¡¾²úÏ߸üС¿Schneider | ¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-130x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
Schneider Electric²úÆ· |
CVE-2020-7475 |
I |
ÑϳÁ |
ÊÇ |
EcoStruxure Control Expert 14.1 Hot Fix֮ǰ°æ±¾£»£»£»£»£»£»£»£»Unity Pro£¨È«Êý°æ±¾£©£»£»£»£»£»£»£»£»Modicon M340 V3.20֮ǰ°æ±¾£»£»£»£»£»£»£»£»Modicon M580 V3.10֮ǰ°æ±¾ |
|
CVE-2020-7489 |
I |
ÑϳÁ |
ÊÇ |
SchneiderElectric EcoStruxure Machine Expert ¨C Basic»òSoMachine Basic |
0x01 ·ì϶ÏêÇé
Ê©ÄÍµÂµçÆø¹«Ë¾ÊÇÈ«ÇòÄÜЧÖÎÀíÁìÓòµÄ¸¨µ¼Õߣ¬£¬£¬£¬£¬£¬Îª100¶à¸ö¹ú¶ÈµÄÄÜÔ´¼°»ù´¡ÉèÊ©¡¢¹¤Òµ¡¢Êý¾ÝÖÐÐļ°ÍøÂ硢¥ÓîºÍסլÊг¡ÌṩÕûÌå½â¾ö¹æ»®¡£¡£¡£¡£¡£¡£¡£¡£Schneider Electric Modicon M580µÈ¶¼ÊǸù«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£¡£¡£¡£
×î½ü£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÓÖ´ÓÊ©ÄÍµÂµçÆøÈí¼þÖз¢ÏÖÁËÒ»¸ö·ì϶£¨CVE-2020-7489£©£¬£¬£¬£¬£¬£¬ËüÀàËÆÓÚ³ôÃûÔ¶ÑïµÄ¡°ÕðÍø¡±²¡¶¾(Stuxnet)¶ñÒâÈí¼þÔøÀûÓõķì϶¡£¡£¡£¡£¡£¡£¡£¡£
Ê®¶àÄêǰ£¬£¬£¬£¬£¬£¬ÃÀ¹úºÍÒÔÉ«Áб»Ö¸ÀûÓá°ÕðÍø¡±²¡¶¾ÇÖº¦ÒÁÀʵĺ˴òË㣬£¬£¬£¬£¬£¬Ö¸±êÊÇÎ÷ÃÅ× SIMATIC S7-300ºÍS7-400¿É±à³ÌÂß¼½ÚÔìÆ÷(PLCs)¡£¡£¡£¡£¡£¡£¡£¡£Õâ¿î¶ñÒâÈí¼þͨ¹ý´úÌæ½«ÓëÎ÷ÃÅ×Ó STEP7½ÚÔìÆ÷±à³ÌÈí¼þÓйØÁªµÄÒ»¸öDLLÎļþ£¬£¬£¬£¬£¬£¬½«¶ñÒâ´úÂë¼ÓÔØµ½Ö¸±êPLCsÉÏ¡£¡£¡£¡£¡£¡£¡£¡£
2020Äê3Ô·ݣ¬£¬£¬£¬£¬£¬AirbusÍøÂ簲ȫ¹«Ë¾±¨Â·³Æ´ÓÊ©ÄÍµÂµçÆøµÄEcoStruxure ControlExpert¹¤³ÌÈí¼þ£¨´ËǰÃûΪ Unity Pro£©Öз¢ÏÖÁËÒ»¸öÀàËÆ·ì϶ CVE-2020-7475£¬£¬£¬£¬£¬£¬Ëü¿Éͨ¹ý´úÌæÓë¸Ã¹¤³ÌÈí¼þÓйØÁªµÄÆäÖÐÒ»¸öDLLÎļþ£¬£¬£¬£¬£¬£¬½«¶ñÒâ´úÂëÉÏ´«µ½Modicon M340 ºÍM580 PLCsÖУ¬£¬£¬£¬£¬£¬´Ó¶øÔì³É¹ý³Ì·ÛËéºÍÆäËüÇÖº¦¡£¡£¡£¡£¡£¡£¡£¡£CVE-2020-7475ÊǶà¿îSchneider Electric²úÆ·ÖдæÔÚµÄ×¢Èë·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶Ïò½ÚÔìÆ÷Öз¢ËͶñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
2020Äê5ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ¹«Ë¾TrustwaveµÄ×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬ËûÃÇÒ²´ÓÊ©Ä͵ÂÈí¼þ EcoStruxure MachineExpert£¨´ËǰÃûΪSoMachine£©Öз¢ÏÖÁËÒ»¸öÀàËÆ·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶Ϊ CVE-2020-7489£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶½«¶ñÒâ´úÂë´«Êäµ½½ÚÔìÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ²úÆ·¹æ»®
8827Ì«Ñô¼¯ÍÅÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ-¹¤¿ØÏµÍ³×¨ÓðæV6.0ÓÚ2020Äê5ÔÂ13ÈÕ°ä²¼Éý¼¶°ü£¬£¬£¬£¬£¬£¬Äܹ»¶ÔÉÏÊö·ì϶½øÐмì²â¡£¡£¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ìÉý¼¶Ì쾵©ɨ²úÆ··ì϶¿âÖÁ6075°æ±¾£¬£¬£¬£¬£¬£¬ÏÂÔØµØÖ·£ºhttps://venustech.download.venuscloud.cn/
0x03 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://www.se.com/ww/en/download/document/SEVD-2020-080-01/
https://www.se.com/ww/en/download/document/SEVD-2020-105-01/
0x04 ÓйØÐÂÎÅ
https://www.securityweek.com/another-stuxnet-style-vulnerability-found-schneider-electric-software
0x05 ²Î¿¼Á´½Ó
http://www.se.com/ww/en/download/document/SEVD-2020-080-01
https://www.se.com/ww/en/download/document/SEVD-2020-105-01
0x06 ¹¦·òÏß
2020-05-08 VSRC°ä²¼·ì϶¹«¸æ
2020-05-13 Ìì¾µ¹¤¿ØÂ©É¨¸üÐÂ


¾©¹«Íø°²±¸11010802024551ºÅ