Emerson OpenEnterprise SCADA | ¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-05-29

0x00 Îó²î¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Ó°Ïì¹æÄ£

Emerson OpenEnterprise SCADA

CVE-2020-6970

BO

ÑÏÖØ

ÊÇ

Emerson OpenEnterprise SCADA Server 3.1-3.3.3,2.83°æ±¾

CVE-2020-10640

MA

ÑÏÖØ

ÊÇ

Emerson OpenEnterprise SCADA <= 3.3.4

CVE-2020-10632

IOM

¸ßΣ

·ñ

CVE-2020-10636

IES

ÖÐΣ

·ñ


0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Emerson Electric OpenEnterpriseÊÇÃÀ¹ú°¬Ä¬ÉúµçÆø£¨Emerson Electric£©¹«Ë¾µÄÒ»Ì×Ö÷ÒªÓÃÓÚÔ¶³ÌʯÓͺÍ×ÔÈ»ÆøÓ¦ÓõÄÊý¾ÝÊÕÂÞÓë¼à¿ØÏµÍ³£¨SCADA£©¡£¡£¡£¡£

¿ËÈÕ£¬£¬£¬¿¨°Í˹»ùµÄÑо¿Ö°Ô±Roman Lozko·¢Ã÷ÁËEmerson OpenEnterpriseÖеÄËĸöÇå¾²Îó²î£¬£¬£¬ÕâËĸöÎó²î»®·ÖΪ»ùÓڶѵĻº³åÇøÒç³ö¡¢È±ÉÙÉí·ÝÑéÖ¤¡¢ËùÓÐȨÖÎÀí²»µ±ºÍÈõ¼ÓÃÜÎÊÌ⣬£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º

CVE-2020-6970ÊÇEmerson Electric OpenEnterprise SCADA ServerÖб£´æµÄ»º³åÇøÒç³öÎó²î£¬£¬£¬CVE-2020-10640ÊÇEmerson Electric OpenEnterpriseÖб£´æµÄÇå¾²Îó²î¡£¡£¡£¡£ÒÔÉÏÁ½¸öÎó²î¶¼±»ÆÀ¼¶Îª¡°ÑÏÖØ¡±£¬£¬£¬¿ÉÒÔʹ¹¥»÷ÕßÔÚÔËÐÐOpenEnterpriseµÄ×°±¸ÉÏÒÔÌáÉýµÄÌØÈ¨Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

CVE-2020-10632ÊÇEmerson Electric OpenEnterpriseÖб£´æµÄÇå¾²Îó²î£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòΪÎļþ¼ÐÉèÖÃÁ˲»Çå¾²µÄȨÏÞ¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÐÞ¸ÄÖ÷ÒªµÄÉèÖÃÎļþ£¬£¬£¬Ôì³Éϵͳ¹ÊÕÏ»òÒì³£¡£¡£¡£¡£

CVE-2020-10636ÊÇEmerson Electric OpenEnterpriseÖб£´æµÄ¼ÓÃÜÎÊÌâÎó²î¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡OpenEnterpriseÓû§ÕÊ»§µÄÃÜÂë¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.emerson.com/


0x03 Ïà¹ØÐÂÎÅ


https://www.securityweek.com/vulnerabilities-found-emerson-scada-product-made-oil-and-gas-industry


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-049-02

https://www.us-cert.gov/ics/advisories/icsa-20-140-02


0x05 ʱ¼äÏß


2020-05-29 VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨