Rockwell AutomationÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-09-25

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-14829 £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ10 £¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-14827 £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.3 £¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-14821 £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ7.5 £¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


RSLinx Classic Versions <= 4.00.01


Îó²î¸ÅÊö


Rockwell Automation RSLinx ClassicÊÇÃÀ¹úÂÞ¿ËΤ¶û£¨Rockwell Automation£©¹«Ë¾µÄÒ»Ì×¹¤³§Í¨Ñ¶½â¾ö¼Æ»® ¡£¡£¡£ ¡£¡£¡£¡£¸Ã¼Æ»®Ö§³Öͨ¹ýAllen-Bradley¿É±à³Ì¿ØÖÆÆ÷»á¼ûRockwell SoftwareºÍAllen-BradleyÓ¦ÓóÌÐòµÈ ¡£¡£¡£ ¡£¡£¡£¡£ Rockwell Automation RSLinx Classic 4.00.01¼°Ö®Ç°°æ±¾Öб£´æÇå¾²Îó²î ¡£¡£¡£ ¡£¡£¡£¡£

CVE-2018-14829£º¹¥»÷Õß¿Éͨ¹ýÏò44818¶Ë¿Ú·¢ËÍ»ûÐεÄCIPÊý¾Ý°üʹÓøÃÎó²îÔì³ÉÓ¦ÓóÌÐò×èÖ¹ÏìÓ¦ £¬£¬£¬£¬£¬£¬£¬Ê¹ÆäÍ߽Ⲣ¿ÉÄÜÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£ ¡£¡£¡£¡£

CVE-2018-14827£ºÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏò44818¶Ë¿Ú·¢ËÍ»ûÐεÄCIPÊý¾Ý°üʹÓøÃÎó²îÔì³ÉRSLinx ClassicÓ¦ÓóÌÐò×èֹЧÀÍ ¡£¡£¡£ ¡£¡£¡£¡£

CVE-2018-14821£ºÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏò44818¶Ë¿Ú·¢ËÍÌØÖÆµÄEthernet/IPÊý¾Ý°üʹÓøÃÎó²îÔì³ÉÓ¦ÓóÌÐò×èÖ¹ÏìÓ¦²¢Ôì³ÉÆäÍ߽⠡£¡£¡£ ¡£¡£¡£¡£



Îó²îÑéÖ¤


ÔÝÎÞPOC\EXP
Îó²îÔ­ÀíÆÊÎö²Î¿¼£º

https://www.tenable.com/security/research/tra-2018-26


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î £¬£¬£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.rockwellautomation.com


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-263-02
https://www.securityweek.com/rockwell-automation-patches-severe-flaws-communications-software