Rockwell Automation PLCÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-22681£©
°ä²¼¹¦·ò 2021-03-010x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-22681 | ʱ ¼ä | 2021-03-01 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò |
0x01 ·ì϶ÏêÇé

2021Äê02ÔÂ25ÈÕ£¬CISA°ä²¼°²È«²¼¸æ£¬ÃÀ¹úÂÞ¿ËΤ¶û£¨Rockwell Automation£©¹«Ë¾µÄRSLogix5000¡¢Studio 5000 Logix DesignerÈí¼þºÍRockwell Logix ControllersÖдæÔÚÒ»¸öÑϳÁµÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-22681£©£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ10.0¡£
Rockwell AutomationÊÇÈ«Çò×î´óµÄ×Ô¶¯»¯ºÍÐÅÏ¢»¯¹«Ë¾Ö®Ò»¡£RSLogix 5000ºÍStudio 5000 Logix DesignerÊÇÓÃÓÚ¹¤Òµ½ÚÔìϵͳµÄ±à³ÌÈí¼þ£¬CompactLogix¡¢DriveLogiºÍCompact GuardLogixµÈÊÇRockwell¹«Ë¾Ñз¢µÄLogix ½ÚÔìÆ÷¡£
ÓÉÓÚLogix DesignerʹÓÃÁ˲»°²È«µÄ˽ԿÀ´ÑéÖ¤Óë½ÚÔìÆ÷µÄͨѶ£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ìÏ¶ÈÆ¹ýÑéÖ¤»úÔì²¢ÓëLogix½ÚÔìÆ÷Ïνӣ¬»òÕßͨ¹ýÀûÓô˷ì϶ʹÓÃδÊÚȨµÄµÚÈý·½¹¤¾ßÀ´¸ü¸Ä½ÚÔìÆ÷µÄÅäÖûòÀûÓ÷¨Ê½´úÂ룬¶øÎÞÐè¾¹ýÉí·ÝÑéÖ¤¡£
Ó°ÏìÁìÓò
Rockwell software£º
RSLogix 5000£º°æ±¾16-20
Studio 5000 Logix Designer£º°æ±¾21¼°¸ü¸ß°æ±¾
Rockwell Logix Controllers£º
CompactLogix 1768
CompactLogix 1769
CompactLogix 5370
CompactLogix 5380
CompactLogix 5480
ControlLogix 5550
ControlLogix 5560
ControlLogix 5570
ControlLogix 5580
DriveLogix 5560
DriveLogix 5730
DriveLogix 1794-L34
Compact GuardLogix 5370
Compact GuardLogix 5380
GuardLogix 5570
GuardLogix 5580
SoftLogix 5800
0x02 ´ëÖý¨Òé
ĿǰCISAÒѾ°ä²¼Á˸÷ì϶µÄ»º½â´ëÊ©£¬ÏêÇéÇë²Î¿¼ÒÔÏÂÁ´½Ó£º
https://us-cert.cisa.gov/ics/advisories/icsa-21-056-03
¹Ù·½°²È«»ã±¨Á´½ÓÈçÏ£º
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1130301
0x03 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ics/advisories/icsa-21-056-03
https://securityaffairs.co/wordpress/115085/ics-scada/rockwell-automation-software-flaw.html?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22681
0x04 ¹¦·òÏß
2021-02-25 CISA°ä²¼°²È«²¼¸æ
2021-03-01 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ