Ê©ÄÍµÂµçÆø²úÆ·¶à¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-12

Îó²î±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2018-7846£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.3£¬£¬£¬£¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7849£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7843£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7844£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7848£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.9£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7842£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7847£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7850£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º5.3
CVE±àºÅ£ºCVE-2018-7845£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7852£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7853£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7854£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7855£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7856£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7857£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-6806£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½£º6.5
CVE±àºÅ£ºCVE-2018-6807£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-6808£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10.0£¬£¬£¬£¬¹Ù·½£º7.5



Ó°Ïì°æ±¾



ÊÜÓ°ÏìµÄ°æ±¾


Modicon M580ËùÓа汾
Modicon M340ËùÓа汾
Modicon QuantumËùÓа汾

Modicon PremiumËùÓа汾



Îó²î¸ÅÊö



Schneider Electric Modicon M580µÈ¶¼ÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£Schneider Electric Modicon M580ÊÇÒ»¿î¿É±à³Ì×Ô¶¯»¯¿ØÖÆÆ÷¡£¡£¡£¡£¡£Schneider Electric Modicon PremiumÊÇÒ»¿îÓÃÓÚÀëÉ¢»òÀú³ÌÓ¦ÓõĴóÐͿɱà³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©¡£¡£¡£¡£¡£Schneider Electric Modicon QuantumÊÇÒ»¿îÓÃÓÚÀú³ÌÓ¦Óᢸ߿ÉÓÃÐÔºÍÇå¾²½â¾ö¼Æ»®µÄ´óÐͿɱà³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©¡£¡£¡£¡£¡£¶à¿îSchneider Electric²úÆ·Öб£´æÈçÏÂÎó²î£º


CVE-2018-7846

´ËÎó²îΪ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸ÔÚ²»ÑéÖ¤·¢¼þÈËÕæÊµÐÔµÄÇéÐÎÏÂʹ»á»°ÎÞЧ£¬£¬£¬£¬´Ó¶øµ¼ÖÂÕýµ±×°±¸¶Ï¿ªÅþÁ¬¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7849

´ËÎó²îΪ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë¿É»Ö¸´µÄ¹ÊÕÏ״̬£¬£¬£¬£¬´Ó¶øµ¼ÖÂ×°±¸Õý³£Ö´ÐÐ×èÖ¹¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7843

´ËÎó²îΪ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬£¬£¬£¬£¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7844

´ËÎó²îΪÐÅϢй¶Îó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸·µ»ØÄÚ´æ¿é£¬£¬£¬£¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁÈ¡£¬£¬£¬£¬Ð´ÈëºÍ²¶»ñSNMPÉçÇø×Ö·û´®¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7848

´ËÎó²îΪÐÅϢй¶Îó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸·µ»Ø±à³ÌÕ½ÂԵĿ飬£¬£¬£¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁд£¬£¬£¬£¬Ð´ÈëºÍÏÝÚåSNMPÉçÇø×Ö·û´®µÄй¶¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7842

´ËÎó²îΪ²»×¼È·ÈÏÖ¤Îó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÒÔÔÊÐí¹¥»÷Õßαװ³É¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§£¬£¬£¬£¬´Ó¶ø¿ÉÒÔÈÆ¹ýÉè±¹ØÁ¬ÄÃÜÂë±£»£»£»£»£»£»¤¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7847

´ËÎó²îΪδ¾­Éí·ÝÑéÖ¤µÄÎļþдÈëÎó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁîÐòÁпÉÄܻᵼÖÂ×°±¸ÁýÕÖÆä±à³ÌÕ½ÂÔ£¬£¬£¬£¬´Ó¶ø±¬·¢ÖÖÖÖÓ°Ï죬£¬£¬£¬°üÀ¨ÉèÖÃÐ޸쬣¬£¬£¬ÔËÐÐÀú³ÌÖÐÖ¹ºÍDZÔڵĴúÂëÖ´ÐС£¡£¡£¡£¡£ ¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7850

Schneider Electric UnityProL±à³ÌÈí¼þµÄÕ½ÂÔ´«Ê书ЧÖб£´æ¿ÉʹÓõĶԲ»¿ÉÐÅÊäÈëÎó²îµÄÒÀÀµ¡£¡£¡£¡£¡£½«ÌØÖÆÕ½ÂÔ±à³Ìµ½Modicon M580¿É±à³Ì×Ô¶¯»¯¿ØÖÆÆ÷£¬£¬£¬£¬²¢Ê¹ÓÃUnityProL¶ÁÈ¡¸ÃÕ½ÂÔʱ£¬£¬£¬£¬»áÏòÓû§ÏÔʾÓë×°±¸²î±ðµÄÉèÖᣡ£¡£¡£¡£Õâµ¼ÖÂUnityProLÓû§ÎÞ·¨Ñé֤װ±¸ÊÇ·ñ°´Ô¤ÆÚÔËÐС£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7845

´ËÎó²îΪÐÅϢй¶Îó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÇëÇó¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡£¬£¬£¬£¬´Ó¶øµ¼ÖÂÃô¸ÐÐÅÏ¢µÄй¶¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7852

´ËÎó²îΪ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬£¬£¬£¬£¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢ÕâЩÎó²î¡£¡£¡£¡£¡£


CVE-2018-7853

´ËÎó²îΪ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬£¬£¬£¬£¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7854

´ËÎó²îΪ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬£¬£¬£¬£¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7855

´ËÎó²îΪ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬£¬£¬£¬£¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7856

´ËÎó²îΪ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬£¬£¬£¬£¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-7857

´ËÎó²îΪ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬£¬£¬£¬£¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-6806

´ËÎó²îΪÐÅϢй¶Îó²î¡£¡£¡£¡£¡£ ÌØÖÆµÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸·µ»ØÄÚ´æ¿é£¬£¬£¬£¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁÈ¡£¬£¬£¬£¬Ð´ÈëºÍ²¶»ñSNMPÉçÇø×Ö·û´®¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-6807

¿É±à³ÌµÄ¾Ü¾øÐ§ÀÍÎó²î±£´æÓÚSchneider Electric Modicon M580¿É±à³Ì×Ô¶¯»¯¿ØÖÆÆ÷µÄ¹Ì¼þ°æ±¾SV2.70µÄUMASдÈëϵͳλºÍ¿é¹¦Ð§ÖС£¡£¡£¡£¡£Ò»×éÌØÖÆµÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬£¬£¬£¬£¬´Ó¶øµ¼ÖÂ×°±¸Ô¶³ÌͨѶÍêÈ«×èÖ¹¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£


CVE-2018-6808

Schneider Electric Unity Pro±à³ÌÈí¼þPLCÄ£ÄâÆ÷µÄUMASÕ½ÂÔ±à³Ì¹¦Ð§Öб£´æ¿ÉʹÓõÄÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£¡£·¢Ë͵½Èí¼þPLC·ÂÕæÆ÷µÄÌØÖÆUMASÏÂÁîÐòÁпÉÒÔµ¼ÖÂÐÞ¸ÄÕ½ÂÔ±à³Ì£¬£¬£¬£¬´Ó¶øÔÚ·ÂÕæÆ÷Çл»µ½Æô¶¯Ä£Ê½Ê±Ö´ÐдúÂë¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£



Îó²îÑéÖ¤



ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£



ÐÞ¸´½¨Òé



¹Ù·½ÒÑÍÆ³ö¸üв¹¶¡£¬£¬£¬£¬Çëʵʱ¸üУºhttps://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-11+-+Modicon+Controller.pdf&p_Doc_Ref=SEVD-2019-134-11¡£¡£¡£¡£¡£



²Î¿¼Á´½Ó



https://blog.talosintelligence.com/2019/06/vulnerability-spotlight-multiple.html