ÈýÁâsmartRTU²Ù×÷ϵͳºÅÁî×¢Èë·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-20¡ñ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-14931£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
¡ñÓ°Ïì°æ±¾
²úÆ·: ÈýÁâµç»úsmartRTU ºÍINEA ME-RTU
¹Ì¼þ°æ±¾: ÈýÁâµç»ú2.02¼°Ö®Ç°°æ±¾/INEA 3.0¼°Ö®Ç°°æ±¾
¡ñ·ì϶¸ÅÊö
ÈýÁâµç»úµÄsmartRTUºÍINEA ME-RTUÖдæÔÚδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì²Ù×÷ϵͳºÅÁî×¢Èë·ì϶¡£
¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÔÚÓйØRTUÉÏÔ¶³ÌÖ´ÐÐËÁÒâ²Ù×÷ϵͳºÅÁÓÉÓÚRTU»ùÓÚwebµÄÔ¶³ÌÅäÖÃÀûÓöÔÓû§ÊäÈëÊý¾Ý²»×öÈκιýÂË¡£ÔÚ¡°mobile.php¡±Ò³ÃæÌṩµÄ¡°Mobile Connection Test¡±Ö°ÄÜÖУ¬ÔÊÐíÓû§pingËÁÒâÍøÖ·»òÕßIPµØÖ·£»ºÚ¿ÍÄܹ»ÔÚÊäÈëIPµØÖ·»òÕßÍøÖ·µÄβ²¿Ôö³¤shellºÅÁî·Ö¸ô·û£¨£»£©£¬Ö®ºó½Ó×ÅÊäÈëËù±ØÒªÖ´ÐеIJÙ×÷ϵͳָÁî¡£
µ±¡°Mobile Connection Test¡±Ö°Äܱ»Ö´ÐеÄʱ³½£¬RTU»áŲÓá°action.php¡±£¬¸Ã¾ç±¾µÄÄÚÈÝÈçÏ£º
ÓÉÓÚ²»×ã¶ÔÓû§ÊäÈëÊý¾ÝµÄ¹ýÂË£¬ºÚ¿ÍÄܹ»ÔÚ$command±äÁ¿ºóÃæ¼Ó¹Ò±ØÒªÖ´ÐеIJÙ×÷ϵͳºÅÁî¡£ÀýÈ磬host±äÁ¿¿ÉËùÒÔ×Ö·û´®£º¡°www.inea.si;ping 127.0.0.1¡±£¬ÄÇôϵͳÊ×ÏÈ»áÖ´ÐкϷ¨µÄpingºÅÁîÀ´²âÊÔwww.inea.siµÄÁ¬Í¨ÐÔ£¬¶øºóÔÙÖ´Ðз¸·¨pingºÅÁîÀ´²âÊÔ±¾µØÖ÷»úµÄÁ¬Í¨ÐÔ¡£
ͨ¹ýÅäÖÃÎļþÄܹ»·¢ÏÖ£¬Óû§¡°www-data¡±Äܹ»Í¨¹ýsudoersÖ´ÐÐÈô¸ÉÓµÓÐrootȨÏÞµÄÖ¸Á¸ÃÅäÖÃÎļþµÄ´æ´¢µÄÎļþõ辶Ϊ/etc/sudoers.d/viswww¡£Ï±íËùʾΪÓû§¡°www-data¡±µÄËùÓÐȨÏÞ¡£
¹ÌÈ»ÔÊÐíÒÔrootȨÏÞÖ´ÐеĺÅÁ¶ÈÓÐÏÞ£¬µ«ÊÇÒÀÈ»Äܹ»ÀûÓÃ/usr/sbin/serviceºÅÁîÀ´ÈƹýÊÚȨÏÞ¶È¡£Í¨¹ýÀûÓá°service¡±ºÅÁÄܹ»ÔÚRTUÉÏÆô¶¯netcat·þÎñ²¢´´½¨Ò»¸öÓµÓÐrootȨÏÞµÄshell¡£¾ßÌå²Ù×÷ÈçÏ£º
ÏÂÃæ´úÂëËùʾΪ³É¹¦ÔÚRTUÉϳɹ¦ÒÔrootȨÏÞÔËÐÐshell£º
ÓÉÓÚsession²é³µÄȱʧ£¬Ê¹µÃºÚ¿ÍÄܹ»Ö±½Ó°Ñpayload·¢Ë͸ø¡°action.php¡±´Ó¶øÊµÏÖÉÏÊö¹¥»÷¡£ÏÂͼËùʾΪÔÚ¹¥»÷Ö÷»úÉÏÔ¶³ÌÖ´ÐÐcurlºÅÁî¡£
¡ñ·ì϶ÑéÖ¤
POC£ºhttps://cxsecurity.com/issue/WLB-2019080056¡£
¡ñ½¨¸´½¨Òé
Ŀǰ¹Ù·½Ã»°ä²¼Óйز¹¶¡£¬Çë¹Ø×¢¹ÙÍø£ºhttps://www.mitsubishielectric.com/¡£
¡ñ²Î¿¼Á´½Ó
https://www.mogozobo.com/?p=3593


¾©¹«Íø°²±¸11010802024551ºÅ