Î÷ÃÅ×Ó¶à¸ö²úÆ·ÑÏÖØÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-04-11Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-6579£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ10£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-5379£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
SIMATIC WinCC OA Version 3.15 < P018
SIMATIC WinCC OA Version 3.16 < P007
ÓµÓÐWeb Office PortalµÄSpectrum Power 4¾ùÊÜÓ°Ïì
RUGGEDCOM ROX II version < V2.13.0
snapd 2.28 ÖÁ2.37°æ±¾
Îó²î¸ÅÊö
Î÷ÃÅ×Ó£¨SIEMENS£©¹Ù·½Ðû²¼Í¨¸æÐÞ¸´ÁËÆä¶à¿î²úÆ·Öвî±ðˮƽµÄÇå¾²Îó²î£¬£¬£¬£¬ÊÜÓ°Ïì²úÆ·°üÀ¨SIMATIC WinCC OA¡¢Spectrum Power¡¢RUGGEDCOM RXO IIµÈ¡£¡£¡£¡£
SIMATIC WinCC OA Ô¶³Ì´úÂëÖ´ÐÐÎó²î ¨C CVE-2018-3991
Ó°ÏìSIMATIC WinCC OAµÄÎó²îCVE-2018-3991ÊÇÓÉÓÚ22347/TCP¶Ë¿ÚµÄ»á¼û¿ØÖƲ»µ±¶ø±¬·¢£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܻᵼÖ¶ÑÒç³ö£¬£¬£¬£¬´Ó¶øÒý·¢Ç±ÔÚµÄÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£
Spectrum Power 4.7ÏÂÁî×¢ÈëÎó²î ¨C CVE-2019-6579
ÔÚ¶Ë¿Ú80 / TCP»ò443 / TCPÉϾßÓÐÍøÂç»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔʹÓÃÖÎÀíȨÏÞÖ´ÐÐϵͳÏÂÁî¡£¡£¡£¡£
RUGGEDCOM ROX II ¨C CVE-2018-5379
Îó²îÑéÖ¤
ÔÝÎÞPOC¡¢EXP¡£¡£¡£¡£
ÐÞ¸´½¨Òé
https://cert-portal.siemens.com/productcert/pdf/ssa-844562.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-324467.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-451142.pdf
²Î¿¼Á´½Ó