CVE-2020-10607| Advantech WebAccess»º³åÇøÒç³öÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-22

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-10607

ʱ   ¼ä

2020-04-22

Àà    ÐÍ

BO

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Advantech WebAccess <=8.4.2




0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨




Advantech WebAccessÊÇÖйų́ÍåÑлª£¨Advantech£©¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¡£¡£¡£¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý¿ØÖÆ£¬£¬£¬ £¬£¬£¬²¢ÌṩԶ³Ì¿ØÖƺÍÖÎÀí×Ô¶¯»¯×°±¸µÄ¹¦Ð§¡£¡£¡£¡£¡£

Advantech WebAccess 8.4.2¼°Ö®Ç°°æ±¾Öб£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷУÑéÓû§Ìá½»Êý¾ÝµÄ³¤¶È¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐдúÂë¡£¡£¡£¡£¡£CVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬ £¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.advantech.com.cn/

±ðµÄ£¬£¬£¬ £¬£¬£¬½¨ÒéÏà¹ØÓû§Ó¦½ÓÄɵįäËûÇå¾²·À»¤²½·¥ÈçÏ£º

£¨1£© ×î´óÏ޶ȵØïÔÌ­ËùÓпØÖÆÏµÍ³×°±¸ºÍ/»òϵͳµÄÍøÂç̻¶£¬£¬£¬ £¬£¬£¬²¢È·±£ÎÞ·¨´ÓInternet»á¼û£» £»£»£»

£¨2£© ¶¨Î»·À»ðǽ·À»¤µÄ¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸£¬£¬£¬ £¬£¬£¬²¢½«ÆäÓëÓªÒµÍøÂç¸ôÀ룻 £»£»£»

£¨3£© µ±ÐèÒªÔ¶³Ì»á¼ûʱ£¬£¬£¬ £¬£¬£¬ÇëʹÓÃÇå¾²ÒªÁ죬£¬£¬ £¬£¬£¬ÀýÈçÐéÄâרÓÃÍøÂ磨VPN£©£¬£¬£¬ £¬£¬£¬²¢È·ÈÏVPN¿ÉÄܱ£´æµÄÎó²î£¬£¬£¬ £¬£¬£¬Ð轫VPN¸üе½×îа汾¡£¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://www.auscert.org.au/bulletins/ESB-2020.1084/


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-086-01

https://nvd.nist.gov/vuln/detail/CVE-2020-10607

https://www.cnvd.org.cn/flaw/show/CNVD-2020-19926


0x05 ʱ¼äÏß


2020-03-26 CVEÐû²¼¸ÃÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨