Phoenix Contact Automation Worx¶à¸öÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-06-26Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12870£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ³§ÉÌ×ÔÆÀ£º7.8£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12871£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ³§ÉÌ×ÔÆÀ£º7.8£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ÊÊÓÃÓÚPhoenix Contact Automation Worx Software SuiteÖеÄPC Worx 1.86¼°Ö®Ç°°æ±¾¡¢PC Worx Express 1.86¼°Ö®Ç°°æ±¾ºÍConfig+ 1.86¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£¡£¡£
Îó²î¸ÅÊö
Phoenix Contact Automation Worx Software SuiteÊǵ¹ú·ÆÄá¿Ë˹µçÆø£¨Phoenix Contact£©¹«Ë¾µÄÒ»Ì××Ô¶¯»¯WorxÈí¼þÌ×¼þ¡£¡£¡£¡£¡£¡£¡£PC WorxÊÇÆäÖеÄÒ»Ì׿ØÖÆÆ÷±à³ÌÈí¼þ¡£¡£¡£¡£¡£¡£¡£Config+ÊÇÆäÖеÄÒ»Ì×ÓÃÓÚÉèÖúÍÕï¶ÏINTERBUSϵͳµÄÈí¼þ¡£¡£¡£¡£¡£¡£¡£
Phoenix Contact Automation WorxÖб£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬£¬ÏêϸÈçÏ£º
CVE-2019-12869£º
¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬£¬£¬£¬£¬£¬Î´×¼È·ÑéÖ¤Êý¾Ý½çÏߣ¬£¬£¬£¬£¬£¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æÎ»ÖÃÉÏÖ´ÐÐÁ˹ýʧµÄ¶Áд²Ù×÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£¡£¡£¡£¡£¡£¡£
CVE-2019-12870£º
¸ÃÎó²îÔ´ÓÚÔÚ»á¼ûÖ¸Õë֮ǰȱÉÙÊʵ±µÄÖ¸Õë³õʼ»¯¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÄ¿½ñÀú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë
¡£¡£¡£¡£¡£¡£¡£
CVE-2019-12871£º
¸ÃÎó²îÔ´ÓÚÔÚ¶Ô¹¤¾ßÖ´ÐвÙ×÷֮ǰȱ·¦ÑéÖ¤¹¤¾ßÊÇ·ñ±£´æ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÄ¿½ñÀú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º
https://www.phoenixcontact.com/
²Î¿¼Á´½Ó
https://www.zerodayinitiative.com/advisories/ZDI-19-575/
https://www.zerodayinitiative.com/advisories/ZDI-19-576/