EZAutomation¶à¸ö»º³åÇø¹ýʧÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-06¡ñÎó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-13522£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.8
CVE±àºÅ£ºCVE-2019-13518£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.8
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
CVE-2019-13522
EZ PLC Editor Versions 1.8.41 and prior
CVE-2019-13518
EZ Touch Editor Versions 2.1.0 and prior
¡ñÎó²î¸ÅÊö
EZAutomationÊÇAVGÆìϵÄÒ»¸öϵÁС£¡£¡£¡£¡£¡£AVGÊÇÒ»¼Ò×ö¹¤Òµ´¥ÃþÆÁºÍ¿É±à³Ì¿ØÖÆÆ÷µÄÃÀ¹úµçÆø¹«Ë¾¡£¡£¡£¡£¡£¡£EZAutomationϵÁÐÏÂÓÐPLC²úÆ·£¬£¬£¬£¬£¬£¬´¥ÃþÆÁ£¬£¬£¬£¬£¬£¬±àÂëÆ÷£¬£¬£¬£¬£¬£¬ÈüÂíµÆ£¬£¬£¬£¬£¬£¬²Ù×÷½çÃæÖÖÖÖ¸ßÐÔ¼Û²úÆ·¡£¡£¡£¡£¡£¡£¿ËÈÕEZAutomationÐû²¼Á½¸ö»º³åÇø¹ýʧÎó²îÈçÏ£º
CVE-2019-13522
EZAutomation EZ PLC EditorÊÇÃÀ¹úEZAutomation¹«Ë¾µÄÒ»Ì×PLC£¨¿É±à³ÌÂß¼¿ØÖÆÆ÷£©±à³ÌÈí¼þ¡£¡£¡£¡£¡£¡£EZAutomation EZ PLC Editor 1.8.41¼°Ö®Ç°°æ±¾Öб£´æ»º³åÇø¹ýʧÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽèÖúÌØÖÆµÄÏîÄ¿ÎļþʹÓøÃÎó²îËð»µÄÚ´æ²¢ÒÔ¸ÃÓ¦ÓóÌÐòȨÏÞÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£
CVE-2019-13518
EZAutomation EZ Touch EditorÊÇÃÀ¹úEZAutomation¹«Ë¾µÄÒ»Ì×HMI£¨ÈË»ú½çÃæ£©±à³ÌÈí¼þ¡£¡£¡£¡£¡£¡£EZAutomation EZ Touch Editor 2.1.0¼°Ö®Ç°°æ±¾Öб£´æ»º³åÇø¹ýʧÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽèÖúÌØÖÆµÄÏîÄ¿ÎļþʹÓøÃÎó²îÒÔ¸ÃÓ¦ÓóÌÐòµÄȨÏÞÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£
¡ñÎó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£
¡ñÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£ºhttps://www.ezautomation.net/access.php¡£¡£¡£¡£¡£¡£
¡ñ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-19-246-01
https://www.us-cert.gov/ics/advisories/icsa-19-246-02