ABB PLCÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-12-19

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-18995£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-18997£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 7.1£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


GATE-E1 (EOL 2013)

GATE-E2 (EOL OCT 2018)


·ì϶¸ÅÊö


×êÑÐÈËÔ±ÔÚÈðÊ¿¹¤Òµ¼¼Êõ¹«Ë¾ ABB ³ö²úµÄÄ³Ð©Íø¹Ø²úÆ·Öз¢ÏÖÁËÑϳÁ·ì϶£¬µ«ÓÉÓÚ²úÆ·µÄÐÔÃüÖÜÆÚʵÏÖ£¬Òò¶ø³§É̽«²»»áÍÆ³ö²¹¶¡¡£


Applied Risk¹«Ë¾±¾Öܰ䲼°²È«²¼¸æ°µÊ¾£¬ABB ³ö²úµÄ Pluto Íø¹Ø²úÆ·ÖдæÔÚÁ½¸öÑϳÁ·ì϶¡£ÊÜÓ°ÏìµÄÍø¹ØÊÇ GATE-E1 ºÍ GATE-E2£¬ËüÃǿɵ¼Ö ABB ¹«Ë¾µÄ¿É±à³Ì°²È«½ÚÔìÆ÷£¨°²È« PLCs£©ºÍÆäËü½ÚÔìϵͳͨѶ¡£


×êÑÐÈËÔ±Ö¸³ö£¬ÕâЩÉ豸µÄÖÎÀíÔ± telnet ºÍ web ½Ó¿ÚÉ϶ÌȱÈÏÖ¤»úÔ죬¿Éµ¼Ö¹¥»÷ÕßµÈÏлñÈ¡ÊÚȨȨÏÞ¡£¸Ãȱµã±» Applied Risk ¹«Ë¾ºÍ ABB ¹«Ë¾¾ùÆÀΪ¡°ÑϳÁ¡±µÈ¼¶£¬¿É±»ÓÃÓÚÅú¸ÄÉ豸ÅäÖò¢Í¨¹ý³ÖÐø³ÁÖòúÆ·µÄ²½ÖèÒý·¢»Ø¾ø·þÎñǰÌá¡£


ABB ¹«Ë¾Ú¹ÊͳÆ£¬¡°¸Ã·ì϶ÊÇÒò²úÆ·Öв»×ãÈÏÖ¤Ö§³Öµ¼ÖµÄ¡£µ±¿ª·¢²úƷʱ£¬²¢Î´Éè¼ÆÌṩ°²È«·þÎñÈçÈÏÖ¤¡£¡±


Applied Risk¹«Ë¾°µÊ¾£¬ÕâЩ·ì϶¿ÉÔâÔ¶³ÌÀûÓ㬲¢ÇÒÈôÊÇÍøÂçÅäÖÃÁËÕâÀà½Ó¼ûȨÏÞÔò¿ÉÄÜͨ¹ý»¥ÁªÍø±»ÀûÓá£


ABB ¹«Ë¾ÎªÈÏ֤ȱʧºÍ XSS ·ì϶Çé¿ö°ä²¼°²È«²¼¸æ¡£¸Ã¹«Ë¾·î¸æ¿Í»§³Æ£¬²úÆ·ÒÑÊÙÖÕÕýÇÞ£¬Òò¶ø½«²»»áÍÆ³öÈκι̼þ¸üС£È»¶ø£¬Óû§¸Ãµ±»áÊÕµ½¹ØÓÚÈôºÎ± £»¤×°Ö÷¨Ê½°²È«µÄÖ¸ÄÏÓʼþ¡£


ĿǰÉÐδÓÐÖ¤¾ÝÅú×¢£¬ÕâЩȱµãÒѱ»¶ñÒâÀûÓá£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


ABB½«²»»á°ä²¼¸üеĹ̼þ£¬ÓÉÓÚGATE-E1ºÍGATE-E2¶¼ÒѴﵽʹÓÃÊÙÃü£¨EOL£©¡£ ABB½¨ÒéÖ´ÐÐ×ÝÉî·ÀÓù×¼Ôò£¬ÒÔ×î´óÏ޶ȵؽµµÍ·ì϶±»ÀûÓõķçÏÕ¡£


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-352-01

https://www.securityweek.com/serious-flaws-found-abb-safety-plc-gateways