CVE-2020-6994| ºÕ˹ÂüHiOSºÍHiSecOS²úÆ·Çå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-01

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-6994

ʱ    ¼ä

2020-04-01

Àà    ÐÍ

»º³åÇøÒç³ö

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

HiOS <= 07.0.02 Ó°Ïì²úÆ·£ºRSP£¬£¬£¬RSPE£¬£¬£¬RSPS£¬£¬£¬RSPL£¬£¬£¬MSP£¬£¬£¬EES£¬£¬£¬ EESX£¬£¬£¬GRS£¬£¬£¬OS£¬£¬£¬RED½»Á÷»ú£»£»£» £»£»

HiSecOS0 <= 3.2.00 Ó°Ïì²úÆ·£ºEAGLE 20/30·À»ðǽ

x01 Îó²îÏêÇé


µÂ¹úºÕ˹Âü×Ô¶¯»¯ºÍ¿ØÖƹ«Ë¾½¨ÉèÓÚ1924Ä꣬£¬£¬ÓªÒµÂþÑÜÔÚ×Ô¶¯»¯Í¨Ñ¶ÁìÓò£¬£¬£¬²úÆ·¹æÄ£°üÀ¨½ÓÄÉÄ£ÄâºÍÊý×ֹ㲥µçÊÓ´«ÊäÊÖÒÕµÄÒÆ¶¯·¢ÉäºÍÎüÊÕϵͳ£¬£¬£¬ÆóÒµºÍ¹¤ÒµÍøÂç½â¾ö¼Æ»®ÒÔ¼°ÏÖ³¡×ÜÏßϵͳ¡£¡£¡£¡£ºÕ˹ÂüÔÚ2007Äê±»ÃÀ¹ú°Ùͨ£¨Belden£©¹«Ë¾ÊÕ¹º¡£¡£¡£¡£ºÕ˹ÂüHiOSºÍHiSecOS¶¼ÊǰÙÍ¨ÍÆ³öµÄÇå¾²²Ù×÷ϵͳ¡£¡£¡£¡£


HiOSºÍHiSecOSµÄHTTP(S)web serverÖб£´æÒ»¸ö»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ¶ÔURL²ÎÊýµÄÆÊÎö²»µ±ÒýÆðµÄ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ½èÖúÌØÖÆµÄHTTPÇëÇóÈëÇÖÄ¿µÄ×°±¸£¬£¬£¬Ôì³ÉÄÚ²¿»º³åÇøÒç³ö¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬½¨ÒéHiOSÓû§¾¡¿ì¸üÐÂÖÁ07.0.03»ò¸ü¸ß°æ±¾£¬£¬£¬HiSecOSÓû§¸üÐÂÖÁ03.3.00»ò¸ü¸ß°æ±¾¡£¡£¡£¡£

ÔÝʱ²½·¥¿ÉʹÓá°IP»á¼ûÏÞÖÆ¡±¹¦Ð§£¬£¬£¬ÏÞÖÆHTTPºÍHTTPS¶Ô¿ÉÐÅIPµØµãµÄ»á¼û£¬£¬£¬»òÕß½ûÓÃHTTPºÍHTTPSЧÀÍÆ÷¡£¡£¡£¡£


https://www.belden.com/hubfs/support/security/bulletins/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf?hsLang=en


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-091-01


0x05 ʱ¼äÏß


2020-02-14 Ðû²¼Îó²î

2020-02-26 ÍÆ³ö½â¾ö¼Æ»®

2020-03-24 »ñµÃCVE±àºÅ