CVE-2020-10607| Advantech WebAccess»º³åÇøÒç¶Âí½Å¹«¸æ
°ä²¼¹¦·ò 2020-04-220x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-10607 |
ʱ ¼ä |
2020-04-22 |
|
Àà ÐÍ |
BO |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Advantech WebAccess <=8.4.2 |
0x01 ·ì϶ÏêÇé
Advantech WebAccessÊÇÖйų́ÍåÑлª£¨Advantech£©¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý½ÚÔ죬²¢ÌṩԶ³Ì½ÚÔìºÍÖÎÀí×Ô¶¯»¯É豸µÄÖ°ÄÜ¡£
Advantech WebAccess 8.4.2¼°Ö®Ç°°æ±¾ÖдæÔÚ»º³åÇøÒç¶Âí½Å£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýȷУÑéÓû§Ìá½»Êý¾ÝµÄ³¤¶È¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐдúÂë¡£CVSSÆÀ·Ö8.8¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º
https://www.advantech.com.cn/
´Ë±í£¬½¨ÒéÓйØÓû§Ó¦²ÉÈ¡µÄÆäËû°²È«·À»¤´ëÊ©ÈçÏ£º
£¨1£© ×î´óÏ޶ȵØÏ÷¼õËùÓнÚÔìϵͳÉ豸ºÍ/»òϵͳµÄÍøÂç¶³ö£¬²¢È·±£ÎÞ·¨´ÓInternet½Ó¼û£»
£¨2£© ¶¨Î»·À»ðǽ·À»¤µÄ½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸£¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀ룻
£¨3£© µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬ÇëʹÓð²È«²½Ö裬ÀýÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬²¢È·ÈÏVPN¿ÉÄÜ´æÔڵķì϶£¬Ð轫VPN¸üе½×îа汾¡£
0x03 ÓйØÐÂÎÅ
https://www.auscert.org.au/bulletins/ESB-2020.1084/
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-086-01
https://nvd.nist.gov/vuln/detail/CVE-2020-10607
https://www.cnvd.org.cn/flaw/show/CNVD-2020-19926
0x05 ¹¦·òÏß
2020-03-26 CVE°ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ