CVE-2020-10607| Advantech WebAccess»º³åÇøÒç³öÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-220x00 Îó²î¸ÅÊö
CVE ID |
CVE-2020-10607 |
ʱ ¼ä |
2020-04-22 |
Àà ÐÍ |
BO |
µÈ ¼¶ |
¸ßΣ |
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
Advantech WebAccess <=8.4.2 |
0x01 Îó²îÏêÇé

Advantech WebAccessÊÇÖйų́ÍåÑлª£¨Advantech£©¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¡£¡£¡£¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý¿ØÖÆ£¬£¬£¬£¬£¬£¬²¢ÌṩԶ³Ì¿ØÖƺÍÖÎÀí×Ô¶¯»¯×°±¸µÄ¹¦Ð§¡£¡£¡£¡£¡£
Advantech WebAccess 8.4.2¼°Ö®Ç°°æ±¾Öб£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷУÑéÓû§Ìá½»Êý¾ÝµÄ³¤¶È¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐдúÂë¡£¡£¡£¡£¡£CVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º
https://www.advantech.com.cn/
±ðµÄ£¬£¬£¬£¬£¬£¬½¨ÒéÏà¹ØÓû§Ó¦½ÓÄɵįäËûÇå¾²·À»¤²½·¥ÈçÏ£º
£¨1£© ×î´óÏ޶ȵØïÔÌËùÓпØÖÆÏµÍ³×°±¸ºÍ/»òϵͳµÄÍøÂç̻¶£¬£¬£¬£¬£¬£¬²¢È·±£ÎÞ·¨´ÓInternet»á¼û£»£»£»£»
£¨2£© ¶¨Î»·À»ðǽ·À»¤µÄ¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸£¬£¬£¬£¬£¬£¬²¢½«ÆäÓëÓªÒµÍøÂç¸ôÀ룻£»£»£»
£¨3£© µ±ÐèÒªÔ¶³Ì»á¼ûʱ£¬£¬£¬£¬£¬£¬ÇëʹÓÃÇå¾²ÒªÁ죬£¬£¬£¬£¬£¬ÀýÈçÐéÄâרÓÃÍøÂ磨VPN£©£¬£¬£¬£¬£¬£¬²¢È·ÈÏVPN¿ÉÄܱ£´æµÄÎó²î£¬£¬£¬£¬£¬£¬Ð轫VPN¸üе½×îа汾¡£¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
https://www.auscert.org.au/bulletins/ESB-2020.1084/
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-086-01
https://nvd.nist.gov/vuln/detail/CVE-2020-10607
https://www.cnvd.org.cn/flaw/show/CNVD-2020-19926
0x05 ʱ¼äÏß
2020-03-26 CVEÐû²¼¸ÃÎó²î
