Î÷ÃÅ×ÓÁ½¿î²úÆ·ÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-09-13

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-13799£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.1£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-13807£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.6£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


SIMATIC WinCC OA Version <= 3.14

SCALANCE X300 Version < 4.0.0

SCALANCE X408 Version < 4.0.0

SCALANCE X414 ËùÓа汾


Îó²î¸ÅÊö


Î÷ÃÅ×Ó¹Ù·½Ðû²¼Í¨¸æÐÞ¸´ÁËÆäÁ½¿î²úÆ·µÄÇå¾²Îó²î£¬£¬£¬£¬ÊÜÓ°Ïì²úÆ·°üÀ¨SIMATIC WinCC OA¡¢SCALANCE X½»Á÷»ú¡£¡£¡£¡£¡£¡£


SIMATIC WinCC OAµÄÎó²îCVE-2018-13799ÊÇÓÉÓÚ5678/TCP¶Ë¿ÚµÄ»á¼û¿ØÖƲ»µ±¶ø±¬·¢£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚSIMATIC WinCC OAÇéÐÎÖÐÌáÉýÆäȨÏÞ¡£¡£¡£¡£¡£¡£


SCALANCE X½»Á÷»úµÄÎó²îCVE-2018-13807¿ÉÔÊÐí¹¥»÷Õßͨ¹ýÏòWebЧÀÍÆ÷·¢ËÍÌØÖÆÊý¾Ý°üÀ´µ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£Ê¹×°±¸×Ô¶¯ÖØÆô£¬£¬£¬£¬Ó°ÏìÆäËû×°±¸µÄÍøÂç¿ÉÓÃÐÔ¡£¡£¡£¡£¡£¡£²»¹ý¹¥»÷Õß±ØÐè¾ßÓжÔ443/TCP¶Ë¿ÚµÄÍøÂç»á¼ûÄÜÁ¦²Å»ªÊ¹ÓôËÎó²î£¬£¬£¬£¬Ê¹ÓôËÎó²î¼È²»ÐèÒªÓÐÓÃÆ¾Ö¤Ò²²»ÐèÒªÕýµ±Óû§µÄ½»»¥¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC\EXP


ÐÞ¸´½¨Òé


Î÷ÃÅ×Ó¹Ù·½ÒѾ­Ðû²¼ÁËSIMATIC WinCC OAÏà¹Ø²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬¿É´ÓÒÔÏÂÁ´½Ó»ñµÃ£º

https://portal.etm.at/index.php?option=com_content&view=category&id=67&layout=blog&Itemid=80 £¨ÒªÇóµÇ¼£©


Î÷ÃÅ×Ó»¹½¨Òé½ÓÄÉÒÔÏÂÊÖ¶¯»º½â²½·¥À´½µµÍΣº¦£º

ƾ֤ÒÔÏÂÁ´½ÓÖеİ취ÊÖ¶¯ÐÞ¸´Îó²î£º

https://portal.etm.at/patchdownload.php?fp=version_3.14/win64vc12/ReadmeP021.txt £¨ÒªÇóµÇ¼£©

×ñÕÕSIMATIC WinCC OAÇå¾²Ö¸ÄÏÒÔά»¤Çå¾²µÄSIMATIC WinCC OAÇéÐΣº

https://portal.etm.at/index.php?option=com_phocadownload&view=category&id=52:security&Itemid=81 £¨ÒªÇóµÇ¼£©

Ó¦ÓÃÉî¶È·ÀÓù£º

https://www.siemens.com/cert/operational-guidelines-industrial-security

 

Î÷ÃÅ×ÓΪSCALANCE X300ºÍSCALANCE X408Ìṩ¸üУ¬£¬£¬£¬²¢ÎªSCALANCE X414Ìṩ»º½â²½·¥¡£¡£¡£¡£¡£¡£

SCALANCE X300£º¸üÐÂÖÁ4.1.2°æ

https://support.industry.siemens.com/cs/us/en/view/109753720

SCALANCE X408£º¸üÐÂÖÁ4.1.2°æ

https://support.industry.siemens.com/cs/us/en/view/109753720

SCALANCE X414£º

Î÷ÃÅ×ÓÒÑÈ·¶¨Óû§¿ÉÒÔÓ¦ÓÃÒÔϽâ¾ö¼Æ»®»ººÍ½â²½·¥½µµÍΣº¦£º

ʹÓÃÊʵ±µÄ»úÖÆ±£»£»£»£»¤¶Ô443/TCP¶Ë¿ÚÉϼ¯³ÉµÄWebЧÀÍÆ÷µÄÍøÂç»á¼û¡£¡£¡£¡£¡£¡£

½«443/TCP¶Ë¿ÚµÄÍøÂç»á¼ûÏÞÖÆÔÚ¿ÉÐÅIPµØµãÄÚ£¬£¬£¬£¬²¢×èÖ¹ÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÔËÐÐÀ´×Ô¿ÉÐÅIPµØµãµÄÎó²îɨÃ蹤¾ß¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó

https://ics-cert.us-cert.gov/advisories/ICSA-18-254-05   https://www.siemens.com/global/en/home/products/services/cert.html#SecurityPublications