EZAutomation¶à¸ö»º³åÇøÃýÎó·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-06

¡ñ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13522£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.8

CVE±àºÅ£ºCVE-2019-13518£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.8


¡ñÓ°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


CVE-2019-13522

EZ PLC Editor Versions 1.8.41 and prior


CVE-2019-13518

EZ Touch Editor Versions 2.1.0 and prior


¡ñ·ì϶¸ÅÊö


EZAutomationÊÇAVGÆìϵÄÒ»¸öϵÁС£AVGÊÇÒ»¼Ò×ö¹¤Òµ´¥ÃþÆÁºÍ¿É±à³Ì½ÚÔìÆ÷µÄÃÀ¹úµçÆø¹«Ë¾¡£EZAutomationϵÁÐÏÂÓÐPLC²úÆ·£¬´¥ÃþÆÁ£¬±àÂëÆ÷£¬ÅÜÂíµÆ£¬²Ù×÷½çÃæ¸÷Àà¸ßÐÔ¼Û²úÆ·¡£½üÈÕEZAutomation°ä²¼Á½¸ö»º³åÇøÃýÎó·ì϶ÈçÏ£º


CVE-2019-13522

EZAutomation EZ PLC EditorÊÇÃÀ¹úEZAutomation¹«Ë¾µÄÒ»Ì×PLC£¨¿É±à³ÌÂß¼­½ÚÔìÆ÷£©±à³ÌÈí¼þ¡£EZAutomation EZ PLC Editor 1.8.41¼°Ö®Ç°°æ±¾ÖдæÔÚ»º³åÇøÃýÎó·ì϶¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÏîÄ¿ÎļþÀûÓø÷ì϶°Ü»µÄÚ´æ²¢ÒÔ¸ÃÀûÓ÷¨Ê½È¨ÏÞÖ´ÐдúÂë¡£


CVE-2019-13518

EZAutomation EZ Touch EditorÊÇÃÀ¹úEZAutomation¹«Ë¾µÄÒ»Ì×HMI£¨ÈË»ú½çÃæ£©±à³ÌÈí¼þ¡£EZAutomation EZ Touch Editor 2.1.0¼°Ö®Ç°°æ±¾ÖдæÔÚ»º³åÇøÃýÎó·ì϶¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÏîÄ¿ÎļþÀûÓø÷ì϶ÒÔ¸ÃÀûÓ÷¨Ê½µÄȨÏÞÖ´ÐдúÂë¡£


¡ñ·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


¡ñ½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏÂÔØÁ´½Ó£ºhttps://www.ezautomation.net/access.php¡£


¡ñ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-19-246-01

https://www.us-cert.gov/ics/advisories/icsa-19-246-02