Î÷ÃÅ×Ó¶à¿î²úÆ·Çå¾²Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-16

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10942 £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6 £¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-6568 £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬CVSS·ÖÖµ£º7.5


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


CVE-2019-10942

SCALANCE X-200: All versions
SCALANCE X-200IRT: All versions
SCALANCE X-200RNA: All versions


CVE-2019-6568

SINAMICS GH150 V4.7 (Control Unit):All versions

SINAMICS GH150 V4.8 (Control Unit):All versions < V4.8 SP2 HF6
SINAMICS GL150 V4.7 (Control Unit):All versions
SINAMICS GL150 V4.8 (Control Unit):All versions < V4.8 SP2 HF7
SINAMICS GM150 V4.7 (Control Unit):All versions
SINAMICS GM150 V4.8 (Control Unit):All versions < V4.8 SP2 HF9
SINAMICS SL150 V4.7 (Control Unit):All versions
SINAMICS SL150 V4.8 (Control Unit):All versions
SINAMICS SM120 V4.7 (Control Unit):All versions
SINAMICS SM120 V4.8 (Control Unit):All versions
SINAMICS SM150 V4.8 (Control Unit):All versions


Îó²î¸ÅÊö


Î÷ÃÅ×ÓÐû²¼Á˸ßÑÏÖØÐÔ²úÆ·Îó²îÔ¤¾¯ £¬£¬£¬°üÀ¨Ó°ÏìSCALANCE X¹¤Òµ½»Á÷»úµÄ¾Ü¾øÐ§ÀÍ£¨DoS£©Îó²îCVE-2019-10942ºÍÓ°ÏìSINAMICSת»»Æ÷WebЧÀÍÆ÷µÄ¾Ü¾øÐ§ÀÍ£¨DoS£©Îó²îCVE-2019-6568¡£¡£¡£¡£¡£¡£¡£Îó²îÐÅÏ¢ÈçÏ£º


CVE-2019-10942

¸ÃÎó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÖØ¸´ÏòTelnetЧÀÍ·¢ËÍ´ó×ÚÐÂÎŰü £¬£¬£¬µ¼ÖÂ×°±¸½øÈëDoS״̬¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ¹¥»÷Õßͨ¹ýÏòTCP 23¶Ë¿Ú·¢ËÍ´ó×ÚÊý¾Ý°üÀ´ÆÆËðtelnetЧÀÍ £¬£¬£¬×°±¸Íß½âºó»á×Ô¶¯ÖØÆô £¬£¬£¬Õâ¿ÉÄܵ¼ÖÂDZÔÚµÄÁ÷³ÌÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓøÃÎó²îÐèÒª»á¼ûÄ¿µÄ½»Á÷»úµÄÍøÂç £¬£¬£¬²¢ÇÒÖ»ÐèÒªÏàʶһЩ±ê×¼µÄtelnetЭÒé¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒѾ­È·¶¨ÁËһЩ¿ÉÄÜÖ±½ÓÊܵ½À´×Ô»¥ÁªÍø¹¥»÷µÄ×°±¸ £¬£¬£¬µ«¸ÃÎó²î²¢½ûÖ¹Ò×ʹÓà £¬£¬£¬ÓÉÓÚËü¿ÉÄÜÓÐÒ»¸ö·ÇÈ·¶¨ÐԵĸ´Öư취±»´¥·¢¡£¡£¡£¡£¡£¡£¡£


CVE-2019-6568

¸ÃÎó²îÔÊÐí¾ßÓжÔÊÜÓ°ÏìϵͳµÄÍøÂç»á¼ûȨÏ޵Ĺ¥»÷ÕßÔÚ²»ÐèÒªÉí·ÝÑéÖ¤»òÓû§½»»¥µÄÇéÐÎϵ¼Ö¾ܾøÐ§ÀÍ £¬£¬£¬µ¼ÖÂÖØÐÂÆô¶¯WebЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


CVE-2019-10942

ÏÖÔÚÎ÷ÃÅ×ÓÉÐδÕë¶Ô¸ÃÎó²îÐû²¼Èκβ¹¶¡³ÌÐò £¬£¬£¬Ïà¹ØÓû§¿Éͨ¹ýÔÚÊÜÓ°ÏìµÄ×°±¸ÉϽûÓÃTelnetЧÀÍ£¨½¨ÒéʹÓÃSSH£©ÒÔ¼°ÏÞÖÆ¶ÔTCP¶Ë¿Ú23µÄÍøÂç»á¼û £¬£¬£¬À´±ÜÃâDZÔÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£


CVE-2019-6568

ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î £¬£¬£¬¼û²Î¿¼Á´½Ó¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://cert-portal.siemens.com/productcert/pdf/ssa-100232.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-530931.pdf