Emerson OpenEnterprise SCADA | ¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-29

0x00 ·ì϶¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Emerson OpenEnterprise SCADA

CVE-2020-6970

BO

ÑϳÁ

ÊÇ

Emerson OpenEnterprise SCADA Server 3.1-3.3.3,2.83°æ±¾

CVE-2020-10640

MA

ÑϳÁ

ÊÇ

Emerson OpenEnterprise SCADA <= 3.3.4

CVE-2020-10632

IOM

¸ßΣ

·ñ

CVE-2020-10636

IES

ÖÐΣ

·ñ


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Emerson Electric OpenEnterpriseÊÇÃÀ¹ú°¬Ä¬ÉúµçÆø£¨Emerson Electric£©¹«Ë¾µÄÒ»Ì×ÖØÒªÓÃÓÚÔ¶³ÌʯÓͺÍÌìÈ»ÆøÀûÓõÄÊý¾Ý²É¼¯Óë¼à¿ØÏµÍ³£¨SCADA£© ¡£

½üÈÕ£¬¿¨°Í˹»ùµÄ×êÑÐÈËÔ±Roman Lozko·¢ÏÖÁËEmerson OpenEnterpriseÖеÄËĸö°²È«·ì϶£¬ÕâËĸö·ì϶±ðÀëΪ»ùÓڶѵĻº³åÇøÒç³ö¡¢¶ÌȱÉí·ÝÑéÖ¤¡¢ËùÓÐȨÖÎÀí²»µ±ºÍÈõ¼ÓÃÜÎÊÌ⣬¾ßÌåÐÅÏ¢ÈçÏ£º

CVE-2020-6970ÊÇEmerson Electric OpenEnterprise SCADA ServerÖдæÔڵĻº³åÇøÒç¶Âí½Å£¬CVE-2020-10640ÊÇEmerson Electric OpenEnterpriseÖдæÔڵݲȫ·ì϶ ¡£ÒÔÉÏÁ½¸ö·ì϶¶¼±»ÆÀ¼¶Îª¡°ÑϳÁ¡±£¬Äܹ»Ê¹¹¥»÷ÕßÔÚÔËÐÐOpenEnterpriseµÄÉ豸ÉÏÒÔÌáÉýµÄÌØÈ¨Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë ¡£

CVE-2020-10632ÊÇEmerson Electric OpenEnterpriseÖдæÔڵݲȫ·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½ÎªÎļþ¼ÐÉèÖÃÁ˲»°²È«µÄȨÏÞ ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶Åú¸Ä³ÁÒªµÄÅäÖÃÎļþ£¬Ôì³Éϵͳ¹ÊÕÏ»òÒì³£ ¡£

CVE-2020-10636ÊÇEmerson Electric OpenEnterpriseÖдæÔڵļÓÃÜÎÊÌâ·ì϶ ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡OpenEnterpriseÓû§ÕÊ»§µÄÃÜÂë ¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.emerson.com/


0x03 ÓйØÐÂÎÅ


https://www.securityweek.com/vulnerabilities-found-emerson-scada-product-made-oil-and-gas-industry


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-049-02

https://www.us-cert.gov/ics/advisories/icsa-20-140-02


0x05 ¹¦·òÏß


2020-05-29 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾