Fuji Electric¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-01-290x00 ·ì϶¸ÅÊö
2021Äê01ÔÂ26ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©°ä²¼°²È«²¼¸æ£¬Åû¶Á˹¤Òµ×éÖ¯ÈÕ±¾µçÆøÉ豸¹«Ë¾Fuji Electric³ö²úµÄ²¿ÃÅSCADA / HMI²úÆ·TellusºÍV-ServerÖеĶà¸ö°²È«·ì϶¡£
0x01 ·ì϶ÏêÇé

TellusºÍV-Server ²úÆ·¿ÉÔ¶³Ì¼à¿ØºÍ½ÚÔ칤³§µÄÉ豸£¬ËüÃÇÔڹؼüµÄÔì×÷ÒµÖб»¿í·ºÑ¡È¡¡£
ÕâЩ·ì϶ÊǶÔÓû§ÌṩµÄÊý¾Ý²»×ãÕýÈ·ÑéÖ¤µ¼Öµģ¬¿ÉÄÜ´¥·¢»º³åÇøÒç³ö²¢Òò¶øµ¼ÖÂËÁÒâ´úÂëÖ´ÐС£ÀûÓÃÕâЩ·ì϶±ØÒªÓû§½»»¥£¬¹¥»÷ÕßÄܹ»Í¨¹ýÓÕÆÖ¸±êÓû§´ò¿ª¶ñÒâÏîÄ¿ÎļþÀ´´¥·¢·ì϶£¬×îÖÕÖ´ÐÐËÁÒâ´úÂë¡£
±¾´ÎÅû¶µÄ·ì϶ÈçÏ£º
CVE | ÀàÐÍ | CVSSÆÀ·Ö | ÑϳÁˮƽ |
CVE-2021-22637 | »ùÓڶѵĻº³åÇøÒç³ö | 7.8 | ¸ßΣ |
CVE-2021-22655 | Ô½½ç¶ÁÈ¡ | 7.8 | ¸ßΣ |
CVE-2021-22653 | Ô½½çдÈë | 7.8 | ¸ßΣ |
CVE-2021-22639 | ´úÂëÖ´ÐÐ | 7.8 | ¸ßΣ |
CVE-2021-22641 | »ùÓڶѵĻº³åÇøÒç³ö | 7.8 | ¸ßΣ |
Fuji Electric»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¨CVE-2021-22637£©
ÔÚÀûÓ÷¨Ê½´¦ÖÃÏîÄ¿ÎļþµÄ·½Ê½ÖдæÔÚÒ»¸ö»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»Ôì×÷Ö´ÐÐËÁÒâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ£¬ÆäCVSSÆÀ·Ö7.8¡£
Fuji ElectricÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2021-22655£©
ÔÚÀûÓ÷¨Ê½´¦ÖÃÏîÄ¿ÎļþµÄ·½Ê½ÖдæÔÚÒ»¸öÔ½½ç¶ÁÈ¡·ì϶£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»Ôì×÷Ö´ÐÐËÁÒâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ£¬ÆäCVSSÆÀ·Ö7.8¡£
Fuji ElectricÔ½½çдÈë·ì϶£¨CVE-2021-22653£©
¸Ã·ì϶´æÔÚÓÚÀûÓ÷¨Ê½´¦ÖÃÏîÄ¿ÎļþµÄ·½Ê½ÖУ¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ôì×÷¶ñÒâµÄÏîÄ¿Îļþ£¬×îÖÕÖ´ÐÐËÁÒâ´úÂ룬ÆäCVSSÆÀ·Ö7.8¡£
Fuji Electric´úÂëÖ´Ðзì϶£¨CVE-2021-22639£©
ÔÚÀûÓ÷¨Ê½´¦ÖÃÏîÄ¿ÎļþµÄ·½Ê½ÖдæÔÚδ³õʼ»¯µÄÖ¸ÕëÎÊÌ⣬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»Ôì×÷Ö´ÐÐËÁÒâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ£¬ÆäCVSSÆÀ·Ö7.8¡£
Fuji Electric»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¨CVE-2021-22641£©
ÔÚÀûÓ÷¨Ê½´¦ÖÃÏîÄ¿ÎļþµÄ·½Ê½Öз¢ÏÖÁË»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¬¹¥»÷ÕßÄܹ»Í¨¹ýÔì×÷¶ñÒâµÄÏîÄ¿ÎļþÀ´Ö´ÐÐËÁÒâ´úÂ룬ÆäCVSSÆÀ·Ö7.8¡£
Ó°ÏìÁìÓò
Tellus Lite V-Simulator£ºv4.0.10.0֮ǰµÄ°æ±¾
V-Server Lite£ºv4.0.10.0֮ǰµÄ°æ±¾
0x02 ´ëÖý¨Òé
½¨ÒéÉý¼¶ÖÁv4.0.10.0°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://felib.fujielectric.co.jp/download/details.htm?dataid=43821668&site=global&lang=en
0x03 ²Î¿¼Á´½Ó
https://securityaffairs.co/wordpress/113950/ics-scada/fuji-electric-hmi-flaws.html?utm_source=rss&utm_medium=rss&utm_campaign=fuji-electric-hmi-flaws
https://us-cert.cisa.gov/ics/advisories/icsa-21-026-01
https://felib.fujielectric.co.jp/download/details.htm?dataid=43821669&site=global&lang=en
0x04 ¹¦·òÏß
2021-01-26 CISA°ä²¼°²È«²¼¸æ
2021-01-29 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ