Sick MSC800ÐÅÀµÖÎÀíÎÊÌâ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-03

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10979£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Sick MSC800 4.0֮ǰ°æ±¾¡£


·ì϶¸ÅÊö


Sick MSC800Êǵ¹úÎ÷¿Ë£¨Sick£©¹«Ë¾µÄÒ»¿î¿É±à³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©¡£


ÊÜÓ°ÏìµÄ½ÚÔìÆ÷ÔÚÈ«ÇòÁìÓòÄÚʹÓ㬳ö¸ñÊÇÔڹؼüÔì×÷ÁìÓò£¬Êܵ½CVE-2019-10979×·×ÙµÄÑϳÁ·ì϶µÄÓ°Ïì¡£


Sick MSC800 4.0֮ǰ°æ±¾ÖдæÔÚÐÅÀµÖÎÀíÎÊÌâ·ì϶¡£ÓÉÓÚ´æÔÚÓ²±àÂëÆ¾Ö¤£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶³ÁÐÂÅäÖûòÆÆ»Â·´×Ե¹ú´«¸ÐÆ÷Ôì×÷ÉÌSickµÄMSC800Ä £¿é»¯ÏµÍ³½ÚÔìÆ÷¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt/#advisories


²Î¿¼Á´½Ó


 https://www.securityweek.com/hardcoded-credentials-expose-sick-controllers-remote-attacks