SoftPAC | ¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-200x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
SoftPAC |
CVE-2020-12042 |
DF |
ÖÐΣ |
ÊÇ |
Opto 22 SoftPAC Project <= 9.6 |
|
CVE-2020-12046 |
DF |
ÖÐΣ |
ÊÇ |
||
|
CVE-2020-10612 |
ACE |
ÑϳÁ |
ÊÇ |
||
|
CVE-2020-10616 |
CI |
¸ßΣ |
ÊÇ |
||
|
CVE-2020-10620 |
AI |
ÑϳÁ |
ÊÇ |
0x01 ·ì϶ÏêÇé
Opto 22 SoftPAC ProjectÊÇÃÀ¹úOpto 22¹«Ë¾µÄÒ»Ì××Ô¶¯»¯Èí¼þÌ×¼þ¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·¿ÉÄÜÌṩ¹¤Òµ×Ô¶¯»¯¡¢¹ý³Ì½ÚÔ졢¥Óî×Ô¶¯»¯¡¢Ô¶³Ì¼à¿Ø¡¢Êý¾Ý²É¼¯ºÍ¹¤ÒµÎïÁªÍøµÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£
SoftPACÓµÓÐÈý¸öÖØÒª×é¼þ£ºMonitor£¬£¬£¬£¬£¬´úÀíºÍÐé¹¹½ÚÔìÆ÷×ÔÉí¡£¡£¡£¡£¡£¡£¡£MonitorÔÊÐíÓû§Æô¶¯ºÍÖÕ³¡PAC·þÎñÒÔ¼°¸üÐÂSoftPAC¹Ì¼þ¡£¡£¡£¡£¡£¡£¡£´úÀíÆ¾¾Ý´ÓMonitorÊÕµ½µÄÓû§ºÅÁîÀ´ÖÎÀíSoftPAC PLC¡£¡£¡£¡£¡£¡£¡£µ«ÊÇÔÚÊʵ±µÄÇé¿öÏ£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý±í²¿Ô¶³ÌÏÎ½Ó¶ÔÆä½øÐаѳ֣¬£¬£¬£¬£¬Ïê¼ûÏÂͼ£º
½üÈÕClaroty×êÑÐÔ±Åû¶Opto 22 SoftPACÖдæÔÚÎå¸ö°²È«·ì϶£¬£¬£¬£¬£¬¾ßÌåÈçÏ£º
CVE-2020-12042ÊÇÊý¾ÝαÔìÎÊÌâ·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚ·¨Ê½Î´¶Ï¸ùÓÃÓÚ¸üÐÂSoftPAC¹Ì¼þµÄzipÎļþÖÐÖ¸¶¨µÄõè¾¶¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñµÃËÁÒâÎļþдÈëȨÏÞ¡£¡£¡£¡£¡£¡£¡£
CVE-2020-12046ÊÇÊý¾ÝαÔìÎÊÌâ·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓڹ̼þ¸üÐÂʱδÑéÖ¤ÎļþÊðÃû¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÓöñÒâÎļþ´úÌæºÏ·¨µÄ¹Ì¼þÎļþ¡£¡£¡£¡£¡£¡£¡£
CVE-2020-10612ÊǽӼû½ÚÔìÃýÎó·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚSoftPACAgentͨ¹ý22000ÍøÂç¶Ë¿ÚÓëSoftPACMonitor½øÐÐͨѶ£¬£¬£¬£¬£¬µ«·¨Ê½²¢Ã»ÓжÔÕâһʢ¿ªµÄ¶Ë¿Ú½øÐÐÈκÎÏÞ¶È¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½ÚÔìSoftPACAgent·þÎñ£¬£¬£¬£¬£¬Ô̺¬¸üÐÂSoftPAC¹Ì¼þ£¬£¬£¬£¬£¬Æô¶¯»òÖÕ³¡·þÎñ»òдÈëijЩע²á±íÖµ¡£¡£¡£¡£¡£¡£¡£
CVE-2020-10616ÊÇ´úÂëÎÊÌâ·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚSoftPACδָ¶¨¶à¸öµ¼Èë.dllÎļþµÄõè¾¶¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶´úÌæÎļþ²¢Ö´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
CVE-2020-10620ÊÇÊÚȨÎÊÌâ·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚÓëSoftPAC½øÐÐͨѶʱ²¢²»±ØÒªÈÎºÎÆ¾Ö¤¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ֱ½ÓÓëSoftPACͨѶ£¬£¬£¬£¬£¬Ô̺¬Ô¶³ÌÖÕ³¡·þÎñ¡£¡£¡£¡£¡£¡£¡£
ÀûÓÃÕâЩCVE½øÐй¥»÷µÄMITER ATT&CK·ÖÀàÔ̺¬£º
0x02 ´ëÖý¨Òé
ÓÉÓÚÉÏÊö·ì϶½öÓ°Ïì9.6ºÍ¸üµÍ°æ±¾µÄSoftPAC Project£¬£¬£¬£¬£¬Òò¶øÄܹ»Í¨¹ý¸üÐÂÖÁ×îа汾µÄSoftPAC Project Professional»òSoftPAC Project BasicÀ´»º½âÕâЩ·ì϶¡£¡£¡£¡£¡£¡£¡£
https://www.opto22.com/support/resources-tools/downloads/pac_project_basic?ext=
һʱ´ëÊ©£ºÈôÊǴ˸üÐÂÎÞ·¨Á¢¼´ÉúЧ£¬£¬£¬£¬£¬½¨Òé²ÉÈ¡ÒÔÏ´ëÊ©À´×î´óˮƽµØÏ÷¼õÔÚÄúµÄ»·¾³ÖÐÀûÓÃÕâЩ·ì϶µÄ¿ÉÄÜÐÔ£º
? ÔÚ·À»ðǽÉϼල»òÏÞ¶ÈTCP¶Ë¿Ú22000£»£»£»£»£»£»
? ×î´óÏ޶ȵØÏ÷¼õËùÓнÚÔìϵͳÉ豸ºÍ/»òϵͳµÄÍøÂç¶³ö£¬£¬£¬£¬£¬²¢È·±£ÎÞ·¨´ÓInternet½Ó¼û£»£»£»£»£»£»
? ¶¨Î»·À»ðǽ·À»¤µÄ½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸£¬£¬£¬£¬£¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀ룻£»£»£»£»£»
? µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬£¬£¬£¬£¬ÇëʹÓð²È«²½Ö裬£¬£¬£¬£¬ÀýÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬£¬£¬£¬£¬²¢È·ÈÏVPN¿ÉÄÜ´æÔڵķì϶£¬£¬£¬£¬£¬Ð轫VPN¸üе½×îа汾¡£¡£¡£¡£¡£¡£¡£
0x03 ÓйØÐÂÎÅ
https://www.securityweek.com/vulnerabilities-softpac-virtual-controller-expose-ot-networks-attacks
0x04 ²Î¿¼Á´½Ó
https://blog.claroty.com/software-based-plc-vulnerabilities-enable-remote-code-execution
https://www.us-cert.gov/ics/advisories/icsa-20-135-01
0x05 ¹¦·òÏß
2020-05-20 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ