Î÷ÃÅ×Ó¶à¸ö²úÆ·ÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-04-11

Îó²î±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2018-3991£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ10£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-6579£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ10£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-5379£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨



Ó°Ïì°æ±¾



SIMATIC WinCC OA Version 3.14 < P025
SIMATIC WinCC OA Version 3.15 < P018
SIMATIC WinCC OA Version 3.16 < P007
ÓµÓÐWeb Office PortalµÄSpectrum Power 4¾ùÊÜÓ°Ïì
RUGGEDCOM ROX II version < V2.13.0

snapd 2.28 ÖÁ2.37°æ±¾



Îó²î¸ÅÊö



Î÷ÃÅ×Ó£¨SIEMENS£©¹Ù·½Ðû²¼Í¨¸æÐÞ¸´ÁËÆä¶à¿î²úÆ·Öвî±ðˮƽµÄÇå¾²Îó²î£¬£¬£¬£¬ÊÜÓ°Ïì²úÆ·°üÀ¨SIMATIC WinCC OA¡¢Spectrum Power¡¢RUGGEDCOM RXO IIµÈ¡£¡£¡£¡£


SIMATIC WinCC OA Ô¶³Ì´úÂëÖ´ÐÐÎó²î ¨C CVE-2018-3991


Ó°ÏìSIMATIC WinCC OAµÄÎó²îCVE-2018-3991ÊÇÓÉÓÚ22347/TCP¶Ë¿ÚµÄ»á¼û¿ØÖƲ»µ±¶ø±¬·¢£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܻᵼÖ¶ÑÒç³ö£¬£¬£¬£¬´Ó¶øÒý·¢Ç±ÔÚµÄÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£


Spectrum Power 4.7ÏÂÁî×¢ÈëÎó²î ¨C CVE-2019-6579


ÔÚ¶Ë¿Ú80 / TCP»ò443 / TCPÉϾßÓÐÍøÂç»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔʹÓÃÖÎÀíȨÏÞÖ´ÐÐϵͳÏÂÁî¡£¡£¡£¡£


RUGGEDCOM ROX II ¨C CVE-2018-5379


ÔÚ´¦Öóͷ£Ä³Ð©ÐÎʽµÄUPDATEÐÂÎÅ£¨°üÀ¨¼¯ÈºÁбíºÍ/»òδ֪ÊôÐÔ£©Ê±£¬£¬£¬£¬Quagga BGPÊØ»¤³ÌÐò£¨bgpd£©µÄ¿¯Ðа汾¿ÉÒÔË«ÖØÊÍ·ÅÄÚ´æ¡£¡£¡£¡£ ÀֳɵĹ¥»÷¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ»ò¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£



Îó²îÑéÖ¤



ÔÝÎÞPOC¡¢EXP¡£¡£¡£¡£



ÐÞ¸´½¨Òé



Î÷ÃÅ×Ó¹Ù·½ÒѾ­Ðû²¼ÁËÏà¹Ø²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬¸ü¶àÐÅÏ¢Çë²Î¿¼£º
https://cert-portal.siemens.com/productcert/pdf/ssa-844562.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-324467.pdf

https://cert-portal.siemens.com/productcert/pdf/ssa-451142.pdf



²Î¿¼Á´½Ó



https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications