SoftPAC | ¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-200x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
SoftPAC |
CVE-2020-12042 |
DF |
ÖÐΣ |
ÊÇ |
Opto 22 SoftPAC Project <= 9.6 |
|
CVE-2020-12046 |
DF |
ÖÐΣ |
ÊÇ |
||
|
CVE-2020-10612 |
ACE |
ÑϳÁ |
ÊÇ |
||
|
CVE-2020-10616 |
CI |
¸ßΣ |
ÊÇ |
||
|
CVE-2020-10620 |
AI |
ÑϳÁ |
ÊÇ |
0x01 ·ì϶ÏêÇé
Opto 22 SoftPAC ProjectÊÇÃÀ¹úOpto 22¹«Ë¾µÄÒ»Ì××Ô¶¯»¯Èí¼þÌ×¼þ¡£¸Ã²úÆ·¿ÉÄÜÌṩ¹¤Òµ×Ô¶¯»¯¡¢¹ý³Ì½ÚÔ졢¥Óî×Ô¶¯»¯¡¢Ô¶³Ì¼à¿Ø¡¢Êý¾Ý²É¼¯ºÍ¹¤ÒµÎïÁªÍøµÈÖ°ÄÜ¡£
SoftPACÓµÓÐÈý¸öÖØÒª×é¼þ£ºMonitor£¬´úÀíºÍÐé¹¹½ÚÔìÆ÷×ÔÉí¡£MonitorÔÊÐíÓû§Æô¶¯ºÍÖÕ³¡PAC·þÎñÒÔ¼°¸üÐÂSoftPAC¹Ì¼þ¡£´úÀíÆ¾¾Ý´ÓMonitorÊÕµ½µÄÓû§ºÅÁîÀ´ÖÎÀíSoftPAC PLC¡£µ«ÊÇÔÚÊʵ±µÄÇé¿öÏ£¬¹¥»÷ÕßÄܹ»Í¨¹ý±í²¿Ô¶³ÌÏÎ½Ó¶ÔÆä½øÐаѳ֣¬Ïê¼ûÏÂͼ£º
½üÈÕClaroty×êÑÐÔ±Åû¶Opto 22 SoftPACÖдæÔÚÎå¸ö°²È«·ì϶£¬¾ßÌåÈçÏ£º
CVE-2020-12042ÊÇÊý¾ÝαÔìÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Î´¶Ï¸ùÓÃÓÚ¸üÐÂSoftPAC¹Ì¼þµÄzipÎļþÖÐÖ¸¶¨µÄõè¾¶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñµÃËÁÒâÎļþдÈëȨÏÞ¡£
CVE-2020-12046ÊÇÊý¾ÝαÔìÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓڹ̼þ¸üÐÂʱδÑéÖ¤ÎļþÊðÃû¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÓöñÒâÎļþ´úÌæºÏ·¨µÄ¹Ì¼þÎļþ¡£
CVE-2020-10612ÊǽӼû½ÚÔìÃýÎó·ì϶£¬¸Ã·ì϶ԴÓÚSoftPACAgentͨ¹ý22000ÍøÂç¶Ë¿ÚÓëSoftPACMonitor½øÐÐͨѶ£¬µ«·¨Ê½²¢Ã»ÓжÔÕâһʢ¿ªµÄ¶Ë¿Ú½øÐÐÈκÎÏÞ¶È¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½ÚÔìSoftPACAgent·þÎñ£¬Ô̺¬¸üÐÂSoftPAC¹Ì¼þ£¬Æô¶¯»òÖÕ³¡·þÎñ»òдÈëijЩע²á±íÖµ¡£
CVE-2020-10616ÊÇ´úÂëÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓÚSoftPACδָ¶¨¶à¸öµ¼Èë.dllÎļþµÄõè¾¶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶´úÌæÎļþ²¢Ö´ÐдúÂë¡£
CVE-2020-10620ÊÇÊÚȨÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓÚÓëSoftPAC½øÐÐͨѶʱ²¢²»±ØÒªÈÎºÎÆ¾Ö¤¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ֱ½ÓÓëSoftPACͨѶ£¬Ô̺¬Ô¶³ÌÖÕ³¡·þÎñ¡£
ÀûÓÃÕâЩCVE½øÐй¥»÷µÄMITER ATT&CK·ÖÀàÔ̺¬£º
0x02 ´ëÖý¨Òé
ÓÉÓÚÉÏÊö·ì϶½öÓ°Ïì9.6ºÍ¸üµÍ°æ±¾µÄSoftPAC Project£¬Òò¶øÄܹ»Í¨¹ý¸üÐÂÖÁ×îа汾µÄSoftPAC Project Professional»òSoftPAC Project BasicÀ´»º½âÕâЩ·ì϶¡£
https://www.opto22.com/support/resources-tools/downloads/pac_project_basic?ext=
һʱ´ëÊ©£ºÈôÊǴ˸üÐÂÎÞ·¨µ±¼´ÉúЧ£¬½¨Òé²ÉÈ¡ÒÔÏ´ëÊ©À´×î´óˮƽµØÏ÷¼õÔÚÄúµÄ»·¾³ÖÐÀûÓÃÕâЩ·ì϶µÄ¿ÉÄÜÐÔ£º
? ÔÚ·À»ðǽÉϼල»òÏÞ¶ÈTCP¶Ë¿Ú22000£»
? ×î´óÏ޶ȵØÏ÷¼õËùÓнÚÔìϵͳÉ豸ºÍ/»òϵͳµÄÍøÂç¶³ö£¬²¢È·±£ÎÞ·¨´ÓInternet½Ó¼û£»
? ¶¨Î»·À»ðǽ·À»¤µÄ½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸£¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀ룻
? µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬ÇëʹÓð²È«²½Ö裬ÀýÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬²¢È·ÈÏVPN¿ÉÄÜ´æÔڵķì϶£¬Ð轫VPN¸üе½×îа汾¡£
0x03 ÓйØÐÂÎÅ
https://www.securityweek.com/vulnerabilities-softpac-virtual-controller-expose-ot-networks-attacks
0x04 ²Î¿¼Á´½Ó
https://blog.claroty.com/software-based-plc-vulnerabilities-enable-remote-code-execution
https://www.us-cert.gov/ics/advisories/icsa-20-135-01
0x05 ¹¦·òÏß
2020-05-20 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ