Fuji Electric¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-01-290x00 Îó²î¸ÅÊö
2021Äê01ÔÂ26ÈÕ£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©Ðû²¼Ç徲ͨ¸æ£¬£¬£¬Åû¶Á˹¤Òµ×éÖ¯ÈÕ±¾µçÆø×°±¸¹«Ë¾Fuji ElectricÉú²úµÄ²¿·ÖSCADA / HMI²úÆ·TellusºÍV-ServerÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
TellusºÍV-Server ²úÆ·¿ÉÔ¶³Ì¼à¿ØºÍ¿ØÖƹ¤³§µÄ×°±¸£¬£¬£¬ËüÃÇÔÚÒªº¦µÄÖÆÔìÒµÖб»ÆÕ±é½ÓÄÉ¡£¡£¡£¡£¡£
ÕâЩÎó²îÊǶÔÓû§ÌṩµÄÊý¾Ýȱ·¦×¼È·ÑéÖ¤µ¼Öµģ¬£¬£¬¿ÉÄÜ´¥·¢»º³åÇøÒç³ö²¢Òò´Ëµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£Ê¹ÓÃÕâЩÎó²îÐèÒªÓû§½»»¥£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕÆÄ¿µÄÓû§·¿ª¶ñÒâÏîÄ¿ÎļþÀ´´¥·¢Îó²î£¬£¬£¬×îÖÕÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
±¾´ÎÅû¶µÄÎó²îÈçÏ£º
CVE | ÀàÐÍ | CVSSÆÀ·Ö | ÑÏÖØË®Æ½ |
CVE-2021-22637 | »ùÓڶѵĻº³åÇøÒç³ö | 7.8 | ¸ßΣ |
CVE-2021-22655 | Ô½½ç¶ÁÈ¡ | 7.8 | ¸ßΣ |
CVE-2021-22653 | Ô½½çдÈë | 7.8 | ¸ßΣ |
CVE-2021-22639 | ´úÂëÖ´ÐÐ | 7.8 | ¸ßΣ |
CVE-2021-22641 | »ùÓڶѵĻº³åÇøÒç³ö | 7.8 | ¸ßΣ |
Fuji Electric»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2021-22637£©
ÔÚÓ¦ÓóÌÐò´¦Öóͷ£ÏîÄ¿ÎļþµÄ·½·¨Öб£´æÒ»¸ö»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔÖÆ×÷Ö´ÐÐí§Òâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£
Fuji ElectricÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-22655£©
ÔÚÓ¦ÓóÌÐò´¦Öóͷ£ÏîÄ¿ÎļþµÄ·½·¨Öб£´æÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔÖÆ×÷Ö´ÐÐí§Òâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£
Fuji ElectricÔ½½çдÈëÎó²î£¨CVE-2021-22653£©
¸ÃÎó²î±£´æÓÚÓ¦ÓóÌÐò´¦Öóͷ£ÏîÄ¿ÎļþµÄ·½·¨ÖУ¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÖÆ×÷¶ñÒâµÄÏîÄ¿Îļþ£¬£¬£¬×îÖÕÖ´ÐÐí§Òâ´úÂ룬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£
Fuji Electric´úÂëÖ´ÐÐÎó²î£¨CVE-2021-22639£©
ÔÚÓ¦ÓóÌÐò´¦Öóͷ£ÏîÄ¿ÎļþµÄ·½·¨Öб£´æÎ´³õʼ»¯µÄÖ¸ÕëÎÊÌ⣬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔÖÆ×÷Ö´ÐÐí§Òâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£
Fuji Electric»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2021-22641£©
ÔÚÓ¦ÓóÌÐò´¦Öóͷ£ÏîÄ¿ÎļþµÄ·½·¨Öз¢Ã÷ÁË»ùÓڶѵĻº³åÇøÒç³öÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÖÆ×÷¶ñÒâµÄÏîÄ¿ÎļþÀ´Ö´ÐÐí§Òâ´úÂ룬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Tellus Lite V-Simulator£ºv4.0.10.0֮ǰµÄ°æ±¾
V-Server Lite£ºv4.0.10.0֮ǰµÄ°æ±¾
0x02 ´¦Öóͷ£½¨Òé
½¨ÒéÉý¼¶ÖÁv4.0.10.0°æ±¾¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://felib.fujielectric.co.jp/download/details.htm?dataid=43821668&site=global&lang=en
0x03 ²Î¿¼Á´½Ó
https://securityaffairs.co/wordpress/113950/ics-scada/fuji-electric-hmi-flaws.html?utm_source=rss&utm_medium=rss&utm_campaign=fuji-electric-hmi-flaws
https://us-cert.cisa.gov/ics/advisories/icsa-21-026-01
https://felib.fujielectric.co.jp/download/details.htm?dataid=43821669&site=global&lang=en
0x04 ʱ¼äÏß
2021-01-26 CISAÐû²¼Ç徲ͨ¸æ
2021-01-29 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/