GE URϵÁжà¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-03-24

0x00 ·ì϶¸ÅÊö

2021Äê03ÔÂ16ÈÕ£¬CISA°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËGE£¨Í¨ÓÃµçÆø¹«Ë¾£©URϵÁУ¨µçÔ´ÖÎÀíÉ豸£¬ÖØÒªÓÃÓÚ½ÚÔìºÍ±£»¤¸÷ÀàÉ豸µÄ¹¦ºÄ£©ÖеĶà¸ö°²È«·ì϶¡£³É¹¦ÀûÓÃÕâЩ·ì϶µÄ¹¥»÷Õß¿ÉÄܽӼûÃô¸ÐÐÅÏ¢¡¢³ÁÆôUR¡¢ÌáÉýȨÏÞ»òµ¼Ö»ؾø·þÎñ¡£

 

0x01 ·ì϶ÏêÇé

image.png

 

±¾´Î¹«¿ªµÄURÉ豸Öеķì϶ÈçÏ£º

CVE-ID

CVSSÆÀ·Ö

ÀàÐÍ

ÏêÇé

CVE-2016-2183 CVE-2013-2566

7.5

¼ÓÃÜÇ¿¶È²»¼°

ÔÚUR¹Ì¼þ°æ±¾8.1x֮ǰ£¬UR SSHͨѶʹÓÃÈõ¼ÓÃܺÍMACËã·¨¡£

CVE-1999-1085

5.3

»á»°¹Ì¶¨

ÔÚ7.4x¹Ì¼þ°æ±¾Ö®Ç°£¬UR½öÖ§³ÖSSHv2¡£´Ó¹Ì¼þ°æ±¾7.4xÆðÍ·£¬URÖ§³ÖÓµÓÐÒÑÖª·ì϶µÄSSHv1£¨SSHºÍ̸»á»°ÃÜÔ¿¼ìË÷ºÍ²åÈë¹¥»÷£©¡£

CVE-2021-27422

7.5

ÐÅϢй¶

UR over HTTPºÍ̸֧³ÖWeb·þÎñÆ÷½Ó¿Ú£¬Ëü¿ÉÄܵ¼ÖÂδ¾­Éí·ÝÑé֤й¼ûô¸ÐÐÅÏ¢¡£

CVE-2021-27418

5.3

ÊäÈëÑéÖ¤²»ÕýÈ·

URÖ§³ÖÓµÓÐÖ»¶Á½Ó¼ûȨÏÞµÄWeb½çÃæ¡£ÓÉÓÚÉ豸ÎÞ·¨ÕýÈ·ÑéÖ¤ÊäÈ룬´Ó¶ø¿ÉÄܵ¼ÖÂXSS¹¥»÷£¬¸Ã¹¥»÷¿ÉÓÃÓÚ·¢ËͶñÒâ¾ç±¾¡£Áí±í£¬UR¹Ì¼þWeb·þÎñÆ÷²»ºÏÓû§ÌṩµÄ×Ö·û´®Ö´ÐÐHTML±àÂë¡£

CVE-2021-27420

5.3

ÊäÈëÑéÖ¤²»ÕýÈ·

UR Firmware Web·þÎñÆ÷¹¤×÷ûÓÐÕýÈ·´¦Öýӹܲ»Ö§³ÖµÄHTTP verbs£¬µ¼ÖÂWeb·þÎñÆ÷Ôڽӹܵ½Ò»ÏµÁв»Ö§³ÖµÄHTTPÒªÇóºóÁÙʱ²»ÏìÓ¦¡£µ±ÎÞÏìӦʱ£¬Web·þÎñÆ÷ÊDz»³É½Ó¼ûµÄ¡£

CVE-2021-27428

7.5

ÎļþÉÏ´«

UR IEDÖ§³ÖʹÓÃUR SetupÅäÖù¤¾ß--Enervista UR SetupÉý¼¶¹Ì¼þ¡£¸ÃUR Setup¹¤¾ßÔÚÉÏ´«UR IED֮ǰÑéÖ¤¹Ì¼þÎļþµÄÕæÊµÐÔºÍÆëÈ«ÐÔ¡£¹¥»÷ÕßÄܹ»ÔÚûÓÐÊʵ±È¨ÏÞµÄÇé¿öÏÂÉý¼¶¹Ì¼þ¡££¨¹Ì¼þ8.10°æ±¾ÖÐÀûÓûº½â´ëÊ©¡££©

CVE-2021-27426

9.8

²»°²È«µÄĬÈϱäÁ¿³õʼ»¯

¾ßÓÓ×°Basic¡±°²È«ÐÔ±äÌåµÄUR IED²»ÔÊÐí½ûÓá°Factory Mode¡±£¬¸ÃģʽÓÃÓÚΪ¡°Factory¡±Óû§Î¬½¨IED¡£

CVE-2021-27424

5.3

ÐÅϢй¶

×÷ΪͨѶָÄϵÄÒ»²¿ÃÅ£¬UR¹²ÏíMODBUSÄÚ´æÓ³Éä¡£GEÊÕµ½ ¡°Last-key pressed¡±µÄMODBUS¼Ä·ÅÆ÷Äܹ»±»ÓÃÀ´»ñȡδ¾­ÊÚȨµÄÐÅÏ¢¡£

CVE-2021-27430

8.4

Ó²±àÂëÆ¾Ö¤

UR bootloader¶þ½øÔì°æ±¾7.00¡¢7.01ºÍ7.02Ô̺¬Î´Ê¹ÓõÄÓ²±àÂëÆ¾Ö¤¡£´Ë±í£¬¿ÉÄÜÎïÀí½Ó¼ûUR IEDµÄÓû§Äܹ»Í¨¹ý³ÁÐÂÆô¶¯URÀ´ÖÐ¶ÏÆô¶¯ÐòÁС£

  

Ó°ÏìÁìÓò

GE URϵÁУ¨B30¡¢B90¡¢C30¡¢C60¡¢C70¡¢C95¡¢D30¡¢D60¡¢F35¡¢F60¡¢G30¡¢G60¡¢L30¡¢L60¡¢L90¡¢M60¡¢N60¡¢T35¡¢T60£©£º

SSHÓйصķì϶£º¹Ì¼þ°æ±¾7.4x-08.0x£¨CyberSentryÑ¡Ï

Web·þÎñÆ÷·ì϶£º8.1x֮ǰµÄËùÓй̼þ°æ±¾

¹Ì¼þÉÏ´«£ºÓµÓиù»ù°²È«ÐÔÑ¡ÏîµÄ8.1x֮ǰµÄËùÓй̼þ°æ±¾

½ûÓóö³§Ä£Ê½£ºÓµÓиù»ù°²È«ÐÔÑ¡ÏîµÄ8.1x֮ǰµÄËùÓй̼þ°æ±¾

½Ó¼û¡°Last-key pressed¡±µÄ¼Ä·ÅÆ÷£ºÓµÓиù»ù°²È«ÐÔÑ¡ÏîµÄ8.1x֮ǰµÄËùÓй̼þ°æ±¾

UR Bootloader¶þ½øÔìÎļþ£º7.03/7.04֮ǰµÄËùÓÐBootloader°æ±¾

 

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´£¬½¨Ò齫URÉ豸¸üÐÂΪUR¹Ì¼þ°æ±¾8.10»ò¸ü¸ß°æ±¾¡£¸ü¶àÐÅÏ¢Çë²Î¿¼CISA¹Ù·½¹«¸æ¡£

ÓйØÁ´½Ó£º

https://www.gegridsolutions.com/Passport/Login.aspx

 

0x03 ²Î¿¼Á´½Ó

https://us-cert.cisa.gov/ics/advisories/icsa-21-075-02

https://securityaffairs.co/wordpress/115881/security/cisa-ge-power-management-devices-flaws.html?

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27426

 

0x04 ¹¦·òÏß

2021-03-16  CISA°ä²¼°²È«²¼¸æ

2021-03-24  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png