Ê©ÄÍµÂµçÆø²úÆ·¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-12

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2018-7846£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.3£¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7849£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7843£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7844£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7848£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.9£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7842£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7847£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7850£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º5.3
CVE±àºÅ£ºCVE-2018-7845£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7852£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7853£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7854£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7855£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7856£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7857£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-6806£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½£º6.5
CVE±àºÅ£ºCVE-2018-6807£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-6808£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10.0£¬¹Ù·½£º7.5



Ó°Ïì°æ±¾



ÊÜÓ°ÏìµÄ°æ±¾


Modicon M580ËùÓа汾
Modicon M340ËùÓа汾
Modicon QuantumËùÓа汾

Modicon PremiumËùÓа汾



·ì϶¸ÅÊö



Schneider Electric Modicon M580µÈ¶¼ÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄ²úÆ·¡£Schneider Electric Modicon M580ÊÇÒ»¿î¿É±à³Ì×Ô¶¯»¯½ÚÔìÆ÷¡£Schneider Electric Modicon PremiumÊÇÒ»¿îÓÃÓÚÀëÉ¢»ò¹ý³ÌÀûÓõĴóÐͿɱà³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©¡£Schneider Electric Modicon QuantumÊÇÒ»¿îÓÃÓÚ¹ý³ÌÀûÓᢸ߿ÉÓÃÐԺͰ²È«½â¾ö¹æ»®µÄ´óÐͿɱà³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©¡£¶à¿îSchneider Electric²úÆ·ÖдæÔÚÈçÏ·ì϶£º


CVE-2018-7846

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸ÔÚ²»ÑéÖ¤·¢¼þÈËÕæÊµÐÔµÄÇé¿öÏÂʹ»á»°ÎÞЧ£¬´Ó¶øµ¼ÖºϷ¨É豸¶Ï¿ªÏνÓ¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7849

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë¿É¸´Ô­µÄ¹ÊÕÏ״̬£¬´Ó¶øµ¼ÖÂÉ豸Õý³£Ö´ÐÐÖÕ³¡¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7843

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7844

´Ë·ì϶ΪÐÅϢй¶·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸·µ»ØÄÚ´æ¿é£¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁÈ¡£¬Ð´ÈëºÍ²¶»ñSNMPÉçÇø×Ö·û´®¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7848

´Ë·ì϶ΪÐÅϢй¶·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸·µ»Ø±à³ÌÕ½ÊõµÄ¿é£¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁд£¬Ð´ÈëºÍÏÝÚåSNMPÉçÇø×Ö·û´®µÄй¶¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7842

´Ë·ì϶Ϊ²»ÕýÈ·ÈÏÖ¤·ì϶¡£ÌØÔìµÄUMASºÅÁîÄܹ»ÔÊÐí¹¥»÷Õß¼Ù×°³É¾­¹ýÉí·ÝÑéÖ¤µÄÓû§£¬´Ó¶øÄܹ»ÈƹýÉ豸ÉϵÄÃÜÂë±£»¤¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7847

´Ë·ì϶Ϊδ¾­Éí·ÝÑéÖ¤µÄÎļþдÈë·ì϶¡£ÌØÔìµÄUMASºÅÁîÐòÁпÉÄܻᵼÖÂÉ豸¸²¸ÇÆä±à³ÌÕ½Êõ£¬´Ó¶ø²úÉú¸÷ÀàÓ°Ï죬Ô̺¬ÅäÖÃÅú¸Ä£¬ÔËÐйý³ÌÖжϺÍDZÔڵĴúÂëÖ´ÐС£ ¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7850

Schneider Electric UnityProL±à³ÌÈí¼þµÄÕ½Êõ´«ÊäÖ°ÄÜÖдæÔÚ¿ÉÀûÓõĶԲ»³ÉÐÅÊäÈë·ì϶µÄÒÀÀµ¡£½«ÌØÔìÕ½Êõ±à³Ìµ½Modicon M580¿É±à³Ì×Ô¶¯»¯½ÚÔìÆ÷£¬²¢Ê¹ÓÃUnityProL¶ÁÈ¡¸ÃÕ½Êõʱ£¬»áÏòÓû§ÏÔʾÓëÉ豸·ÖÆçµÄÅäÖá£Õâµ¼ÖÂUnityProLÓû§ÎÞ·¨ÑéÖ¤É豸ÊÇ·ñ°´Ô¤ÆÚÔËÐС£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7845

´Ë·ì϶ΪÐÅϢй¶·ì϶¡£ÌØÔìµÄUMASÒªÇó¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡£¬´Ó¶øµ¼ÖÂÃô¸ÐÐÅÏ¢µÄй¶¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7852

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢ÕâЩ·ì϶¡£


CVE-2018-7853

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7854

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7855

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7856

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-7857

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-6806

´Ë·ì϶ΪÐÅϢй¶·ì϶¡£ ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸·µ»ØÄÚ´æ¿é£¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁÈ¡£¬Ð´ÈëºÍ²¶»ñSNMPÉçÇø×Ö·û´®¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-6807

¿É±à³ÌµÄ»Ø¾ø·þÎñ·ì϶´æÔÚÓÚSchneider Electric Modicon M580¿É±à³Ì×Ô¶¯»¯½ÚÔìÆ÷µÄ¹Ì¼þ°æ±¾SV2.70µÄUMASдÈëϵͳλºÍ¿éÖ°ÄÜÖС£Ò»×éÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬£¬´Ó¶øµ¼ÖÂÉ豸Զ³ÌͨѶÆëÈ«ÖÕ³¡¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£


CVE-2018-6808

Schneider Electric Unity Pro±à³ÌÈí¼þPLC·ÂÕÕÆ÷µÄUMASÕ½Êõ±à³ÌÖ°ÄÜÖдæÔÚ¿ÉÀûÓõÄÔ¶³ÌÖ´ÐдúÂë·ì϶¡£·¢Ë͵½Èí¼þPLC·ÂÕæÆ÷µÄÌØÔìUMASºÅÁîÐòÁÐÄܹ»µ¼ÖÂÅú¸ÄÕ½Êõ±à³Ì£¬´Ó¶øÔÚ·ÂÕæÆ÷Çл»µ½Æô¶¯Ä£Ê½Ê±Ö´ÐдúÂë¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£



·ì϶ÑéÖ¤



ÔÝÎÞPOC/EXP¡£



½¨¸´½¨Òé



¹Ù·½ÒÑÍÆ³ö¸üв¹¶¡£¬Çëʵʱ¸üУºhttps://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-11+-+Modicon+Controller.pdf&p_Doc_Ref=SEVD-2019-134-11¡£



²Î¿¼Á´½Ó



https://blog.talosintelligence.com/2019/06/vulnerability-spotlight-multiple.html