Ê©Ä͵¹¤ÒµÈí¼þÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-06-04

Îó²î±àºÅ


CVE-2018-7784
CVE-2018-7785


Îó²î¼¶±ð


ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º10   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º10   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£ºU.motion server 1.3.4¼°ÒÔÏ¡£¡£¡£¡£


Îó²îÐÎò


Ê©Ä͵Â2018Äê5ÔÂ31ÈÕÐû²¼Ç徲ͨ¸æÍ¨Öª¿Í»§£¬£¬£¬£¬£¬£¬ £¬ÆìϲúÆ·U.motion builder±£´æÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²îÓ°Ï죬£¬£¬£¬£¬£¬ £¬Îó²î±àºÅΪCVE-2018-7784¡¢CVE-2018-7785£¬£¬£¬£¬£¬£¬ £¬Á½Ã¶Îó²îµÄÆÀ·Ö¾ùΪ10·Ö£¨Âú·Ö£©¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬ £¬Ê©Ä͵¹ٷ½ÒÑÍÆ³öÐÞ¸´²¹¶¡¡£¡£¡£¡£


U.motion ÊÇÒ»¿î×Ô¶¯»¯¹¹½¨½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬ £¬ÓÃÓÚÈ«ÇòÉÌÒµÉèÊ©¡¢Òªº¦ÖÆÔìÒµºÍÄÜÔ´ÐÐÒµ¡£¡£¡£¡£U.motion Builder ¹¤¾ßÄÜÈÃÓû§Îª×Ô¼ºµÄ U.motion ×°±¸½¨ÉèÏîÄ¿¡£¡£¡£¡£


Îó²îϸ½Ú


1.CVE-2018-7784£º


³ÌÐò¶ÔÌá½»µÄÊý¾Ý¹ýÂ˲»ÑÏ£¬£¬£¬£¬£¬£¬ £¬µ¼ÖÂÊäÈëµÄÊý¾Ý±»¿´³É´úÂëÖ´ÐС£¡£¡£¡£Í¨¹ýÕâ¸öÎó²î£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔÔÚ±£´æÎó²îµÄ»úеÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂ롢й¶ÐÅÏ¢»òÕßÒý·¢³ÌÐò±¨´í¡£¡£¡£¡£


2.CVE-2018-7785£º


Ô¶³ÌÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬ £¬ÓÚ±£´æÎó²îµÄÖ÷»úÖ´ÐÐí§ÒâÔ¶³ÌÏÂÁî¡£¡£¡£¡£

 

½â¾ö²½·¥


½¨ÒéÏà¹ØÓû§¾¡¿ìµ½Ê©Ä͵¹ٷ½ÍøÕ¾ÏÂÔØ²¹¶¡ÐÞ²¹Îó²î¡£¡£¡£¡£


ÏÂÔØµØµã£º


https://www.schneider-electric.com/en/download/document/Umotion_Server_update/

 

²Î¿¼×ÊÁÏ


https://www.schneider-electric.com/en/download/document/Umotion_Server_update/