Schneider | ¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-05-080x00 Îó²î¸ÅÊö
0x01 Îó²îÏêÇé

Ê©ÄÍµÂµçÆø¹«Ë¾ÊÇÈ«ÇòÄÜЧÖÎÀíÁìÓòµÄÏòµ¼Õߣ¬£¬£¬£¬£¬£¬£¬Îª100¶à¸ö¹ú¼ÒµÄÄÜÔ´¼°»ù´¡ÉèÊ©¡¢¹¤Òµ¡¢Êý¾ÝÖÐÐļ°ÍøÂ硢¥ÓîºÍסլÊг¡ÌṩÕûÌå½â¾ö¼Æ»®¡£¡£¡£¡£¡£Schneider Electric Modicon M580µÈ¶¼ÊǸù«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£
×î½ü£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÓÖ´ÓÊ©ÄÍµÂµçÆøÈí¼þÖз¢Ã÷ÁËÒ»¸öÎó²î£¨CVE-2020-7489£©£¬£¬£¬£¬£¬£¬£¬ËüÀàËÆÓÚÎÛÃûÕÑÖøµÄ¡°ÕðÍø¡±²¡¶¾(Stuxnet)¶ñÒâÈí¼þÔøÊ¹ÓõÄÎó²î¡£¡£¡£¡£¡£
Ê®¶àÄêǰ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úºÍÒÔÉ«Áб»Ö¸Ê¹Óá°ÕðÍø¡±²¡¶¾Ëðº¦ÒÁÀʵĺËÍýÏ룬£¬£¬£¬£¬£¬£¬Ä¿µÄÊÇÎ÷ÃÅ× SIMATIC S7-300ºÍS7-400¿É±à³ÌÂß¼¿ØÖÆÆ÷(PLCs)¡£¡£¡£¡£¡£Õâ¿î¶ñÒâÈí¼þͨ¹ýÌæ»»½«ÓëÎ÷ÃÅ×Ó STEP7¿ØÖÆÆ÷±à³ÌÈí¼þÏà¹ØÁªµÄÒ»¸öDLLÎļþ£¬£¬£¬£¬£¬£¬£¬½«¶ñÒâ´úÂë¼ÓÔØµ½Ä¿µÄPLCsÉÏ¡£¡£¡£¡£¡£
2020Äê3Ô·ݣ¬£¬£¬£¬£¬£¬£¬AirbusÍøÂçÇå¾²¹«Ë¾±¨µÀ³Æ´ÓÊ©ÄÍµÂµçÆøµÄEcoStruxure ControlExpert¹¤³ÌÈí¼þ£¨´ËǰÃûΪ Unity Pro£©Öз¢Ã÷ÁËÒ»¸öÀàËÆÎó²î CVE-2020-7475£¬£¬£¬£¬£¬£¬£¬Ëü¿Éͨ¹ýÌæ»»Óë¸Ã¹¤³ÌÈí¼þÏà¹ØÁªµÄÆäÖÐÒ»¸öDLLÎļþ£¬£¬£¬£¬£¬£¬£¬½«¶ñÒâ´úÂëÉÏ´«µ½Modicon M340 ºÍM580 PLCsÖУ¬£¬£¬£¬£¬£¬£¬´Ó¶øÔì³ÉÀú³ÌÆÆËðºÍÆäËüË𺦡£¡£¡£¡£¡£CVE-2020-7475ÊǶà¿îSchneider Electric²úÆ·Öб£´æµÄ×¢ÈëÎó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÏò¿ØÖÆÆ÷Öз¢ËͶñÒâ´úÂë¡£¡£¡£¡£¡£CVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£
2020Äê5ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾TrustwaveµÄÑо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ËûÃÇÒ²´ÓÊ©Ä͵ÂÈí¼þ EcoStruxure MachineExpert£¨´ËǰÃûΪSoMachine£©Öз¢Ã÷ÁËÒ»¸öÀàËÆÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îΪ CVE-2020-7489£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î½«¶ñÒâ´úÂë´«Êäµ½¿ØÖÆÆ÷¡£¡£¡£¡£¡£CVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://www.se.com/ww/en/download/document/SEVD-2020-080-01/
https://www.se.com/ww/en/download/document/SEVD-2020-105-01/
0x03 Ïà¹ØÐÂÎÅ
https://www.securityweek.com/another-stuxnet-style-vulnerability-found-schneider-electric-software
0x04 ²Î¿¼Á´½Ó
http://www.se.com/ww/en/download/document/SEVD-2020-080-01
https://www.se.com/ww/en/download/document/SEVD-2020-105-01
0x05 ʱ¼äÏß
2020-05-08 VSRCÐû²¼Îó²îͨ¸æ
