Ê©Ä͵¹¤ÒµÈí¼þÑÏÖØÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-06-04Îó²î±àºÅ
CVE-2018-7784
CVE-2018-7785
Îó²î¼¶±ð
ÑÏÖØ ³§ÉÌ×ÔÆÀ£º10 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÑÏÖØ ³§ÉÌ×ÔÆÀ£º10 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾£ºU.motion server 1.3.4¼°ÒÔÏ¡£¡£¡£¡£
Îó²îÐÎò
Ê©Ä͵Â2018Äê5ÔÂ31ÈÕÐû²¼Ç徲ͨ¸æÍ¨Öª¿Í»§£¬£¬£¬£¬£¬£¬£¬ÆìϲúÆ·U.motion builder±£´æÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²îÓ°Ï죬£¬£¬£¬£¬£¬£¬Îó²î±àºÅΪCVE-2018-7784¡¢CVE-2018-7785£¬£¬£¬£¬£¬£¬£¬Á½Ã¶Îó²îµÄÆÀ·Ö¾ùΪ10·Ö£¨Âú·Ö£©¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬Ê©Ä͵¹ٷ½ÒÑÍÆ³öÐÞ¸´²¹¶¡¡£¡£¡£¡£
U.motion ÊÇÒ»¿î×Ô¶¯»¯¹¹½¨½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÈ«ÇòÉÌÒµÉèÊ©¡¢Òªº¦ÖÆÔìÒµºÍÄÜÔ´ÐÐÒµ¡£¡£¡£¡£U.motion Builder ¹¤¾ßÄÜÈÃÓû§Îª×Ô¼ºµÄ U.motion ×°±¸½¨ÉèÏîÄ¿¡£¡£¡£¡£
Îó²îϸ½Ú
1.CVE-2018-7784£º
³ÌÐò¶ÔÌá½»µÄÊý¾Ý¹ýÂ˲»ÑÏ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÊäÈëµÄÊý¾Ý±»¿´³É´úÂëÖ´ÐС£¡£¡£¡£Í¨¹ýÕâ¸öÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚ±£´æÎó²îµÄ»úеÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂ롢й¶ÐÅÏ¢»òÕßÒý·¢³ÌÐò±¨´í¡£¡£¡£¡£
2.CVE-2018-7785£º
Ô¶³ÌÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ÓÚ±£´æÎó²îµÄÖ÷»úÖ´ÐÐí§ÒâÔ¶³ÌÏÂÁî¡£¡£¡£¡£
½â¾ö²½·¥
½¨ÒéÏà¹ØÓû§¾¡¿ìµ½Ê©Ä͵¹ٷ½ÍøÕ¾ÏÂÔØ²¹¶¡ÐÞ²¹Îó²î¡£¡£¡£¡£
ÏÂÔØµØµã£º
https://www.schneider-electric.com/en/download/document/Umotion_Server_update/
²Î¿¼×ÊÁÏ
https://www.schneider-electric.com/en/download/document/Umotion_Server_update/