B&R AutomatioºÍmbConnect | ¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-10-02

0x00 ·ì϶¸ÅÊö

Ëæ×ÅÒßÇéµÄÊ¢ÐУ¬Ô½À´Ô½¶àµÄ¹«Ë¾ÒÀ¸½Ô¶³Ì½Ó¼ûϵͳÀ´ÊØ»¤Æä¹¤Òµ³ö²ú£¬¹¤ÒµÔ¶³Ì½Ó¼ûϵͳµÄʹÓÃÒ²Ô½À´Ô½ÆµÈÔ¡£½üÈÕOTORIOµÄ×êÑÐÈËÔ±×î½ü·¢ÏÖÁËB&R AutomatioµÄSiteManagerºÍGateManager£¬ÒÔ¼°mbConnectµÄmbConnect24ÕâÁ½ÖÖÊ¢ÐеĹ¤ÒµÔ¶³Ì½Ó¼ûϵͳ´æÔÚ¶à¸öÑϳÁ°²È«·ì϶¡£ÕâЩ·ì϶Äܹ»±»¹¥»÷ÕßÓÃÀ´½Ó¼û¹¤Òµ³ö²ú³µ¼ä¡¢ÈëÇÖ¹«Ë¾ÍøÂç¡¢´Û¸ÄÊý¾Ý»òÇÔÈ¡Ãô¸ÐµÄóÒ×°ÂÃØµÈ¡£

 

0x01 ·ì϶ÏêÇé

 image.png

 

SiteManagerºÍGateManagerÊÇB&R Automatio¹«Ë¾°²È«Ô¶³ÌÊØ»¤Ì×¼þµÄÒ»²¿ÃÅ¡£mbConnectµÄmbConnect24ÖØÒªÓÃÓÚÓ빤ҵ×ʲúµÄÔ¶³ÌÏνÓ¡£ËüÃǹ²Í¬ÎªÆû³µ¡¢ÄÜÔ´¡¢Ê¯ÓͺÍÌìÈ»Æø¡¢½ðÊô¡¢°ü×°ºÍº£Ô˵ÈÐÐÒµµÄÊýǧ¸öÕ¾µãÌṩԶ³Ì½Ó¼û·þÎñ¡£

SiteManagerºÍGateManagerÄܹ»Ê¹×¨Òµ²Ù×÷ÈËÔ±´ÓÊÀ½çÈκδ¦ËùÔ¶³Ì½Ó¼ûºÍÊØ»¤¹¤Òµ»úе£¬Èç¼ìË÷ÈÕÖ¾ºÍÀûÓ÷¨Ê½Êý¾ÝµÈ¡£Õâ´ÎÉæ¼°µÄÁù¸öµÄSiteManagerºÍGateManager°²È«·ì϶ÈçÏ£º

 

·ì϶±àºÅ

·ì϶ÀàÐÍ

·ì϶¼òÊö

ÑϳÁˮƽ

ÆÀ·Ö

CVE-2020-11641

õè¾¶±éÀú

¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Ö°Äܹ»¶ÁÈ¡·þÎñÅäÖÃºÍÆäËûÃô¸ÐÐÅÏ¢£¬²¢ÀÄÓôËÐÅÏ¢½øÐÐSiteManagerÊ·ýÉϵĶñÒâ»î¶¯¡£

¸ß

7.7

CVE-2020-11642

×ÊÔ´¿÷Ëð²»ÊܽÚÔì

¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÄܻᷴ¸´´¥·¢SiteManagerÊ·ýµÄ³ÁÐÂÆô¶¯£¬´Ó¶øÏÞ¶È¿ÉÓÃÐÔ¡£

¸ß

7.7

CVE-2020-11643

ÐÅϢй¶

¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÍøÂçÓйØÊôÓÚ±í¹ú×éÖ¯µÄÉ豸µÄÐÅÏ¢£¬²¢½«ÕâЩÐÅÏ¢ÓÃÓÚ¶ñÒâ»î¶¯¡£

ÖÐ

6.5

CVE-2020-11644

Éí·ÝÑéÖ¤²»ÕýÈ·

¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÑ¡ÔñµÄÐé¹¹ÉóºËÐÂÎÅ/¾¯±¨À´ºýŪ±íÓòÓû§¡£

ÖÐ

6.5

CVE-2020-11645

×ÊÔ´¿÷Ëð²»ÊܽÚÔì

¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÄܻᷴ¸´´¥·¢GateManagerÊ·ýµÄ³ÁÆô£¬´Ó¶øÏÞ¶ÈÁËËüÃǵĿÉÓÃÐÔ¡£

ÖÐ

6.5

CVE-2020-11646

ÐÅϢй¶

¾­¹ýÉí·ÝÑéÖ¤µÄµÐÊÖÄܹ»²é¿´ÓйØÊôÓÚÆäÓòµÄËùÓÐÉ豸µÄÐÅÏ¢£¬²¢½«´ËÐÅÏ¢ÓÃÓÚ¶ñÒâ»î¶¯¡£  

ÖÐ

4.3

 

¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃÕâ6¸öзì϶»ñµÃϵͳµÄÊÚȨ½Ó¼ûȨÏÞ¡¢²é¿´ÆäËûÓû§µÄ×ʲúºÍÃô¸ÐÐÅÏ¢¡£´Ë±í£¬ºÚ¿Í»¹Äܹ»Í¨¹ýʹÓÃÐéαµÄϵͳÐÂÎź;¯±¨½«Óû§ºýŪµ½¶ñÒâµÄ±í²¿Õ¾µã£¬²¢´¥·¢GateManagerºÍSiteManagerµÄ³ÁÐÂÆô¶¯£¬×îÖÕµ¼Ö³ö²úϵͳµÄ¿ÉÓÃÐÔ½µÂä²¢ÖÕ³¡³ö²ú¡£

Ó°ÏìÁìÓò

SiteManager v9.2.620236042֮ǰµÄËùÓа汾

GateManager 4260ºÍ9250 v9.0.20262֮ǰµÄËùÓа汾

GateManager 8250 v9.2.620236042֮ǰµÄËùÓа汾

¸ü¶à¾ßÌåÐÅÏ¢Çë²Î¿¼£º

https://us-cert.cisa.gov/ics/advisories/icsa-20-273-03

 

Õâ´Î»¹·¢ÏÖÁËmymbCONNECT24ºÍmbCONNECT24ÖеĶà¸ö°²È«·ì϶£¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ʹÓÃSQL×¢Èë½Ó¼ûËÁÒâÐÅÏ¢£¬Í¨¹ýÖ´ÐпçÕ¾µãÒªÇóαÔ죨CSRF£©À´ÇÔÈ¡»á»°¾ßÌåÐÅÏ¢£º

·ì϶±àºÅ

·ì϶ÀàÐÍ

·ì϶¼òÊö

ÑϳÁˮƽ

ÆÀ·Ö

CVE-2020-24569

SQL×¢Èë

knximport×é¼þÖдæÔÚÒ»¸öSQLäעעÈë·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼ûËÁÒâÐÅÏ¢¡£

¸ß

7.1

CVE-2020-24568

SQL×¢Èë

lancompenent×é¼þÖдæÔÚÒ»¸öSQLäעעÈë·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼ûËÁÒâÐÅÏ¢¡£

¸ß

7.1

CVE-2020-24570

CSRF

com_mb24proxyÄ£¿éÖдæÔÚÒ»¸öSSRFºÍCSRF·ì϶£¬¹¥»÷ÕßÄܹ»Ê¹ÓöñÒâµÄÁ´½Ó´ÓµÇ¼µÄÓû§ÄÇÀïÇÔÈ¡»á»°ÐÅÏ¢¡£

¸ß

8.8

δ·ÖÅä

ºÅÁî×¢Èë

¹¥»÷Õß¿ÉÄÜ»áÀûÓÃÓë¸ÃÈí¼þ°ó¸¿ÔÚһ·µÄ¹ýÆÚÇÒδʹÓõĵÚÈý·½Èí¼þÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£

¸ß

9.8

 

Ó°ÏìÁìÓò

mymbCONNECT24 v2.6.1¼°¸üµÍ°æ±¾

mbCONNECT24 v2.6.1¼°¸üµÍ°æ±¾

¸ü¶à¾ßÌåÐÅÏ¢Çë²Î¿¼£º

https://us-cert.cisa.gov/ics/advisories/icsa-20-273-01

 

 

0x02 ´ëÖý¨Òé

1.ĿǰÓйطì϶Òѱ»½¨¸´£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾¡£

GateManagerºÍSiteManager£º

SiteManager v9.2.620236042

GateManager 4260ºÍ9250 v9.0.20262

GateManager 8250 v9.2.620236042

ÏÂÔØÁ´½Ó£º

https://www.br-automation.com/en/downloads/

 

ymbCONNECT24ºÍmbCONNECT24£º

¸üе½°æ±¾2.6.2»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://downloadportal.mbconnectline.com/en/

 

0x03 ²Î¿¼Á´½Ó

https://www.otorio.com/news-events/press-release/otorio-discovers-critical-vulnerabilities-in-leading-industrial-remote-access-software-solutions/

https://www.br-automation.com/downloads_br_productcatalogue/assets/1600003183751-de-original-1.0.pdf

https://us-cert.cisa.gov/ics/advisories/icsa-20-273-01

https://us-cert.cisa.gov/ics/advisories/icsa-20-273-03

https://securityaffairs.co/wordpress/108946/hacking/vulnerable-exchange-servers.html?utm_source=rss&utm_medium=rss&utm_campaign=vulnerable-exchange-servers

 

0x04 ¹¦·òÏß

2020-09-30  OTORIO°ä²¼°²È«²¼¸æ

2020-10-02  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



 image.png