Rockwell Automation¿É±à³ÌÂß¼­½ÚÔìÆ÷°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-18

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-6990£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-6984£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-6988£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-6980£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º4.0£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Rockwell Automation MicroLogix 1400 Controllers Series B v21.001¼°Ö®Ç°°æ±¾ºÍSeries AËùÓа汾

MicroLogix 1100 ControllerËùÓа汾

RSLogix 500 Software v12.001¼°Ö®Ç°°æ±¾


·ì϶¸ÅÊö


ÃÀ¹úRockwell Automation¹«Ë¾ÊÇÈ«Çò×î´óµÄ×Ô¶¯»¯ºÍÐÅÏ¢»¯¹«Ë¾Ö®Ò»¡£MicroLogix 1400 ControllersºÍMicroLogix 1100 ControllersÊÇRockwell Automation¹«Ë¾³öÆ·µÄ¿É±à³ÌÂß¼­½ÚÔìÆ÷¡£RSLogix 500 SoftwareÊÇÒ»Ì×ÓÃÓÚ¹¤Òµ½ÚÔìϵͳµÄ±à³ÌÈí¼þ¡£


ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼ÁËÒ»Ôò°²È«²¼¸æ£¬Åû¼ûÀ¹úRockwell Automation¹«Ë¾MicroLogix 1400 Controllers£¬MicroLogix1100 ControllersºÍRSLogix 500 SoftwareÖеĶà¸ö·ì϶¡£¸ÅÊöÈçÏ£º

CVE-2020-6990£¬ RSLogix 500¶þ½øÔìÎļþʹÓÃÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿£¬¶ø¸Ã¼ÓÃÜÃÜÔ¿ÓÃÓÚ±£»¤ÕË»§ÃÜÂë¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¼ø±ð¼ÓÃÜÃÜÔ¿£¬²¢½«ÆäÓÃÓÚºóÐøµÄÃÜÂë¹¥»÷£¬×îÖÕ´ï³ÉԽȨ½Ó¼û½ÚÔìÆ÷¡£


CVE-2020-6984£¬¸Ã·ì϶ԴÓÚʹÓÃÁ˱»ÆÆ½âµÄ»òÓзçÏÕµÄËã·¨£¬MicroLogixÖÐÓÃÓÚ±£»¤ÃÜÂëµÄ¼ÓÃܺ¯ÊýÈÝÒ×±»·¢ÏÖ¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÆÆ½âËã·¨²¢ÈëÇÖÊܱ£»¤µÄÊý¾Ý£¬×îÖÕй¼ûô¸ÐÐÅÏ¢¡£


CVE-2020-6988£¬Î´¾­Éí·ÝÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õ߿ɴÓRSLogix 500 SoftwareÏòÊܺ¦ÕßµÄMicroLogix½ÚÔìÆ÷·¢ËÍÒ»¸öÒªÇ󣬽ÚÔìÆ÷»áѡȡÒÑÓùýµÄÃÜÂëÖµÏìÓ¦¿Í»§¶Ë£¬¶ÔÔÚ¿Í»§¶ËÉϵÄÓû§½øÐÐÉí·ÝÈÏÖ¤¡£¹¥»÷Õß¿ÉÀûÓôËÖÖÉí·ÝÈÏÖ¤²½ÖèÈÆ¹ýÉí·ÝÈÏÖ¤£¬Ð¹Â¼ûô¸ÐÐÅÏ¢£¬»òй¶ʹ´¦¡£


CVE-2020-6980£¬RSLogix 500Öб£ÁôÁËSMTPÕË»§Êý¾Ý£¬ÓÉÓÚ¸ÃÊý¾ÝÒÔÃ÷ÎÄ´ó¾ÖдÈëµ½ÏîÄ¿ÎļþÖУ¬±¾µØ¹¥»÷ÕßÈôÊÇÄܹ»½Ó¼ûÊܺ¦ÕßµÄÏîÄ¿£¬Ôò¿ÉÄÜÍøÂçSMTP serverµÄÉí·ÝÈÏÖ¤Êý¾Ý¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£


½¨¸´½¨Òé


¶ÔÓÚʹÓÃMicroLogix 1400 Controllers Series BµÄÓû§£¬Rockwell½¨Òé¸üа汾ÖÁ21.002»ò¸ü¸ß°æ±¾£¬²¢Ê¹ÓüÓÇ¿µÄÃÜÂ밲ȫְÄÜ£¬Á´½Ó£ºhttps://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx?crumb=112&refSoft=1&toggleState=&versions=56181,56502,56710,57096,58298¡£


¶ÔÓÚRSLogix 500Èí¼þ£¬Rockwell Automation½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹ÓÃv11»ò¸ü¸ß°æ±¾£¬²¢ÓëºÏÓÃÓÚMicrologix 1400ϵÁÐBÉ豸µÄFRN 21.001»ò¸ü¸ß°æ±¾Ò»Â·Ê¹Óã¬Á´½Ó£ºhttps://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx?crumb=112&refSoft=1&toggleState=&versions=57415,56006¡£


¶ø¶ÔÓÚMicroLogix 1400 Series A½ÚÔìÆ÷»òMicroLogix 1100½ÚÔìÆ÷£¬Rockwell AutomationÏòCISA°µÊ¾Ä¿Ç°ÉÐδÓлº½â´ëÊ©¡£


²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-070-06