Fuji Electric¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-01-29

0x00 Îó²î¸ÅÊö

2021Äê01ÔÂ26ÈÕ£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©Ðû²¼Ç徲ͨ¸æ£¬£¬£¬Åû¶Á˹¤Òµ×éÖ¯ÈÕ±¾µçÆø×°±¸¹«Ë¾Fuji ElectricÉú²úµÄ²¿·ÖSCADA / HMI²úÆ·TellusºÍV-ServerÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

TellusºÍV-Server ²úÆ·¿ÉÔ¶³Ì¼à¿ØºÍ¿ØÖƹ¤³§µÄ×°±¸£¬£¬£¬ËüÃÇÔÚÒªº¦µÄÖÆÔìÒµÖб»ÆÕ±é½ÓÄÉ¡£¡£¡£¡£¡£

ÕâЩÎó²îÊǶÔÓû§ÌṩµÄÊý¾Ýȱ·¦×¼È·ÑéÖ¤µ¼Öµģ¬£¬£¬¿ÉÄÜ´¥·¢»º³åÇøÒç³ö²¢Òò´Ëµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£Ê¹ÓÃÕâЩÎó²îÐèÒªÓû§½»»¥£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕÆ­Ä¿µÄÓû§·­¿ª¶ñÒâÏîÄ¿ÎļþÀ´´¥·¢Îó²î£¬£¬£¬×îÖÕÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

±¾´ÎÅû¶µÄÎó²îÈçÏ£º

CVE

ÀàÐÍ

CVSSÆÀ·Ö

ÑÏÖØË®Æ½

CVE-2021-22637

»ùÓڶѵĻº³åÇøÒç³ö

7.8

¸ßΣ

CVE-2021-22655

Ô½½ç¶ÁÈ¡

7.8

¸ßΣ

CVE-2021-22653

Ô½½çдÈë

7.8

¸ßΣ

CVE-2021-22639

´úÂëÖ´ÐÐ

7.8

¸ßΣ

CVE-2021-22641

»ùÓڶѵĻº³åÇøÒç³ö

7.8

¸ßΣ

 

 

Fuji Electric»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2021-22637£©

ÔÚÓ¦ÓóÌÐò´¦Öóͷ£ÏîÄ¿ÎļþµÄ·½·¨Öб£´æÒ»¸ö»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔÖÆ×÷Ö´ÐÐí§Òâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£

 

Fuji ElectricÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-22655£©

ÔÚÓ¦ÓóÌÐò´¦Öóͷ£ÏîÄ¿ÎļþµÄ·½·¨Öб£´æÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔÖÆ×÷Ö´ÐÐí§Òâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£

 

Fuji ElectricÔ½½çдÈëÎó²î£¨CVE-2021-22653£©

¸ÃÎó²î±£´æÓÚÓ¦ÓóÌÐò´¦Öóͷ£ÏîÄ¿ÎļþµÄ·½·¨ÖУ¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÖÆ×÷¶ñÒâµÄÏîÄ¿Îļþ£¬£¬£¬×îÖÕÖ´ÐÐí§Òâ´úÂ룬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£

 

Fuji Electric´úÂëÖ´ÐÐÎó²î£¨CVE-2021-22639£©

ÔÚÓ¦ÓóÌÐò´¦Öóͷ£ÏîÄ¿ÎļþµÄ·½·¨Öб£´æÎ´³õʼ»¯µÄÖ¸ÕëÎÊÌ⣬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔÖÆ×÷Ö´ÐÐí§Òâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£

 

Fuji Electric»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2021-22641£©

ÔÚÓ¦ÓóÌÐò´¦Öóͷ£ÏîÄ¿ÎļþµÄ·½·¨Öз¢Ã÷ÁË»ùÓڶѵĻº³åÇøÒç³öÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÖÆ×÷¶ñÒâµÄÏîÄ¿ÎļþÀ´Ö´ÐÐí§Òâ´úÂ룬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

Tellus Lite V-Simulator£ºv4.0.10.0֮ǰµÄ°æ±¾

V-Server Lite£ºv4.0.10.0֮ǰµÄ°æ±¾


0x02 ´¦Öóͷ£½¨Òé

½¨ÒéÉý¼¶ÖÁv4.0.10.0°æ±¾¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://felib.fujielectric.co.jp/download/details.htm?dataid=43821668&site=global&lang=en

 

 

0x03 ²Î¿¼Á´½Ó

https://securityaffairs.co/wordpress/113950/ics-scada/fuji-electric-hmi-flaws.html?utm_source=rss&utm_medium=rss&utm_campaign=fuji-electric-hmi-flaws

https://us-cert.cisa.gov/ics/advisories/icsa-21-026-01

https://felib.fujielectric.co.jp/download/details.htm?dataid=43821669&site=global&lang=en

 

0x04 ʱ¼äÏß

2021-01-26  CISAÐû²¼Ç徲ͨ¸æ

2021-01-29  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png