Rockwell Automation | ¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-27

0x00 ·ì϶¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Rockwell Automation EDS Subsystem

CVE-2020-12034

SI

¸ßΣ

ÊÇ

FactoryTalk Linx software:6.00,6.10,6.11

RSLinx Classic <= 4.11.00

RSNetWorx software <= 28.00.00

Studio 5000 Logix Designer software <= 32

CVE-2020-12038

B0

ÖÐΣ

·ñ


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ÂÞ¿ËΤ¶û×Ô¶¯»¯ÓÐÏÞ¹«Ë¾ÊÇÈ«Çò×î´óµÄÖÂÁ¦ÓÚ¹¤Òµ×Ô¶¯»¯ÓëÐÅÏ¢µÄ¹«Ë¾Ö®Ò»  £¬ÖÂÁ¦ÓÚÔ®ÊÖ¿Í»§ÌáÓâÔ½²úÁ¦  £¬ÒÔ¼°ÊÀ½ç¿É³ÖÐø·¢Õ¹¡£

½üÈÕ  £¬¹¤ÒµÍøÂ簲ȫ¹«Ë¾ClarotyµÄ×êÑÐÈËÔ±·¢ÏÖÁËÂÞ¿ËΤ¶û²úƷʹÓõĵç×ÓÊý¾Ý±í£¨EDS£©×ÓϵͳÖеÄÁ½¸ö°²È«·ì϶  £¬·ì϶ÓëEDS×Óϵͳ½âÎöEDSÎļþÄÚÈݵķ½Ê½ÓйØ¡£EDSÎļþÔ̺¬É豸µÄÅäÖÃÊý¾Ý  £¬ÍøÂçÖÎÀí¹¤¾ß½«ÆäÓÃÓÚ±êʶºÍµ÷ÊÔ¡£¹¥»÷ÕßÄܹ»´´½¨Ò»¸ö¶ñÒâµÄEDSÎļþ  £¬ÒÔ±ãÔÚ±»ÂÞ¿ËΤ¶ûµÄÈí¼þ½âÎöºó  £¬½«WindowsÅú´¦ÖÃÎļþдÈëËÁÒâõè¾¶  £¬Ô̺¬Æô¶¯Ä¿Â¼  £¬ÕâÄܹ»µ¼Ö³ÁÐÂÆô¶¯ºóÖ´ÐдúÂë¡£

CVE-2020-12034ÊÇRockwell Automation EDS Subsystem SQL×¢Èë·ì϶¡£¸Ã·ì϶ԴÓÚEDS×ÓϵͳûÓжÔÓû§ÊäÈë½øÐгä·ÖµÄÑéÖ¤  £¬Ê¹¹¥»÷ÕßÄܹ»´´½¨¶ñÒâµÄEDSÎļþ½øÐÐSQL×¢Èë  £¬µ¼Ö»ؾø·þÎñ¡£

CVE-2020-12038ÊÇRockwell Automation EDS Subsystem »º³åÇøÒç¶Âí½Å¡£¹¥»÷ÕßÄܹ»´´½¨¶ñÒâµÄEDSÎļþʹEDSParser COM¶ÔÏó±ÀÀ£  £¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶  £¬²Î¿¼Á´½Ó£º

https://www.rockwellautomation.com/

https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1125928£¨±ØÒª×¢²á£©

ǶÈëʽ²úÆ·µÄ·ì϶»º½â´ëÊ©£º

? ÔÚ·À»ðǽ/UTMÉ豸Éϼල»òÏÞ¶ÈTCP 2222¡¢7153¶Ë¿ÚºÍUDP 44818¶Ë¿Ú¡£

ͨ³£»º½â´ëÊ©£º

? ¶¨Î»·À»ðǽ·À»¤µÄ½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸  £¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀë £»

? Ô¶³Ì½Ó¼ûʱ  £¬½¨ÒéʹÓÃÐ鹹רÓÃÍøÂ磨VPN£©  £¬²¢È·ÈÏVPN¿ÉÄÜ´æÔڵķì϶  £¬Ð轫VPN¸üе½×îа汾¡£


0x03 ÓйØÐÂÎÅ


https://www.securityweek.com/hackers-can-target-rockwell-industrial-software-malicious-eds-files


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-140-01


0x05 ¹¦·òÏß


2020-05-27 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾