Î÷ÃÅ×ÓSPPA-T3000¶à¸ö·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2019-12-16·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-18283£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18315£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18316£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18314£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18313£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
É¢²¼Ê½½ÚÔìϵͳSPPA-T3000
·ì϶¸ÅÊö
Î÷ÃÅ×Ó¹¤ÒµÉ豸Öб»ÆØ´æÔÚ¶à¸ö°²È«·ì϶£¬ ÊÜÓ°Ïì²úÆ·ÊÇÉ¢²¼Ê½½ÚÔìϵͳSPPA-T3000£¬±é²¼ÓÚÃÀ¹ú¡¢µÂ¹ú¡¢¶íÂÞ˹ºÍÆäËü¹ú¶ÈµÄÖØÒª·¢µç³§ÖУ¬ÓÃÓÚкÍг¼à¶½·¢µç¡£
ÀûÓÃÆäÖеÄһЩ·ì϶¿ÉÔÚÀûÓ÷¨Ê½·þÎñÆ÷ÉÏÔËÐÐËÁÒâ´úÂ룬´Ó¶ø½ÚÔì²Ù×÷²¢Ö´ÐзÛËé¡£ÕâÑù×ö¿ÉÄÜ×èÖ¹×°ÖÃÒ×Êܹ¥»÷ϵͳµÄ·¢µç³§·¢µç²¢Òý·¢¹ÊÕÏ¡£
ÕâЩ·ì϶´æÔÚÓÚ¸ÃÆ½Ì¨µÄÁ½¸ö¾ßÌå×é¼þÖУºÀûÓ÷¨Ê½·þÎñÆ÷»ººÍ½â·þÎñÆ÷¡£
ÆäÖÐ×îÑϳÁµÄ·ì϶¿É´¥·¢ÀûÓ÷¨Ê½ÉϵÄÔ¶³Ì´úÂëÖ´ÐÐÎÊÌâ¡£ÀýÈ磬һ¸öÑϳÁµÄ²»ÊÜÐÅÀµµÄÊý¾Ý·´ÐòÁл¯·ì϶ CVE-2019-18283¿Éµ¼Ö¹¥»÷Õßͨ¹ýÏòÆäÖÐÒ»¸öº¯Êý·¢ËÍÌØÊâ»ú¹Ø¶ÔÏóµÄ²½Öè»ñȡԶ³Ì´úÂëÖ´ÐÐȨÏÞ¡£
Áí±íÁ½¸öÑϳÁ·ì϶CVE-2019-18315 ºÍ CVE-2019-18316 ¿Éµ¼ÖÂÕ¼ÓÐÀûÓ÷¨Ê½·þÎñÆ÷ÍøÂç½Ó¼ûȨÏ޵Ĺ¥»÷Õßͨ¹ý¶È±ðÏò 8888/TCP ºÍ1099/TCP ¶Ë¿Ú·¢ËÍÌØÊâ»ú¹ØÊý¾Ý°üµÄ·½Ê½»ñȡԶ³Ì´úÂë½Ó¼ûȨÏÞ¡£
Áí±íÒ»¸öÑϳÁµÄÈÏÖ¤²»µ±È±µã CVE-2019-18314 ¿Éµ¼ÖÂÕâÀ๥»÷Õßͨ¹ý Remote Method Invocation (RMI) ·¢ËÍÌØÊâ»ú¹ØµÄ¶ÔÏó»ñȡԶ³Ì´úÂëÖ´ÐÐȨÏÞ¡£
MS-3000 »º½â·þÎñÆ÷ÖдæÔÚÆäËü¶à¸ö·ì϶¡£ÆäÖÐÁ½¸ö¿Éµ¼ÖÂÔ¶³Ì¶ÁÈ¡ºÍдÈëËÁÒâÎļþ¡£ÀýÈ磬¹¥»÷Õß¿ÉÄܶÁÈ¡ /etc/shadow£¬¶øºóÕßÔ̺¬¿É±»ÓÃÓÚ±©Á¦ÆÆ½âÓû§ÃÜÂëµÄ¹þÏ£¡£Áí±í»¹·¢ÏÖ¶à¸ö¶ÑÒç¶Âí½Å£¬¿É±»ÓÃÓÚÕë¶Ô»º½â·þÎñÆ÷·¢Æð»Ø¾ø·þÎñ¹¥»÷µÈ¡£
ÆäÖÐÒ»¸öÖµÍ×ÌùÐĵķì϶ÊÇCVE-2019-18313£¬ËüÊÇÒ»¸öÑϳÁµÄ²»ÊÜÏÞÉÏ´«·ì϶£¬ÎÞÐèÈÏÖ¤¼´¿É¶³ö±¾ÎªÖÎÀíÔ±Éè¼ÆµÄÔ¶³Ì·¨Ê½Å²Óà (RPCs)¡£Ëü¿Éµ¼ÖÂÓµÓÐ MS-3000 ·þÎñÆ÷×é¼þÍøÂç½Ó¼ûȨÏ޵Ĺ¥»÷Õßͨ¹ýÏòÆäÖÐÒ»ÖÖ RPC ·þÎñ·¢ËÍÌØÊâ»ú¹ØµÄ¶ÔÏó¡£
Î÷ÃÅ×Ó¹«Ë¾°µÊ¾£¬ÀûÓÃÆäÖÐÈκÎÒ»ÖÖ·ì϶¾ùÐè»ñÈ¡¶Ô Application »ò Automation Highway£¨ÏνÓ×é¼þµÄÍøÂ磩µÄ½Ó¼ûȨÏÞ¡£ÈôÊÇÒÀÕÕÎ÷ÃÅ×ӵIJÙ×÷Ö¸ÄÏÉèÖû·¾³µÄ»°²»»á¶³öÕâÐ©ÍøÂç¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Î÷ÃÅ×Ó°µÊ¾ÔÚÍÆ³ö¸üУ¬Í¬Ê±Ö¸³öµçÁ¦³§Ó¦¸ÃÏ޶ȶÔʹÓà SPPA-T3000 ·À»ðǽµÄ Application Highway µÄ½Ó¼ûȨÏÞ£¬Í¬Ê±Ó¦¸ÃûÓÐÔÚ Application »òAutomation highwaysÉÏÇÅ½Ó±í²¿ÍøÂç¡£
²Î¿¼Á´½Ó
https://threatpost.com/critical-remote-code-execution-global-power-plants/151087/


¾©¹«Íø°²±¸11010802024551ºÅ