Phoenix Contact Automation Worx¶à¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-26

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12869£¬£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºµÍΣ£¬£¬£¬£¬£¬ £¬CVSS·ÖÖµ³§ÉÌ×ÔÆÀ£º3.3£¬£¬£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12870£¬£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ £¬CVSS·ÖÖµ³§ÉÌ×ÔÆÀ£º7.8£¬£¬£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-12871£¬£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ £¬CVSS·ÖÖµ³§ÉÌ×ÔÆÀ£º7.8£¬£¬£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚPhoenix Contact Automation Worx Software SuiteÖеÄPC Worx 1.86¼°Ö®Ç°°æ±¾¡¢PC Worx Express 1.86¼°Ö®Ç°°æ±¾ºÍConfig+ 1.86¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£¡£¡£


Îó²î¸ÅÊö


Phoenix Contact Automation Worx Software SuiteÊǵ¹ú·ÆÄá¿Ë˹µçÆø£¨Phoenix Contact£©¹«Ë¾µÄÒ»Ì××Ô¶¯»¯WorxÈí¼þÌ×¼þ¡£¡£¡£¡£¡£¡£¡£PC WorxÊÇÆäÖеÄÒ»Ì׿ØÖÆÆ÷±à³ÌÈí¼þ¡£¡£¡£¡£¡£¡£¡£Config+ÊÇÆäÖеÄÒ»Ì×ÓÃÓÚÉèÖúÍÕï¶ÏINTERBUSϵͳµÄÈí¼þ¡£¡£¡£¡£¡£¡£¡£


Phoenix Contact Automation WorxÖб£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬ £¬ÏêϸÈçÏ£º


CVE-2019-12869£º


¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬£¬£¬£¬£¬ £¬Î´×¼È·ÑéÖ¤Êý¾Ý½çÏߣ¬£¬£¬£¬£¬ £¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æÎ»ÖÃÉÏÖ´ÐÐÁ˹ýʧµÄ¶Áд²Ù×÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£¡£¡£¡£¡£¡£¡£


CVE-2019-12870£º


¸ÃÎó²îÔ´ÓÚÔÚ»á¼ûÖ¸Õë֮ǰȱÉÙÊʵ±µÄÖ¸Õë³õʼ»¯¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÄ¿½ñÀú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë

¡£¡£¡£¡£¡£¡£¡£

CVE-2019-12871£º


¸ÃÎó²îÔ´ÓÚÔÚ¶Ô¹¤¾ßÖ´ÐвÙ×÷֮ǰȱ·¦ÑéÖ¤¹¤¾ßÊÇ·ñ±£´æ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÄ¿½ñÀú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬ £¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.phoenixcontact.com/


²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/ZDI-19-579/
https://www.zerodayinitiative.com/advisories/ZDI-19-575/
https://www.zerodayinitiative.com/advisories/ZDI-19-576/