ÂÞ¿ËΤ¶û×Ô¶¯»¯¹¤ÒµµçÄܱíÑÏÖØÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-02-22Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-19615£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ6.1£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19616£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÂÞ¿ËΤ¶û Allen-Bradley PowerMonitor 1000ËùÓа汾
Îó²î¸ÅÊö
PowerMonitor 1000ÊÇÒ»ÖÖÓÃÓÚ¹¤Òµ¿ØÖÆÓ¦ÓõĵçÄܼÆÁ¿×°±¸£¬£¬£¬£¬£¬£¬£¬Èç·ÅµçÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬¹¤Òµ¿ØÖÆÃæ°åºÍµç»ú¿ØÖÆÖÐÐÄ¡£¡£¡£¡£¡£¡£Ëü¿ÉÕÉÁ¿µç·ÖеĵçѹºÍµçÁ÷£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÒÔÌ«Íø»ò´®ÐÐÍøÂ罫µçÔ´ºÍÄÜÔ´²ÎÊý´«Ë͸øFactoryTalk EnergyMetrixTM£¬£¬£¬£¬£¬£¬£¬SCADAϵͳºÍ¿É±à³Ì¿ØÖÆÆ÷µÈÓ¦Óᣡ£¡£¡£¡£¡£
CVE-2019-19615£¬£¬£¬£¬£¬£¬£¬Ò»¸ö¿çÕ¾¾ç±¾Îó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÈÃÔ¶³Ì¹¥»÷Õß½«í§Òâ´úÂë×¢ÈëÄ¿µÄÓû§µÄWebä¯ÀÀÆ÷ÒÔ»ñÈ¡¶ÔÊÜÓ°Ïì×°±¸µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£
CVE-2019-19616£¬£¬£¬£¬£¬£¬£¬Ò»ÖÖÉí·ÝÑéÖ¤ÈÆ¹ý£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÊðÀíÀ´ÆôÓÃͨ³£¶Ô¾ßÓÐWebÓ¦ÓóÌÐòÖÎÀíȨÏÞµÄÖ°Ô±¿ÉÓõĹ¦Ð§¡£¡£¡£¡£¡£¡£ÈƹýÉí·ÝÑéÖ¤ºó£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ¸ü¸ÄÓû§ÉèÖúÍ×°±¸ÉèÖᣡ£¡£¡£¡£¡£
Îó²îÑéÖ¤
POC£º
ACSIµÄLuca Chiou£¬£¬£¬£¬£¬£¬£¬ÔÚNCCIC£¨¹ú¼ÒÍøÂçÇå¾²ºÍͨѶ¼¯³ÉÖÐÐÄ£©Öз¢Ã÷²¢±¨¸æÕâÁ½¸öÎó²î£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Ò²Ðû²¼ÁËÕë¶ÔÕâÁ½¸öÎó²îµÄPOC
https://www.exploit-db.com/exploits/45928
https://www.exploit-db.com/exploits/45937
ÐÞ¸´½¨Òé
ÏÖÔÚ»¹Ã»ÓÐÕë¶ÔÕâЩȱÏݵĿÉÓÃÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£¡£¹Ø×¢¹ÙÍøÍøÕ¾µÄ¸üУº
https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1084790
²Î¿¼Á´½Ó
https://ics-cert.us-cert.gov/advisories/ICSA-19-050-04