B&R AutomatioºÍmbConnect | ¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-10-02

0x00 Îó²î¸ÅÊö

Ëæ×ÅÒßÇéµÄÊ¢ÐÐ £¬£¬£¬£¬£¬£¬£¬Ô½À´Ô½¶àµÄ¹«Ë¾ÒÀÀµÔ¶³Ì»á¼ûϵͳÀ´Î¬»¤Æä¹¤ÒµÉú²ú £¬£¬£¬£¬£¬£¬£¬¹¤ÒµÔ¶³Ì»á¼ûϵͳµÄʹÓÃÒ²Ô½À´Ô½ÆµÈÔ¡£¡£¡£¡£¡£¿ËÈÕOTORIOµÄÑо¿Ö°Ô±×î½ü·¢Ã÷ÁËB&R AutomatioµÄSiteManagerºÍGateManager £¬£¬£¬£¬£¬£¬£¬ÒÔ¼°mbConnectµÄmbConnect24ÕâÁ½ÖÖÊ¢ÐеĹ¤ÒµÔ¶³Ì»á¼ûϵͳ±£´æ¶à¸öÑÏÖØÇå¾²Îó²î¡£¡£¡£¡£¡£ÕâЩÎó²î¿ÉÒÔ±»¹¥»÷ÕßÓÃÀ´»á¼û¹¤ÒµÉú²ú³µ¼ä¡¢ÈëÇÖ¹«Ë¾ÍøÂç¡¢¸Ä¶¯Êý¾Ý»òÇÔÈ¡Ãô¸ÐµÄÉÌÒµÉñÃØµÈ¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

 image.png

 

SiteManagerºÍGateManagerÊÇB&R Automatio¹«Ë¾Çå¾²Ô¶³Ìά»¤Ì×¼þµÄÒ»²¿·Ö¡£¡£¡£¡£¡£mbConnectµÄmbConnect24Ö÷ÒªÓÃÓÚÓ빤ҵ×ʲúµÄÔ¶³ÌÅþÁ¬¡£¡£¡£¡£¡£ËüÃÇÅäºÏΪÆû³µ¡¢ÄÜÔ´¡¢Ê¯ÓͺÍ×ÔÈ»Æø¡¢½ðÊô¡¢°ü×°ºÍº£Ô˵ÈÐÐÒµµÄÊýǧ¸öÕ¾µãÌṩԶ³Ì»á¼ûЧÀÍ¡£¡£¡£¡£¡£

SiteManagerºÍGateManager¿ÉÒÔʹרҵ²Ù×÷Ö°Ô±´ÓÌìÏÂÈκεط½Ô¶³Ì»á¼ûºÍά»¤¹¤Òµ»úе £¬£¬£¬£¬£¬£¬£¬Èç¼ìË÷ÈÕÖ¾ºÍÓ¦ÓóÌÐòÊý¾ÝµÈ¡£¡£¡£¡£¡£´Ë´ÎÉæ¼°µÄÁù¸öµÄSiteManagerºÍGateManagerÇå¾²Îó²îÈçÏ£º

 

Îó²î±àºÅ

Îó²îÀàÐÍ

Îó²î¼òÊö

ÑÏÖØË®Æ½

ÆÀ·Ö

CVE-2020-11641

·¾¶±éÀú

¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÐÔ¿ÉÒÔ¶ÁȡЧÀÍÉèÖÃºÍÆäËûÃô¸ÐÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬²¢ÀÄÓôËÐÅÏ¢¾ÙÐÐSiteManagerʵÀýÉϵĶñÒâ»î¶¯¡£¡£¡£¡£¡£

¸ß

7.7

CVE-2020-11642

×ÊÔ´ÏûºÄ²»ÊÜ¿ØÖÆ

¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÄÜ»áÖØ¸´´¥·¢SiteManagerʵÀýµÄÖØÐÂÆô¶¯ £¬£¬£¬£¬£¬£¬£¬´Ó¶øÏÞÖÆ¿ÉÓÃÐÔ¡£¡£¡£¡£¡£

¸ß

7.7

CVE-2020-11643

ÐÅϢй¶

¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÍøÂçÓйØÊôÓÚÍâ¹ú×éÖ¯µÄ×°±¸µÄÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬²¢½«ÕâЩÐÅÏ¢ÓÃÓÚ¶ñÒâ»î¶¯¡£¡£¡£¡£¡£

ÖÐ

6.5

CVE-2020-11644

Éí·ÝÑéÖ¤²»×¼È·

¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÑ¡ÔñµÄÐé¹¹ÉóºËÐÂÎÅ/¾¯±¨À´ÓÕÆ­ÍâÓòÓû§¡£¡£¡£¡£¡£

ÖÐ

6.5

CVE-2020-11645

×ÊÔ´ÏûºÄ²»ÊÜ¿ØÖÆ

¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÄÜ»áÖØ¸´´¥·¢GateManagerʵÀýµÄÖØÆô £¬£¬£¬£¬£¬£¬£¬´Ó¶øÏÞÖÆÁËËüÃǵĿÉÓÃÐÔ¡£¡£¡£¡£¡£

ÖÐ

6.5

CVE-2020-11646

ÐÅϢй¶

¾­ÓÉÉí·ÝÑéÖ¤µÄµÐÊÖ¿ÉÒÔÉó²éÓйØÊôÓÚÆäÓòµÄËùÓÐ×°±¸µÄÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬²¢½«´ËÐÅÏ¢ÓÃÓÚ¶ñÒâ»î¶¯¡£¡£¡£¡£¡£  

ÖÐ

4.3

 

¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÕâ6¸öÐÂÎó²î»ñµÃϵͳµÄÊÚȨ»á¼ûȨÏÞ¡¢Éó²éÆäËûÓû§µÄ×ʲúºÍÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬£¬ºÚ¿Í»¹¿ÉÒÔͨ¹ýʹÓÃÐéαµÄϵͳÐÂÎź;¯±¨½«Óû§ÓÕÆ­µ½¶ñÒâµÄÍⲿվµã £¬£¬£¬£¬£¬£¬£¬²¢´¥·¢GateManagerºÍSiteManagerµÄÖØÐÂÆô¶¯ £¬£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂÉú²úϵͳµÄ¿ÉÓÃÐÔϽµ²¢×èÖ¹Éú²ú¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ£

SiteManager v9.2.620236042֮ǰµÄËùÓа汾

GateManager 4260ºÍ9250 v9.0.20262֮ǰµÄËùÓа汾

GateManager 8250 v9.2.620236042֮ǰµÄËùÓа汾

¸ü¶àÏêϸÐÅÏ¢Çë²Î¿¼£º

https://us-cert.cisa.gov/ics/advisories/icsa-20-273-03

 

´Ë´Î»¹·¢Ã÷ÁËmymbCONNECT24ºÍmbCONNECT24ÖеĶà¸öÇå¾²Îó²î £¬£¬£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹÓÃSQL×¢Èë»á¼ûí§ÒâÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬Í¨¹ýÖ´ÐпçÕ¾µãÇëÇóαÔ죨CSRF£©À´ÇÔÈ¡»á»°ÏêϸÐÅÏ¢£º

Îó²î±àºÅ

Îó²îÀàÐÍ

Îó²î¼òÊö

ÑÏÖØË®Æ½

ÆÀ·Ö

CVE-2020-24569

SQL×¢Èë

knximport×é¼þÖб£´æÒ»¸öSQLäעעÈëÎó²î £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»á¼ûí§ÒâÐÅÏ¢¡£¡£¡£¡£¡£

¸ß

7.1

CVE-2020-24568

SQL×¢Èë

lancompenent×é¼þÖб£´æÒ»¸öSQLäעעÈëÎó²î £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»á¼ûí§ÒâÐÅÏ¢¡£¡£¡£¡£¡£

¸ß

7.1

CVE-2020-24570

CSRF

com_mb24proxyÄ£¿£¿£¿éÖб£´æÒ»¸öSSRFºÍCSRFÎó²î £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓöñÒâµÄÁ´½Ó´ÓµÇ¼µÄÓû§ÄÇÀïÇÔÈ¡»á»°ÐÅÏ¢¡£¡£¡£¡£¡£

¸ß

8.8

δ·ÖÅÉ

ÏÂÁî×¢Èë

¹¥»÷Õß¿ÉÄÜ»áʹÓÃÓë¸ÃÈí¼þÀ¦°óÔÚÒ»ÆðµÄ¹ýʱÇÒδʹÓõĵÚÈý·½Èí¼þÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£

¸ß

9.8

 

Ó°Ïì¹æÄ£

mymbCONNECT24 v2.6.1¼°¸üµÍ°æ±¾

mbCONNECT24 v2.6.1¼°¸üµÍ°æ±¾

¸ü¶àÏêϸÐÅÏ¢Çë²Î¿¼£º

https://us-cert.cisa.gov/ics/advisories/icsa-20-273-01

 

 

0x02 ´¦Öóͷ£½¨Òé

1.ÏÖÔÚÏà¹ØÎó²îÒѱ»ÐÞ¸´ £¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾¡£¡£¡£¡£¡£

GateManagerºÍSiteManager£º

SiteManager v9.2.620236042

GateManager 4260ºÍ9250 v9.0.20262

GateManager 8250 v9.2.620236042

ÏÂÔØÁ´½Ó£º

https://www.br-automation.com/en/downloads/

 

ymbCONNECT24ºÍmbCONNECT24£º

¸üе½°æ±¾2.6.2»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://downloadportal.mbconnectline.com/en/

 

0x03 ²Î¿¼Á´½Ó

https://www.otorio.com/news-events/press-release/otorio-discovers-critical-vulnerabilities-in-leading-industrial-remote-access-software-solutions/

https://www.br-automation.com/downloads_br_productcatalogue/assets/1600003183751-de-original-1.0.pdf

https://us-cert.cisa.gov/ics/advisories/icsa-20-273-01

https://us-cert.cisa.gov/ics/advisories/icsa-20-273-03

https://securityaffairs.co/wordpress/108946/hacking/vulnerable-exchange-servers.html?utm_source=rss&utm_medium=rss&utm_campaign=vulnerable-exchange-servers

 

0x04 ʱ¼äÏß

2020-09-30  OTORIOÐû²¼Ç徲ͨ¸æ

2020-10-02  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



 image.png