CODESYS²úÆ·¶à¸ö·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-18¡ñ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-13558£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-13552£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º8.8
CVE±àºÅ£ºCVE-2019-13556£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º8.8
CVE±àºÅ£ºCVE-2019-13550£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º10
CVE±àºÅ£ºCVE-2019-9013£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º8.8
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
CVE-2019-13558¡¢CVE-2019-13552¡¢CVE-2019-13556¡¢CVE-2019-13550
WebAccess Versions 8.4.1 and prior
CVEÔÝÎÞ
All CODESYS V2.3 ENI servers prior version V3.2.2.24
CVE-2019-9013
CODESYS V3 products
¡ñ·ì϶¸ÅÊö
×î½üÔڵ¹ú3S-Smart Software SolutionsÔì×÷µÄ¿í·ºÊ¹ÓõÄCODESYS¹¤Òµ²úÆ·Öз¢ÏÖÁ˼¸¸ö¹Ø¼üÇÒ¸ßÑϳÁÐԵķì϶¡£¡£¡£¡£¡£¡£¡£
CVE-2019-13558
ͨ¹ýÍøÂçÖ´Ðеķì϶¿ÉÄܵ¼Ö¶ԴúÂëÌìÉúµÄ²»ÕýÈ·½ÚÔ죬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÔÊÐíÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬Êý¾Ýй©»òµ¼ÖÂϵͳ±ÀÀ£¡£¡£¡£¡£¡£¡£¡£
CVE-2019-13552
¶à¸öºÅÁî×¢Èë·ì϶ÊÇÓɲ»×ã¶ÔÓû§ÌṩµÄÊý¾ÝµÄÕýÈ·ÑéÖ¤ÒýÆðµÄ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÔÊÐíËÁÒâÎļþɾ³ýºÍÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£
CVE-2019-13556
ÓÉÓÚ²»×ã¶ÔÓû§ÌṩµÄÊý¾Ý³¤¶ÈµÄÊʵ±ÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¶à¸ö»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£ÀûÓÃÕâЩ·ì϶¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
CVE-2019-13550
²»Õýµ±µÄÊÚȨ·ì϶¿ÉÄÜÔÊÐí¹¥»÷Õßй¼ûô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¶ԴúÂëÌìÉúµÄ²»ÕýÈ·½ÚÔ죬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÔÊÐíÔ¶³Ì´úÂëÖ´Ðлòµ¼ÖÂϵͳ±ÀÀ£¡£¡£¡£¡£¡£¡£¡£
CODESYS ENI·þÎñÆ÷»º³åÇøÒç¶Âí½Å
CODESYS ENI·þÎñÆ÷ÖлùÓÚ²Ö¿âµÄ¹Ø¼ü»º³åÇøÒç³ö£¬£¬£¬£¬£¬£¬£¬£¬ËüÓÐÖúÓÚÖÎÀíCODESYSÏîÄ¿ÖеĶÔÏ󡣡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£Äܹ»Í¨¹ýÏòÖ¸±ê·þÎñÆ÷·¢ËÍÌØÔìÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÌáÒéÔ¶³ÌËÁÒâ´úÂëÖ´ÐлòDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£
CVE-2019-9013
ÕâÖÖÈõµãÔÊÐíÔ¶³Ì¹¥»÷ÕßÊÕÊÜ»ò¹Ø¹ØÏÖÓеÄͨѶÐÅ·¡£¡£¡£¡£¡£¡£¡£Í³Ò»×é¼þÖеÄÁíÒ»¸öÎÊÌâÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËÍÌØÔìÒªÇóÀ´µ¼ÖÂDoSǰÌá¡£¡£¡£¡£¡£¡£¡£
¡ñ·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
¡ñ½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://support.advantech.com/support/DownloadSRDetail_New.aspx?SR_ID=1-MS9MJV&Doc_Source=Download
https://www.codesys.com/security/security-reports.html
¡ñ²Î¿¼Á´½Ó
https://www.securityweek.com/serious-flaws-codesys-products-expose-industrial-systems-remote-attacks


¾©¹«Íø°²±¸11010802024551ºÅ