CVE-2020-10939| Phoenix Contact PC WORX SRTȨÏÞÌáÉýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-22

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-10939

ʱ   ¼ä

2020-04-22

Àà    ÐÍ

EOP

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£

PHOENIX CONTACT PC WORX SRT <=1.14


0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Phoenix Contact PC WORX SRTÊǵ¹ú·ÆÄá¿Ë˹µçÆø£¨Phoenix Contact£©¹«Ë¾µÄÒ»¿î¿É±à³ÌÂß¼­¿ØÖÆÆ÷¡£¡£¡£¡£¡£¡£¡£

Phoenix Contact PC WORX SRT 1.14¼°Ö®Ç°°æ±¾Öб£´æÈ¨ÏÞÌáÉýÎó²î£¬£¬£¬¸ÃÎó²îÔ´ÓÚ²»Çå¾²µÄĬÈÏ·¾¶È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£CVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£¡£¡£

PC WORX SRTÊÇPhoenix ContactÓ¦ÓÃÖеÄЧÀͳÌÐò¡£¡£¡£¡£¡£¡£¡£¸Ã³ÌÐòµÄ×°Ö÷¾¶ÉèÖñ£´æ²»Çå¾²µÄȨÏÞ£¬£¬£¬¸ÃȨÏÞÔÊÐíÈκÎδÊÚȨÓû§½«í§ÒâÎļþдÈë¸ÃЧÀ͵ÄËùÓÐÉèÖÃÎļþºÍ¶þ½øÖÆÎļþËùÔÚµÄ×°ÖÃĿ¼¡£¡£¡£¡£¡£¡£¡£

¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÓöñÒâ¶þ½øÖÆÎļþÁýÕÖÖ÷ÒªµÄ¡° PC WORX SRT¡±Ð§ÀÍ£¬£¬£¬µ¼ÖÂÒÔϵͳȨÏÞÔËÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥£¬£¬£¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³ÒÔ»ñÈ¡½â¾ö²½·¥£º

https://www.phoenixcontact.com/


0x03 Ïà¹ØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-10939


0x04 ²Î¿¼Á´½Ó


https://cert.vde.com/en-us/advisories/vde-2020-012

https://nvd.nist.gov/vuln/detail/CVE-2020-10939

https://www.cnvd.org.cn/flaw/show/CNVD-2020-20687


0x05 ʱ¼äÏß


2020-03-27 CVEÐû²¼¸ÃÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨