Emerson OpenEnterprise SCADA | ¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-05-290x00 Îó²î¸ÅÊö
²úÆ· |
CVE ID |
Àà ÐÍ |
Îó²îÆ·¼¶ |
Ô¶³ÌʹÓà |
Ó°Ïì¹æÄ£ |
Emerson OpenEnterprise SCADA |
CVE-2020-6970 |
BO |
ÑÏÖØ |
ÊÇ |
Emerson OpenEnterprise SCADA Server 3.1-3.3.3,2.83°æ±¾ |
CVE-2020-10640 |
MA |
ÑÏÖØ |
ÊÇ |
Emerson OpenEnterprise SCADA <= 3.3.4 |
|
CVE-2020-10632 |
IOM |
¸ßΣ |
·ñ |
||
CVE-2020-10636 |
IES |
ÖÐΣ |
·ñ |
0x01 Îó²îÏêÇé
Emerson Electric OpenEnterpriseÊÇÃÀ¹ú°¬Ä¬ÉúµçÆø£¨Emerson Electric£©¹«Ë¾µÄÒ»Ì×Ö÷ÒªÓÃÓÚÔ¶³ÌʯÓͺÍ×ÔÈ»ÆøÓ¦ÓõÄÊý¾ÝÊÕÂÞÓë¼à¿ØÏµÍ³£¨SCADA£©¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬¿¨°Í˹»ùµÄÑо¿Ö°Ô±Roman Lozko·¢Ã÷ÁËEmerson OpenEnterpriseÖеÄËĸöÇå¾²Îó²î£¬£¬£¬ÕâËĸöÎó²î»®·ÖΪ»ùÓڶѵĻº³åÇøÒç³ö¡¢È±ÉÙÉí·ÝÑéÖ¤¡¢ËùÓÐȨÖÎÀí²»µ±ºÍÈõ¼ÓÃÜÎÊÌ⣬£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º
CVE-2020-6970ÊÇEmerson Electric OpenEnterprise SCADA ServerÖб£´æµÄ»º³åÇøÒç³öÎó²î£¬£¬£¬CVE-2020-10640ÊÇEmerson Electric OpenEnterpriseÖб£´æµÄÇå¾²Îó²î¡£¡£¡£¡£ÒÔÉÏÁ½¸öÎó²î¶¼±»ÆÀ¼¶Îª¡°ÑÏÖØ¡±£¬£¬£¬¿ÉÒÔʹ¹¥»÷ÕßÔÚÔËÐÐOpenEnterpriseµÄ×°±¸ÉÏÒÔÌáÉýµÄÌØÈ¨Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
CVE-2020-10632ÊÇEmerson Electric OpenEnterpriseÖб£´æµÄÇå¾²Îó²î£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòΪÎļþ¼ÐÉèÖÃÁ˲»Çå¾²µÄȨÏÞ¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÐÞ¸ÄÖ÷ÒªµÄÉèÖÃÎļþ£¬£¬£¬Ôì³Éϵͳ¹ÊÕÏ»òÒì³£¡£¡£¡£¡£
CVE-2020-10636ÊÇEmerson Electric OpenEnterpriseÖб£´æµÄ¼ÓÃÜÎÊÌâÎó²î¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡OpenEnterpriseÓû§ÕÊ»§µÄÃÜÂë¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º
https://www.emerson.com/
0x03 Ïà¹ØÐÂÎÅ
https://www.securityweek.com/vulnerabilities-found-emerson-scada-product-made-oil-and-gas-industry
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-049-02
https://www.us-cert.gov/ics/advisories/icsa-20-140-02
0x05 ʱ¼äÏß
2020-05-29 VSRCÐû²¼Îó²îͨ¸æ
