Rockwell Automation | ¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-270x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
Rockwell Automation EDS Subsystem |
CVE-2020-12034 |
SI |
¸ßΣ |
ÊÇ |
FactoryTalk Linx software:6.00,6.10,6.11 RSLinx Classic <= 4.11.00 RSNetWorx software <= 28.00.00 Studio 5000 Logix Designer software <= 32 |
|
CVE-2020-12038 |
B0 |
ÖÐΣ |
·ñ |
0x01 ·ì϶ÏêÇé
ÂÞ¿ËΤ¶û×Ô¶¯»¯ÓÐÏÞ¹«Ë¾ÊÇÈ«Çò×î´óµÄÖÂÁ¦ÓÚ¹¤Òµ×Ô¶¯»¯ÓëÐÅÏ¢µÄ¹«Ë¾Ö®Ò»£¬ÖÂÁ¦ÓÚÔ®ÊÖ¿Í»§ÌáÓâÔ½²úÁ¦£¬ÒÔ¼°ÊÀ½ç¿É³ÖÐø·¢Õ¹¡£
½üÈÕ£¬¹¤ÒµÍøÂ簲ȫ¹«Ë¾ClarotyµÄ×êÑÐÈËÔ±·¢ÏÖÁËÂÞ¿ËΤ¶û²úƷʹÓõĵç×ÓÊý¾Ý±í£¨EDS£©×ÓϵͳÖеÄÁ½¸ö°²È«·ì϶£¬·ì϶ÓëEDS×Óϵͳ½âÎöEDSÎļþÄÚÈݵķ½Ê½Óйء£EDSÎļþÔ̺¬É豸µÄÅäÖÃÊý¾Ý£¬ÍøÂçÖÎÀí¹¤¾ß½«ÆäÓÃÓÚ±êʶºÍµ÷ÊÔ¡£¹¥»÷ÕßÄܹ»´´½¨Ò»¸ö¶ñÒâµÄEDSÎļþ£¬ÒÔ±ãÔÚ±»ÂÞ¿ËΤ¶ûµÄÈí¼þ½âÎöºó£¬½«WindowsÅú´¦ÖÃÎļþдÈëËÁÒâõè¾¶£¬Ô̺¬Æô¶¯Ä¿Â¼£¬ÕâÄܹ»µ¼Ö³ÁÐÂÆô¶¯ºóÖ´ÐдúÂë¡£
CVE-2020-12034ÊÇRockwell Automation EDS Subsystem SQL×¢Èë·ì϶¡£¸Ã·ì϶ԴÓÚEDS×ÓϵͳûÓжÔÓû§ÊäÈë½øÐгä·ÖµÄÑéÖ¤£¬Ê¹¹¥»÷ÕßÄܹ»´´½¨¶ñÒâµÄEDSÎļþ½øÐÐSQL×¢È룬µ¼Ö»ؾø·þÎñ¡£
CVE-2020-12038ÊÇRockwell Automation EDS Subsystem »º³åÇøÒç¶Âí½Å¡£¹¥»÷ÕßÄܹ»´´½¨¶ñÒâµÄEDSÎļþʹEDSParser COM¶ÔÏó±ÀÀ££¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²Î¿¼Á´½Ó£º
https://www.rockwellautomation.com/
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1125928£¨±ØÒª×¢²á£©
ǶÈëʽ²úÆ·µÄ·ì϶»º½â´ëÊ©£º
? ÔÚ·À»ðǽ/UTMÉ豸Éϼල»òÏÞ¶ÈTCP 2222¡¢7153¶Ë¿ÚºÍUDP 44818¶Ë¿Ú¡£
ͨ³£»º½â´ëÊ©£º
? ¶¨Î»·À»ðǽ·À»¤µÄ½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸£¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀ룻
? Ô¶³Ì½Ó¼ûʱ£¬½¨ÒéʹÓÃÐ鹹רÓÃÍøÂ磨VPN£©£¬²¢È·ÈÏVPN¿ÉÄÜ´æÔڵķì϶£¬Ð轫VPN¸üе½×îа汾¡£
0x03 ÓйØÐÂÎÅ
https://www.securityweek.com/hackers-can-target-rockwell-industrial-software-malicious-eds-files
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-140-01
0x05 ¹¦·òÏß
2020-05-27 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ