Phoenix Contact²úÆ·¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-03-16·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-9435£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.1£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-9436£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.2£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2017-16544£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½£º8.8
Ó°Ïì°æ±¾
Article name
Article number
Affected versions
TC ROUTER
TC ROUTER 3002T-4G
2702528
<= 2.05.3
TC ROUTER 3002T-4G
2702530
<= 2.05.3
TC ROUTER 2002T-3G
2702529
<= 2.05.3
TC ROUTER 2002T-3G
2702531
<= 2.05.3
TC ROUTER 3002T-4G VZW
2702532
<= 2.05.3
TC ROUTER 3002T-4G ATT
2702533
<= 2.05.3
TC CLOUD CLIENT
TC CLOUD CLIENT 1002-4G
2702886
<= 2.03.17
TC CLOUD CLIENT 1002-4G VZW
2702887
<= 2.03.17
TC CLOUD CLIENT 1002-4G ATT
2702888
<= 2.03.17
TC CLOUD CLIENT 1002-TXTX
2702885
<= 1.03.17
·ì϶¸ÅÊö
Phoenix ContactΪ×ܲ¿Î»Óڵ¹úµÄ¹¤Òµ×Ô¶¯»¯¡¢ÏνӺͽӿڽâ¾ö¹æ»®ÌṩÉÌ¡£ÔÚPhoenix Contact³ö²úµÄPhoenix Contact TC·ÓÉÆ÷ºÍTCÔÆ¿Í»§¶ËÉ豸Öз¢ÏÖÁËÈý¸ö·ì϶£¬¸ÅÊöÈçÏÂ:
CVE-2020-9435£¬ÓëÓÃÓÚHTTPSµÄÓ²±àÂëÖ¤ÊéµÄ´æÔÚÓйء£¹¥»÷ÕßÄܹ»ÀûÓôËÖ¤Êé½øÐÐÖÐÑëÈË(MitM)¹¥»÷¡¢É豸·ÂÕպͱ»¶¯½âÃÜ£¬´Ó¶ø»ñµÃÖÎÀíԱƾ֤ºÍÆäËûÃô¸ÐÐÅÏ¢¡£
CVE-2020-9436£¬¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶À´½øÐкÅÁî×¢È룬´Ó¶øÈëÇÖÉ豸µÄ²Ù×÷ϵͳ¡£
CVE-2017-16544£¬ÔÚBusyBox 1.27.2¼°Ö®Ç°µÄ°æ±¾ÖУ¬shellµÄtab auto complete¸öÐÔÓÃÓÚ»ñȡĿ¼ÖеÄÎļþÃûÁÐ±í£¬Ëü²»»áËãÕÊÎļþÃû£¬²¢µ¼ÖÂÔÚÖÕ¶ËÖÐÖ´ÐÐÈκÎתÒåÐòÁС£´Ë·ì϶¿ÉÄܵ¼Ö´úÂëÖ´ÐÓ×¢ËÁÒâÎļþдÈë»òÆäËû¹¥»÷¡£´Ë·ì϶¶ÔÉ豸µÄÓ°ÏìÓÐÏÞ£¬ÓÉÓÚÖ»ÓÐÓµÓÐÖÎÀíԱȨÏÞÄÜÁ¦½Ó¼ûshell·¨Ê½¡£
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£
½¨¸´½¨Òé
Ŀǰ¹Ù·½ÒѰ䲼×îа汾½¨¸´¸Ã·ì϶£¬Á´½Ó£ºhttps://cert.vde.com/en-us/advisories/vde-2020-003¡£
²Î¿¼Á´½Ó
https://cert.vde.com/en-us/advisories/vde-2020-003


¾©¹«Íø°²±¸11010802024551ºÅ