CODESYS²úÆ·¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-18

¡ñ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13558£¬£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2019-13552£¬£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º8.8

CVE±àºÅ£ºCVE-2019-13556£¬£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º8.8

CVE±àºÅ£ºCVE-2019-13550£¬£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º10

CVE±àºÅ£ºCVE-2019-9013£¬£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º8.8


¡ñÓ°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


CVE-2019-13558¡¢CVE-2019-13552¡¢CVE-2019-13556¡¢CVE-2019-13550


WebAccess Versions 8.4.1 and prior


CVEÔÝÎÞ


All CODESYS V2.3 ENI servers prior version V3.2.2.24


CVE-2019-9013


CODESYS V3 products


¡ñ·ì϶¸ÅÊö


×î½üÔڵ¹ú3S-Smart Software SolutionsÔì×÷µÄ¿í·ºÊ¹ÓõÄCODESYS¹¤Òµ²úÆ·Öз¢ÏÖÁ˼¸¸ö¹Ø¼üÇÒ¸ßÑϳÁÐԵķì϶¡£¡£¡£¡£¡£¡£ ¡£


CVE-2019-13558

ͨ¹ýÍøÂçÖ´Ðеķì϶¿ÉÄܵ¼Ö¶ԴúÂëÌìÉúµÄ²»ÕýÈ·½ÚÔ죬£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄÜÔÊÐíÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬ £¬£¬£¬£¬Êý¾Ýй©»òµ¼ÖÂϵͳ±ÀÀ£¡£¡£¡£¡£¡£¡£ ¡£


CVE-2019-13552

¶à¸öºÅÁî×¢Èë·ì϶ÊÇÓɲ»×ã¶ÔÓû§ÌṩµÄÊý¾ÝµÄÕýÈ·ÑéÖ¤ÒýÆðµÄ£¬£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÔÊÐíËÁÒâÎļþɾ³ýºÍÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£ ¡£


CVE-2019-13556

ÓÉÓÚ²»×ã¶ÔÓû§ÌṩµÄÊý¾Ý³¤¶ÈµÄÊʵ±ÑéÖ¤£¬£¬£¬£¬ £¬£¬£¬£¬µ¼Ö¶à¸ö»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£ ¡£ÀûÓÃÕâЩ·ì϶¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£ ¡£


CVE-2019-13550

²»Õýµ±µÄÊÚȨ·ì϶¿ÉÄÜÔÊÐí¹¥»÷Õßй¼ûô¸ÐÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬µ¼Ö¶ԴúÂëÌìÉúµÄ²»ÕýÈ·½ÚÔ죬£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄÜÔÊÐíÔ¶³Ì´úÂëÖ´Ðлòµ¼ÖÂϵͳ±ÀÀ£¡£¡£¡£¡£¡£¡£ ¡£


CODESYS ENI·þÎñÆ÷»º³åÇøÒç¶Âí½Å

CODESYS ENI·þÎñÆ÷ÖлùÓÚ²Ö¿âµÄ¹Ø¼ü»º³åÇøÒç³ö£¬£¬£¬£¬ £¬£¬£¬£¬ËüÓÐÖúÓÚÖÎÀíCODESYSÏîÄ¿ÖеĶÔÏ󡣡£¡£¡£¡£¡£ ¡£¿ £¿£¿£¿£¿£¿ £Äܹ»Í¨¹ýÏòÖ¸±ê·þÎñÆ÷·¢ËÍÌØÔìÒªÇ󣬣¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÌáÒéÔ¶³ÌËÁÒâ´úÂëÖ´ÐлòDoS¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£


CVE-2019-9013

ÕâÖÖÈõµãÔÊÐíÔ¶³Ì¹¥»÷ÕßÊÕÊÜ»ò¹Ø¹ØÏÖÓеÄͨѶÐÅ·¡£¡£¡£¡£¡£¡£ ¡£Í³Ò»×é¼þÖеÄÁíÒ»¸öÎÊÌâÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËÍÌØÔìÒªÇóÀ´µ¼ÖÂDoSǰÌá¡£¡£¡£¡£¡£¡£ ¡£


¡ñ·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£ ¡£


¡ñ½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬ £¬£¬£¬£¬ÏÂÔØÁ´½Ó£º


https://support.advantech.com/support/DownloadSRDetail_New.aspx?SR_ID=1-MS9MJV&Doc_Source=Download


https://www.codesys.com/security/security-reports.html


¡ñ²Î¿¼Á´½Ó


https://www.securityweek.com/serious-flaws-codesys-products-expose-industrial-systems-remote-attacks