CVE-2020-6994| ºÕ˹ÂüHiOSºÍHiSecOS²úÆ·Çå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-010x00 Îó²î¸ÅÊö
CVE ID |
CVE-2020-6994 |
ʱ ¼ä |
2020-04-01 |
Àà ÐÍ |
»º³åÇøÒç³ö |
µÈ ¼¶ |
ÑÏÖØ |
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
HiOS <= 07.0.02 Ó°Ïì²úÆ·£ºRSP£¬£¬£¬RSPE£¬£¬£¬RSPS£¬£¬£¬RSPL£¬£¬£¬MSP£¬£¬£¬EES£¬£¬£¬ EESX£¬£¬£¬GRS£¬£¬£¬OS£¬£¬£¬RED½»Á÷»ú£»£»£»£»£» HiSecOS0 <= 3.2.00 Ó°Ïì²úÆ·£ºEAGLE 20/30·À»ðǽ |
x01 Îó²îÏêÇé
µÂ¹úºÕ˹Âü×Ô¶¯»¯ºÍ¿ØÖƹ«Ë¾½¨ÉèÓÚ1924Ä꣬£¬£¬ÓªÒµÂþÑÜÔÚ×Ô¶¯»¯Í¨Ñ¶ÁìÓò£¬£¬£¬²úÆ·¹æÄ£°üÀ¨½ÓÄÉÄ£ÄâºÍÊý×ֹ㲥µçÊÓ´«ÊäÊÖÒÕµÄÒÆ¶¯·¢ÉäºÍÎüÊÕϵͳ£¬£¬£¬ÆóÒµºÍ¹¤ÒµÍøÂç½â¾ö¼Æ»®ÒÔ¼°ÏÖ³¡×ÜÏßϵͳ¡£¡£¡£¡£ºÕ˹ÂüÔÚ2007Äê±»ÃÀ¹ú°Ùͨ£¨Belden£©¹«Ë¾ÊÕ¹º¡£¡£¡£¡£ºÕ˹ÂüHiOSºÍHiSecOS¶¼ÊǰÙÍ¨ÍÆ³öµÄÇå¾²²Ù×÷ϵͳ¡£¡£¡£¡£
HiOSºÍHiSecOSµÄHTTP(S)web serverÖб£´æÒ»¸ö»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ¶ÔURL²ÎÊýµÄÆÊÎö²»µ±ÒýÆðµÄ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ½èÖúÌØÖÆµÄHTTPÇëÇóÈëÇÖÄ¿µÄ×°±¸£¬£¬£¬Ôì³ÉÄÚ²¿»º³åÇøÒç³ö¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬½¨ÒéHiOSÓû§¾¡¿ì¸üÐÂÖÁ07.0.03»ò¸ü¸ß°æ±¾£¬£¬£¬HiSecOSÓû§¸üÐÂÖÁ03.3.00»ò¸ü¸ß°æ±¾¡£¡£¡£¡£
ÔÝʱ²½·¥¿ÉʹÓá°IP»á¼ûÏÞÖÆ¡±¹¦Ð§£¬£¬£¬ÏÞÖÆHTTPºÍHTTPS¶Ô¿ÉÐÅIPµØµãµÄ»á¼û£¬£¬£¬»òÕß½ûÓÃHTTPºÍHTTPSЧÀÍÆ÷¡£¡£¡£¡£
https://www.belden.com/hubfs/support/security/bulletins/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf?hsLang=en
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-091-01
0x05 ʱ¼äÏß
2020-02-14 Ðû²¼Îó²î
2020-02-26 ÍÆ³ö½â¾ö¼Æ»®
2020-03-24 »ñµÃCVE±àºÅ