WAGO PLCÖеĶà¸ö·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2019-12-18

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5073 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.3 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5074 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5075 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5077 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5078 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5079 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5080 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5081 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5082 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Series PFC100 (750-81xx/xxx-xxx)

Series PFC200 (750-82xx/xxx-xxx)


·ì϶¸ÅÊö


˼¿ÆTalos×êÑÐÈËÔ±ÔÚWAGOÔì×÷µÄ¿É±à³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©Öз¢ÏÖ¶à¸öÑϳÁ·ì϶ £¬ÕâЩ·ì϶¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐÓ×¢»Ø¾ø·þÎñ¹¥»÷»ò»ñÈ¡É豸µÄµÇ¼ʹ´¦¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬WAGO PFC200ºÍPFC100½ÚÔìÆ÷ £¬ËüÃDZ»¿í·ºÓÃÓÚÆû³µ¡¢Ìú·¡¢µçÁ¦¹¤³Ì¡¢Ôì×÷ºÍ¹¹ÖþÎïÖÎÀíµÈÐÐÒµÖС£·ì϶¸ÅÊöÈçÏ£º


CVE-2019-5073

I/O-CheckÖ°ÄÜ´æÔÚÐÅϢй¶·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÔËÐйý³ÌÖдæÔÚÅäÖõÈÃýÎó¡£Î´ÊÚȨµÄ¹¥»÷Õß¿ÉÀûÓ÷ì϶»ñÈ¡ÊÜÓ°Ïì×é¼þÃô¸ÐÐÅÏ¢¡£


CVE-2019-5074

I/O-CheckÖ°ÄÜ´æÔÚ»º³åÇøÃýÎó·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ £¬Î´ÕýÈ·ÑéÖ¤Êý¾ÝÌìǵ £¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æµØÎ»ÉÏÖ´ÐÐÁËÃýÎóµÄ¶Áд²Ù×÷¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶µ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£


CVE-2019-5075

getcouplerdetails£¨ºÅÁîÐÐʵÓ÷¨Ê½£©´æÔÚ»º³åÇøÃýÎó·ì϶¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÊý¾Ý°üÀûÓø÷ì϶ִÐдúÂë¡£


CVE-2019-5077

I/O-CheckÖ°ÄÜ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÊý¾Ý°üÀûÓø÷ì϶Ôì³É»Ø¾ø·þÎñ £¬Ê¹É豸½øÈëÃýÎóµÄ״̬¡£


CVE-2019-5078

I/O-CheckÖ°ÄÜ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÊý¾Ý°üÀûÓø÷ì϶Ôì³É»Ø¾ø·þÎñ £¬Ê¹É豸½øÈëÃýÎóµÄ״̬¡£


CVE-2019-5079

I/O-CheckÖ°ÄÜ´æÔÚ»º³åÇøÃýÎó·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ £¬Î´ÕýÈ·ÑéÖ¤Êý¾ÝÌìǵ £¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æµØÎ»ÉÏÖ´ÐÐÁËÃýÎóµÄ¶Áд²Ù×÷¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶µ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£


CVE-2019-5080

I/O-CheckÖ°ÄÜ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úƷδÕýÈ·ÏÞ¶ÈÀ´×ÔδÊÚȨ½ÇÉ«µÄ×ÊÔ´½Ó¼û¡£


CVE-2019-5081

I/O-CheckÖ°ÄÜ´æÔÚ»º³åÇøÃýÎó·ì϶¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÊý¾Ý°üÀûÓø÷ì϶ִÐдúÂë¡£


CVE-2019-5082

I/O-CheckÖ°ÄÜ´æÔÚ»º³åÇøÃýÎó·ì϶¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÊý¾Ý°üÀûÓø÷ì϶ִÐдúÂë¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´ÈçÏÂÁù¸ö·ì϶ £¬Çë¸üй̼þÖÁ>= FW 15£ºCVE-2019-5073¡¢CVE-2019-5074¡¢CVE-2019-5075¡¢CVE-2019-5079¡¢CVE-2019-5081¡¢CVE-2019-5082¡£Ç¿ÁÒ½¨ÒéÔÚµ÷ÊÔºó½ûÓÃI/O-Check·þÎñʹÓõĶ˿Ú6626¡£


²Î¿¼Á´½Ó


https://www.securityweek.com/several-critical-vulnerabilities-found-wago-controllers