VxWorks¶à¸ö°²È«·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-07-30¡ô ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12257£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12255£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12260£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12261£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12263£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12258£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12259£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.3£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12262£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12264£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12265£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.4£¬¹Ù·½Î´ÆÀ¶¨
¡ô Ó°Ïì°æ±¾
¡ô ·ì϶¸ÅÊö
VxWorksÊÇÊÀ½çÉÏʹÓÃ×î¿í·ºµÄÒ»ÖÖÔÚǶÈëʽϵͳÖв¿ÊðµÄʵʱ²Ù×÷ϵͳ£¬ÊÇÓÉÃÀ¹úWindRiver¹«Ë¾£¨¼ò³Æ·çºÓ¹«Ë¾£¬¼´WRS ¹«Ë¾£©ÓÚ1983ÄêÉè¼Æ¿ª·¢µÄ£¬VxWorks±»³¬¹ý20ÒŲ́É豸ʹÓã¬Ô̺¬¹Ø¼ü»ù´¡ÉèÊ©£¬ÍøÂçÉ豸£¬Ò½ÁÆÉ豸£¬¹¤ÒµÏµÍ³ÉõÖÁº½ÌìÆ÷¡£Äܹ»Ëµ´ÓPLCµ½MRI»úе£¬µ½·À»ðǽºÍ´òÓ¡»ú£¬ÔÙµ½·É»ú£¬»ð³µµÈµÈ¶¼ÓÐ¿í·ºÀûÓá£
½üÈÕ£¬VxWorks¹Ù·½°ä²¼Á˰²È«·ì϶²¼¸æ³Æ½¨¸´ÁËÓÉArmis×êÑÐÍŶӷ¢ÏÖ²¢»ã±¨µÄ11¸ö°²È«·ì϶£¬ÆäÖÐÓÐ6¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶£¬CVE-2019-12256¡¢CVE-2019-12255¡¢CVE-2019-12260 CVSSÆÀ·ÖΪ9.8·Ö¡£ÆäÓà5¸ö·ì϶¿ÉÄܵ¼Ö»ؾø·þÎñ£¬ÐÅϢй©»ò¹éÀàΪÂ߼ȱµã¡£ÕâЩ·ì϶´æÔÚÓÚVxWorksµÄTCP/IP²Ö¿â£¨IPnet£©ÖУ¬Ó°ÏìVxWorks 7 (SR540 and SR610)¡¢VxWorks 6.5-6.9¼°Ê¹ÓÃInterpeak¶ÀÁ¢ÍøÂç²Ö¿âµÄVxWorks°æ±¾¡£¹¥»÷ÕßÄܹ»ÀûÓÃÆäÖзì϶ʵÏÖÎÞÐèÓû§½»»¥¼°ÈÏ֤ʵÏÖÔ¶³Ì¹¥»÷£¬×îÖÕÔÚÆëÈ«½ÚÔìÓйØÉ豸¡£
¡ô ·ì϶ÑéÖ¤
ĿǰArmis×êÑÐÍŶӰ䲼Á˳ɹ¦ÀûÓ÷ì϶½ÚÔìÁËSonicWall·À»ðǽ¡¢Xerox´òÓ¡»ú¡¢²¡È˼໤ÒǵÄÑÝʾÊÓÆµ£¬µ«ÊÇûÓа䲼·ì϶ÓйØÏ¸½Ú»ò·ì϶ÑéÖ¤·¨Ê½¡£
¡ô ½¨¸´½¨Òé
SonicWall£ºhttps://blog.sonicwall.com/en-us/2019/07/wind-river-vxworks-and-urgent-11-patch-now/
Xerox£ºhttps://security.business.xerox.com/en-us/
¡ô ²Î¿¼Á´½Ó
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/


¾©¹«Íø°²±¸11010802024551ºÅ