¸»Ê¿µç»úËÅ·þϵͳºÍÇý¶¯0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-09-30

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-14794£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-14788£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ5.3£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Alpha5 Smart Loader Versions 3.7¼°Ö®Ç°°æ±¾


Îó²î¸ÅÊö


ICS-CERT ºÍÇ÷ÊÆ¿Æ¼¼ ZDI ÍŶӱ¾ÖÜÅû¶³Æ£¬£¬ £¬ÈÕ±¾¸»Ê¿µç»ú¹«Ë¾µÄËÅ·þϵͳºÍÇý¶¯Öб£´æ¶à¸öδÐÞ¸´µÄÎó²î¡£¡£¡£ ¡£¡£¡£¡£Ñо¿Ô± Michael Flanders ÔÚ¸»Ê¿µç»úµÄ Alpha 5 ÖÇÄÜËÅ·þϵͳLoader Èí¼þÖз¢Ã÷ÁËÁ½¸öÎó²î¡£¡£¡£ ¡£¡£¡£¡£


ÊÜÓ°Ïì²úÆ·Ö÷ÒªÓÃÓÚÅ·ÖÞºÍÑÇÖÞµÄÉÌÒµÉèÊ©ºÍÒªº¦ÖÆÔìÐÐÒµÖУ¬£¬ £¬×÷ÓÃÊÇͨ¹ýµ÷½â£¬£¬ £¬Ê¹Çý¶¯¶àÖÖ»úеµÄµç¶¯ÐÔÄܹ»×¼È·ÔËÐС£¡£¡£ ¡£¡£¡£¡£


ÆäÖÐÒ»¸öÎó²îÊÇÑÏÖØµÄ¶Ñ»º³åÇøÒç³ö (CVE-2018-14794) Îó²î£¬£¬ £¬Äܵ¼ÖÂÔ¶³Ì¹¥»÷ÕßÓÕÆ­Ä¿µÄ·­¿ªÒ»¸öÌØÊâ½á¹¹µÄ C5V Îļþ£¬£¬ £¬´Ó¶øÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£¡£ZDI ÔÚÇ徲ͨ¸æÖÐÖ¸³ö£¬£¬ £¬¡°Õâ¸öÎÊÌⱬ·¢µÄÔµ¹ÊÔ­ÓÉÊÇÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´ÖƵ½Ò»¸ö³¤¶ÈÀο¿ÇÒ»ùÓڶѵĻº³å֮ǰ£¬£¬ £¬È±·¦¶Ô¸ÃÊý¾ÝµÄ׼ȷÑéÖ¤¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹ÓÃÕâ¸öÎó²îÔÚÖÎÀíÔ±ÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£¡£¡±

Ó°ÏìËÅ·þϵͳµÄµÚ¶þ¸öÎó²îÊÇÒ»ÆäÖÐΣµÄ»º³åÇøÒç³öÎó²î£¬£¬ £¬¿Éµ¼ÖÂÔÚ´¦Öóͷ£ÌØÊâ½á¹¹µÄ A5P Îļþʱ£¬£¬ £¬Ãô¸ÐÐÅÏ¢Ôâ̻¶¡£¡£¡£ ¡£¡£¡£¡£µ±Á¬ÏµÆäËüÎó²îʹÓÃʱ£¬£¬ £¬¹¥»÷ÕßÄܹ»ÒÔÖÎÀíԱȨÏÞʹÓøà bug Ö´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC\EXP


ÐÞ¸´½¨Òé


ZDI ¸øÓ踻ʿµç»ú120ÌìµÄʱ¼äÐÞ¸´¸ÃÎó²î¡£¡£¡£ ¡£¡£¡£¡£¸»Ê¿µç»ú±¾Öܹ²Ðû²¼5ƪÇ徲ͨ¸æ£¬£¬ £¬ÏÖÔÚÓÉÓÚÉÐÎ´ÍÆ³ö²¹¶¡£¬£¬ £¬Òò´ËËüÃǾùÊôÓÚ 0day Îó²î״̬¡£¡£¡£ ¡£¡£¡£¡£


¸»Ê¿µç»ú¹«Ë¾ÌåÏÖÕýÔÚÍÆ³ö²¹¶¡¼Æ»®¡£¡£¡£ ¡£¡£¡£¡£ÔÚ´Ë֮ǰ£¬£¬ £¬¸Ã¹«Ë¾½¨ÒéÓû§×èÖ¹ÔÚÊÜÓ°ÏìÓ¦ÓóÌÐòÖв»ÊÜÐÅÈεÄÎļþ¡£¡£¡£ ¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-270-02
https://www.securityweek.com/no-patches-critical-flaws-fuji-electric-servo-system-drives