ABB PLCÑÏÖØÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-12-19Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-18995£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18997£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 7.1£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
GATE-E1 (EOL 2013)
GATE-E2 (EOL OCT 2018)
Îó²î¸ÅÊö
Ñо¿Ö°Ô±ÔÚÈðÊ¿¹¤ÒµÊÖÒÕ¹«Ë¾ ABB Éú²úµÄÄ³Ð©Íø¹Ø²úÆ·Öз¢Ã÷ÁËÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬µ«ÓÉÓÚ²úÆ·µÄÉúÃüÖÜÆÚ¿¢Ê£¬£¬£¬£¬£¬£¬Òò´Ë³§É̽«²»»áÍÆ³ö²¹¶¡¡£¡£¡£¡£
Applied Risk¹«Ë¾±¾ÖÜÐû²¼Ç徲ͨ¸æÌåÏÖ£¬£¬£¬£¬£¬£¬ABB Éú²úµÄ Pluto Íø¹Ø²úÆ·Öб£´æÁ½¸öÑÏÖØÎó²î¡£¡£¡£¡£ÊÜÓ°ÏìµÄÍø¹ØÊÇ GATE-E1 ºÍ GATE-E2£¬£¬£¬£¬£¬£¬ËüÃǿɵ¼Ö ABB ¹«Ë¾µÄ¿É±à³ÌÇå¾²¿ØÖÆÆ÷£¨Çå¾² PLCs£©ºÍÆäËü¿ØÖÆÏµÍ³Í¨Ñ¶¡£¡£¡£¡£
Ñо¿Ö°Ô±Ö¸³ö£¬£¬£¬£¬£¬£¬ÕâЩװ±¸µÄÖÎÀíÔ± telnet ºÍ web ½Ó¿ÚÉÏȱÉÙÈÏÖ¤»úÖÆ£¬£¬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßÈÝÒ×»ñÈ¡ÊÚȨȨÏÞ¡£¡£¡£¡£¸ÃȱÏݱ» Applied Risk ¹«Ë¾ºÍ ABB ¹«Ë¾¾ùÆÀΪ¡°ÑÏÖØ¡±Æ·¼¶£¬£¬£¬£¬£¬£¬¿É±»ÓÃÓÚÐÞ¸Ä×°±¸ÉèÖò¢Í¨¹ýÒ»Á¬ÖØÖòúÆ·µÄÒªÁìÒý·¢¾Ü¾øÐ§ÀÍÌõ¼þ¡£¡£¡£¡£
ABB ¹«Ë¾Ú¹Êͳƣ¬£¬£¬£¬£¬£¬¡°¸ÃÎó²îÊÇÒò²úÆ·ÖÐȱ·¦ÈÏÖ¤Ö§³Öµ¼Öµġ£¡£¡£¡£µ±¿ª·¢²úƷʱ£¬£¬£¬£¬£¬£¬²¢Î´Éè¼ÆÌṩÇ徲ЧÀÍÈçÈÏÖ¤¡£¡£¡£¡£¡±
Applied Risk¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¿ÉÔâÔ¶³ÌʹÓ㬣¬£¬£¬£¬£¬²¢ÇÒÈôÊÇÍøÂçÉèÖÃÁËÕâÀà»á¼ûȨÏÞÔò¿ÉÄÜͨ¹ý»¥ÁªÍø±»Ê¹Óᣡ£¡£¡£
ABB ¹«Ë¾ÎªÈÏ֤ȱʧºÍ XSS Îó²îÇéÐÎÐû²¼Ç徲ͨ¸æ¡£¡£¡£¡£¸Ã¹«Ë¾¼û¸æ¿Í»§³Æ£¬£¬£¬£¬£¬£¬²úÆ·ÒÑÊÙÖÕÕýÇÞ£¬£¬£¬£¬£¬£¬Òò´Ë½«²»»áÍÆ³öÈκι̼þ¸üС£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬Óû§Ó¦µ±»áÊÕµ½¹ØÓÚÔõÑù±£»£»£»£»¤×°ÖóÌÐòÇå¾²µÄÖ¸ÄÏÓʼþ¡£¡£¡£¡£
ÏÖÔÚÉÐδÓÐÖ¤¾ÝÅú×¢£¬£¬£¬£¬£¬£¬ÕâЩȱÏÝÒѱ»¶ñÒâʹÓᣡ£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ABB½«²»»áÐû²¼¸üеĹ̼þ£¬£¬£¬£¬£¬£¬ÓÉÓÚGATE-E1ºÍGATE-E2¶¼ÒѵִïʹÓÃÊÙÃü£¨EOL£©¡£¡£¡£¡£ ABB½¨ÒéʵÑé×ÝÉî·ÀÓùÔÔò£¬£¬£¬£¬£¬£¬ÒÔ×î´óÏ޶ȵؽµµÍÎó²î±»Ê¹ÓõÄΣº¦¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://ics-cert.us-cert.gov/advisories/ICSA-18-352-01
https://www.securityweek.com/serious-flaws-found-abb-safety-plc-gateways


¾©¹«Íø°²±¸11010802024551ºÅ