Î÷ÃÅ×ÓÁ½¿î²úÆ·ÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-09-13

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-13799£¬£¬£¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.1£¬£¬£¬£¬£¬£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-13807£¬£¬£¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.6£¬£¬£¬£¬£¬£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


SIMATIC WinCC OA Version <= 3.14

SCALANCE X300 Version < 4.0.0

SCALANCE X408 Version < 4.0.0

SCALANCE X414 ËùÓа汾


·ì϶¸ÅÊö


Î÷ÃÅ×Ó¹Ù·½°ä²¼¹«¸æ½¨¸´ÁËÆäÁ½¿î²úÆ·µÄ°²È«·ì϶£¬£¬£¬£¬£¬£¬ £¬£¬ÊÜÓ°Ïì²úÆ·Ô̺¬SIMATIC WinCC OA¡¢SCALANCE X»¥»»»ú¡£¡£¡£ ¡£¡£¡£¡£¡£


SIMATIC WinCC OAµÄ·ì϶CVE-2018-13799ÊÇÓÉÓÚ5678/TCP¶Ë¿ÚµÄ½Ó¼û½ÚÔì²»µ±¶ø²úÉú£¬£¬£¬£¬£¬£¬ £¬£¬³É¹¦ÀûÓø÷ì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚSIMATIC WinCC OA»·¾³ÖÐÌáÉýÆäȨÏÞ¡£¡£¡£ ¡£¡£¡£¡£¡£


SCALANCE X»¥»»»úµÄ·ì϶CVE-2018-13807¿ÉÔÊÐí¹¥»÷Õßͨ¹ýÏòWeb·þÎñÆ÷·¢ËÍÌØÔìÊý¾Ý°üÀ´µ¼Ö»ؾø·þÎñ¡£¡£¡£ ¡£¡£¡£¡£¡£Ê¹É豸×Ô¶¯³ÁÆô£¬£¬£¬£¬£¬£¬ £¬£¬Ó°ÏìÆäËûÉ豸µÄÍøÂç¿ÉÓÃÐÔ¡£¡£¡£ ¡£¡£¡£¡£¡£²»Íâ¹¥»÷Õß±ØÐëÓµÓжÔ443/TCP¶Ë¿ÚµÄÍøÂç½Ó¼ûÄÜÁ¦ÄÜÁ¦ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬ £¬£¬ÀûÓô˷ì϶¼È²»±ØÒªÓÐЧʹ´¦Ò²²»±ØÒªºÏ·¨Óû§µÄ½»»¥¡£¡£¡£ ¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC\EXP


½¨¸´½¨Òé


Î÷ÃÅ×Ó¹Ù·½ÒѾ­°ä²¼ÁËSIMATIC WinCC OAÓйز¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬£¬£¬£¬£¬£¬ £¬£¬¿É´ÓÒÔÏÂÁ´½Ó»ñµÃ£º

https://portal.etm.at/index.php?option=com_content&view=category&id=67&layout=blog&Itemid=80 £¨ÒªÇóµÇ¼£©


Î÷ÃÅ×Ó»¹½¨ÒéѡȡÒÔÏÂÊÖ¶¯»º½â´ëÊ©À´½µµÍ·çÏÕ£º

ÒÀÕÕÒÔÏÂÁ´½ÓÖеIJ½ÖèÊÖ¶¯½¨¸´·ì϶£º

https://portal.etm.at/patchdownload.php?fp=version_3.14/win64vc12/ReadmeP021.txt £¨ÒªÇóµÇ¼£©

×ñÑ­SIMATIC WinCC OA°²È«Ö¸ÄÏÒÔÊØ»¤°²È«µÄSIMATIC WinCC OA»·¾³£º

https://portal.etm.at/index.php?option=com_phocadownload&view=category&id=52:security&Itemid=81 £¨ÒªÇóµÇ¼£©

ÀûÓÃÉî¶È·ÀÓù£º

https://www.siemens.com/cert/operational-guidelines-industrial-security

 

Î÷ÃÅ×ÓΪSCALANCE X300ºÍSCALANCE X408Ìṩ¸üУ¬£¬£¬£¬£¬£¬ £¬£¬²¢ÎªSCALANCE X414Ìṩ»º½â´ëÊ©¡£¡£¡£ ¡£¡£¡£¡£¡£

SCALANCE X300£º¸üÐÂÖÁ4.1.2°æ

https://support.industry.siemens.com/cs/us/en/view/109753720

SCALANCE X408£º¸üÐÂÖÁ4.1.2°æ

https://support.industry.siemens.com/cs/us/en/view/109753720

SCALANCE X414£º

Î÷ÃÅ×ÓÒÑÈ·¶¨Óû§Äܹ»ÀûÓÃÒÔϽâ¾ö¹æ»®»ººÍ½â´ëÊ©½µµÍ·çÏÕ£º

ʹÓÃÊʵ±µÄ»úÔì±£»£» £»£»£»¤¶Ô443/TCP¶Ë¿ÚÉϼ¯³ÉµÄWeb·þÎñÆ÷µÄÍøÂç½Ó¼û¡£¡£¡£ ¡£¡£¡£¡£¡£

½«443/TCP¶Ë¿ÚµÄÍøÂç½Ó¼ûÏÞ¶ÈÔÚ¿ÉÐÅIPµØÖ·ÄÚ£¬£¬£¬£¬£¬£¬ £¬£¬²¢Ô¤·ÀÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÔËÐÐÀ´×Ô¿ÉÐÅIPµØÖ·µÄ·ì϶ɨÃ蹤¾ß¡£¡£¡£ ¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó

https://ics-cert.us-cert.gov/advisories/ICSA-18-254-05   https://www.siemens.com/global/en/home/products/services/cert.html#SecurityPublications