Î÷ÃÅ×ÓS7-1200 PLC²úÆ·Çå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-05

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13945£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.8 £¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


S7-1200ËùÓа汾


Îó²î¸ÅÊö


Siemens S7-1200 CPUÖб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»á¼ûÆäËûÕï¶Ï¹¦Ð§£¬£¬£¬£¬£¬£¬Ó°ÏìϵͳµÄÍêÕûÐÔ¡¢¿ÉÓÃÐԺͱ£ÃÜÐÔ¡£¡£¡£¡£¡£


Î÷ÃÅ×Ó×î½üÐû²¼ÁËÒ»·ÝÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Õë¶ÔÑо¿Ö°Ô±ÔÚÆäS7-1200¿É±à³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©Öз¢Ã÷µÄÎó²îµÄ±äͨ²½·¥»ººÍ½â²½·¥£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÓÃÓÚÈÆ¹ý¹Ì¼þÍêÕûÐÔ¼ì²éÒÔ¼ÓÔØ¶ñÒâÈí¼þ»òÐ®ÖÆ×°±¸µÄ¹¤ÒµÁ÷³Ì¡£¡£¡£¡£¡£Î÷ÃÅ×ÓÌåÏÖ£º¡°ÎÒÃÇÕýÔÚÉó²é¼øºÚµ£±£Íø²úÆ·Ä£×Ó£¬£¬£¬£¬£¬£¬²¢½«ÔÚSSA-686531ÉÏÐû²¼¸üУ¬£¬£¬£¬£¬£¬ÒÔ·ÀÆäËûÄ£×ÓÊܵ½Ó°Ïì¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷£¬£¬£¬£¬£¬£¬¿É±à³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©ÖеÄÌØÊâ»á¼û¹¦Ð§Ò²¿ÉÒԺܺõØÓÃ×÷£º×÷Ϊ·ÀÓùÕßµÄȡ֤¹¤¾ß¡£¡£¡£¡£¡£ËûÃÇʹÓøù¦Ð§Éó²éPLC´æ´¢Æ÷µÄÄÚÈÝ£¬£¬£¬£¬£¬£¬Òò´Ë¹¤³§²Ù×÷Ô±Ò²¿ÉÒÔʹÓÃËüÀ´²éÕÒÉè±¹ØÁ¬Ä¶ñÒâ´úÂë¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥½â¾ö´ËÇå¾²ÎÊÌ⣬£¬£¬£¬£¬£¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö²½·¥£ºhttps://www.siemens.com£»£»£»


S7-122 CPUµÄÓû§¿ÉÒÔ½ÓÄÉÕâЩ±äͨ²½·¥»ººÍ½â²½·¥À´½µµÍΣº¦£º


1.È·±£ÎïÆÊÎö¼û±£»£»£»¤£»£»£»

2.Ó¦ÓÃÉî¶È·ÀÓù¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.darkreading.com/vulnerabilities---threats/siemens-offers-workarounds-for-newly-found-plc-vulnerability/d/d-id/1336503