅÊö
×êÑÐÈËÔ±ÔÚÈðÊ¿¹¤Òµ¼¼Êõ¹«Ë¾ ABB ³ö²úµÄÄ³Ð©Íø¹Ø²úÆ·Öз¢ÏÖÁËÑϳÁ·ì϶£¬µ«ÓÉÓÚ²úÆ·µÄÐÔÃüÖÜÆÚʵÏÖ£¬Òò¶ø³§É̽«²»»áÍÆ³ö²¹¶¡¡£
Applied Risk¹«Ë¾±¾Öܰ䲼°²È«²¼¸æ°µÊ¾£¬ABB ³ö²úµÄ Pluto Íø¹Ø²úÆ·ÖдæÔÚÁ½¸öÑϳÁ·ì϶¡£ÊÜÓ°ÏìµÄÍø¹ØÊÇ GATE-E1 ºÍ GATE-E2£¬ËüÃǿɵ¼Ö ABB ¹«Ë¾µÄ¿É±à³Ì°²È«½ÚÔìÆ÷£¨°²È« PLCs£©ºÍÆäËü½ÚÔìϵͳͨѶ¡£
×êÑÐÈËÔ±Ö¸³ö£¬ÕâЩÉ豸µÄÖÎÀíÔ± telnet ºÍ web ½Ó¿ÚÉ϶ÌȱÈÏÖ¤»úÔ죬¿Éµ¼Ö¹¥»÷ÕßµÈÏлñÈ¡ÊÚȨȨÏÞ¡£¸Ãȱµã±» Applied Risk ¹«Ë¾ºÍ ABB ¹«Ë¾¾ùÆÀΪ¡°ÑϳÁ¡±µÈ¼¶£¬¿É±»ÓÃÓÚÅú¸ÄÉ豸ÅäÖò¢Í¨¹ý³ÖÐø³ÁÖòúÆ·µÄ²½ÖèÒý·¢»Ø¾ø·þÎñǰÌá¡£
ABB ¹«Ë¾Ú¹Êͳƣ¬¡°¸Ã·ì϶ÊÇÒò²úÆ·Öв»×ãÈÏÖ¤Ö§³Öµ¼Öµġ£µ±¿ª·¢²úƷʱ£¬²¢Î´Éè¼ÆÌṩ°²È«·þÎñÈçÈÏÖ¤¡£¡±
Applied Risk¹«Ë¾°µÊ¾£¬ÕâЩ·ì϶¿ÉÔâÔ¶³ÌÀûÓ㬲¢ÇÒÈôÊÇÍøÂçÅäÖÃÁËÕâÀà½Ó¼ûȨÏÞÔò¿ÉÄÜͨ¹ý»¥ÁªÍø±»ÀûÓá£
ABB ¹«Ë¾ÎªÈÏ֤ȱʧºÍ XSS ·ì϶Çé¿ö°ä²¼°²È«²¼¸æ¡£¸Ã¹«Ë¾·î¸æ¿Í»§³Æ£¬²úÆ·ÒÑÊÙÖÕÕýÇÞ£¬Òò¶ø½«²»»áÍÆ³öÈκι̼þ¸üС£È»¶ø£¬Óû§¸Ãµ±»áÊÕµ½¹ØÓÚÈôºÎ±£»¤×°Ö÷¨Ê½°²È«µÄÖ¸ÄÏÓʼþ¡£
ĿǰÉÐδÓÐÖ¤¾ÝÅú×¢£¬ÕâЩȱµãÒѱ»¶ñÒâÀûÓá£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
ABB½«²»»á°ä²¼¸üеĹ̼þ£¬ÓÉÓÚGATE-E1ºÍGATE-E2¶¼ÒѴﵽʹÓÃÊÙÃü£¨EOL£©¡£ ABB½¨ÒéÖ´ÐÐ×ÝÉî·ÀÓù×¼Ôò£¬ÒÔ×î´óÏ޶ȵؽµµÍ·ì϶±»ÀûÓõķçÏÕ¡£
²Î¿¼Á´½Ó
https://ics-cert.us-cert.gov/advisories/ICSA-18-352-01
https://www.securityweek.com/serious-flaws-found-abb-safety-plc-gateways


¾©¹«Íø°²±¸11010802024551ºÅ