ÂÞ¿ËΤ¶û×Ô¶¯»¯¹¤ÒµµçÄܱíÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-02-22

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-19615£¬ £¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬ £¬£¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ6.1£¬ £¬£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19616£¬ £¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬ £¬£¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8£¬ £¬£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÂÞ¿ËΤ¶û Allen-Bradley PowerMonitor 1000ËùÓа汾


Îó²î¸ÅÊö


PowerMonitor 1000ÊÇÒ»ÖÖÓÃÓÚ¹¤Òµ¿ØÖÆÓ¦ÓõĵçÄܼÆÁ¿×°±¸£¬ £¬£¬£¬£¬ £¬Èç·ÅµçÖÐÐÄ£¬ £¬£¬£¬£¬ £¬¹¤Òµ¿ØÖÆÃæ°åºÍµç»ú¿ØÖÆÖÐÐÄ¡£¡£¡£Ëü¿ÉÕÉÁ¿µç·ÖеĵçѹºÍµçÁ÷£¬ £¬£¬£¬£¬ £¬²¢Í¨¹ýÒÔÌ«Íø»ò´®ÐÐÍøÂ罫µçÔ´ºÍÄÜÔ´²ÎÊý´«Ë͸øFactoryTalk EnergyMetrixTM£¬ £¬£¬£¬£¬ £¬SCADAϵͳºÍ¿É±à³Ì¿ØÖÆÆ÷µÈÓ¦Óᣡ£¡£


CVE-2019-19615£¬ £¬£¬£¬£¬ £¬Ò»¸ö¿çÕ¾¾ç±¾Îó²î£¬ £¬£¬£¬£¬ £¬¿ÉÒÔÈÃÔ¶³Ì¹¥»÷Õß½«í§Òâ´úÂë×¢ÈëÄ¿µÄÓû§µÄWebä¯ÀÀÆ÷ÒÔ»ñÈ¡¶ÔÊÜÓ°Ïì×°±¸µÄ»á¼ûȨÏÞ¡£¡£¡£


CVE-2019-19616£¬ £¬£¬£¬£¬ £¬Ò»ÖÖÉí·ÝÑéÖ¤ÈÆ¹ý£¬ £¬£¬£¬£¬ £¬¿ÉÒÔÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÊðÀíÀ´ÆôÓÃͨ³£¶Ô¾ßÓÐWebÓ¦ÓóÌÐòÖÎÀíȨÏÞµÄÖ°Ô±¿ÉÓõĹ¦Ð§¡£¡£¡£ÈƹýÉí·ÝÑéÖ¤ºó£¬ £¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔ¸ü¸ÄÓû§ÉèÖúÍ×°±¸ÉèÖᣡ£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Îó²îÑéÖ¤


POC£º

ACSIµÄLuca Chiou£¬ £¬£¬£¬£¬ £¬ÔÚNCCIC£¨¹ú¼ÒÍøÂçÇå¾²ºÍͨѶ¼¯³ÉÖÐÐÄ£©Öз¢Ã÷²¢±¨¸æÕâÁ½¸öÎó²î£¬ £¬£¬£¬£¬ £¬Í¬Ê±Ò²Ðû²¼ÁËÕë¶ÔÕâÁ½¸öÎó²îµÄPOC


https://www.exploit-db.com/exploits/45928

https://www.exploit-db.com/exploits/45937


ÐÞ¸´½¨Òé


ÏÖÔÚ»¹Ã»ÓÐÕë¶ÔÕâЩȱÏݵĿÉÓÃÐÞ¸´³ÌÐò¡£¡£¡£¹Ø×¢¹ÙÍøÍøÕ¾µÄ¸üУº

https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1084790


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-19-050-04