¡¾Îó²îͨ¸æ¡¿OPCÐÒé¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-01-260x00 Îó²î¸ÅÊö
¿ª·Åƽ̨ͨѶ£¨OPC£©ÍøÂçÐÒéÊDzÙ×÷ÊÖÒÕ£¨OT£©ÍøÂçµÄÖÐÐÄÈË£¬£¬£¬£¬È·±£¹¤Òµ¿ØÖÆÏµÍ³£¨ICS£©ºÍרÓÐ×°±¸Ö®¼äµÄ¿É²Ù×÷ÐÔ£¬£¬£¬£¬ÈçÈÏÕæÏÖ³¡×°±¸×¼È·²Ù×÷µÄ¿É±à³ÌÂß¼¿ØÖÆÆ÷(PLC)¡£¡£¡£¡£OPC½ÓÄɱê×¼»¯µÄͨѶÐÒé¼°Æä¹æ·¶£¨OPC DA¡¢AE¡¢HDA¡¢XML DA¡¢DXºÍOPC UA£©£¬£¬£¬£¬°ü¹ÜÁ˶Ô×°±¸ºÍÀú³ÌµÄÖÎÀíºÍ¼àÊÓ¿ÉÒÔ´ÓÒ»¸ö¼¯ÖеÄЧÀÍÆ÷ÉϾÙÐУ¬£¬£¬£¬Æäͨ³£×÷ΪһÖÖÔÚICSÓòÖеÄ×°±¸ÖÐÔËÐеÄǶÈëʽÐÒé¶ø±»ÆÕ±éʹÓᣡ£¡£¡£
2021Äê01ÔÂ25ÈÕ£¬£¬£¬£¬ClarotyÑо¿Ð¡×éÅû¶ÁËMatrikon Honeywell ¡¢ Softing Industrial Automation GmbH ºÍPTC KepwareµÄOPCÖб£´æµÄ¶à¸öÇå¾²Îó²î¡£¡£¡£¡£
0x01 Îó²îÏêÇé
±»Åû¶µÄOPCÎó²îÈçÏ£º
²úÆ· | CVE ID | Àà ÐÍ | Îó²îÆ·¼¶ | Ó°Ïì |
£¨Softing Industrial Automation GmbH£© OPC | CVE-2020-14524 | »ùÓڶѵĻº³åÇøÒç³ö | ÑÏÖØ | ЧÀÍÍ߽⡢´úÂëÖ´ÐÐ |
CVE-2020-14522 | ×ÊÔ´ÏûºÄ | ¸ßΣ | ¾Ü¾øÐ§ÀÍ | |
£¨Honeywell£© OPC UA Tunneller | CVE-2020-27297 | »ùÓڶѵĻº³åÇøÒç³ö | ÑÏÖØ | RCE |
CVE-2020-27299 | Ô½½ç¶ÁÈ¡ | ¸ßΣ | ÐÅϢй¶¡¢×°±¸Íß½â | |
CVE-2020-27274 | ¼ì²é²»µ± | ¸ßΣ | ¾Ü¾øÐ§ÀÍ | |
CVE-2020-27295 | ×ÊÔ´ÏûºÄ | ¸ßΣ | ¾Ü¾øÐ§ÀÍ | |
£¨PTC£© Kepware KEPServerEX | CVE-2020-27265 | »ùÓڶѵĻº³åÇøÒç³ö | ÑÏÖØ | ЧÀÍÍ߽⡢RCE |
CVE-2020-27263 | »ùÓڶѵĻº³åÇøÒç³ö | ÑÏÖØ | ЧÀÍÍ߽⡢Êý¾Ýй¶ | |
CVE-2020-27267 | Use-after-free | ¸ßΣ | ЧÀÍÍß½â |
Softing OPC»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2020-14524£©
Softing OPC DA XML¿âÖб£´æ»ùÓڶѵĻº³åÇøÒç³öÎó²î£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔì³ÉЧÀͱÀÀ£»£»£»£»òÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
Softing WebЧÀÍÆ÷ûÓÐÏÞÖÆSOAP±êÍ·µÄ³¤¶È£¬£¬£¬£¬Ò²Ã»Óо»»¯SOAP±êÍ·µÄÖµ£¬£¬£¬£¬ÓÉÓÚËüͨ¹ýSOAPÆÊÎöΪOPC DA XML¡£¡£¡£¡£
Òì³£³¤µÄ±êÍ·½«µ¼ÖÂЧÀÍÆ÷ÎÞÐÝÖ¹µØ·ÖÅÉÄڴ棬£¬£¬£¬ÄÚ´æ·ÖÅÉ×îÖÕ»áÓÉÓÚ¶ÑÄÚ´æµÄ×ÊÔ´ÏûºÄ¶øÊ§°Ü¡£¡£¡£¡£¿ÉÊÇWebЧÀÍÆ÷²»»á¼ì²éÄÚ´æ·ÖÅɵķµ»ØÂ룬£¬£¬£¬¶øÊÇʵÑ齫Êý¾Ý¸´ÖƵ½·µ»ØµÄÖ¸Õë¡£¡£¡£¡£¿ÉÊÇÓÉÓÚ·µ»ØµÄÖ¸ÕëΪNULL£¬£¬£¬£¬¹¥»÷ÕßµÄÊý¾Ý½«±»¸´ÖƵ½Î´³õʼ»¯µÄÄÚ´æÖУ¬£¬£¬£¬×îÖÕµ¼Ö»á¼ûÒì³£²¢Ê¹Ð§ÀÍÍ߽⡣¡£¡£¡£
Ó°Ïì¹æÄ££¨ËùÓÐÎó²î£©
Softing Industrial Automation GmbH OPC < 4.47.0
Honeywell OPC UA Tunneller»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2020-27297£©
ÔÚHoneywell OPC Tunneller×é¼þÖз¢Ã÷Á˶à¸öÇå¾²Îó²î£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÑÏÖØµÄ¶ÑÒç³öÎó²î£¨CVE-2020-27297£©£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÄÚ´æ²¢Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£
Ó°Ïì¹æÄ££¨ËùÓÐÎó²î£©
OPC UA Tunneller < 6.3.0.8233
PTC Kepware KEPServerEX»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2020-27265£©
¸ÃÎó²îÊÇKEPServerEXÖеÄÒ»¸ö»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµÄOPC UAÐÂÎÅÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬×îÖÕµ¼ÖÂЧÀͱÀÀ£»£»£»£»òÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£
Ó°Ïì¹æÄ££¨ËùÓÐÎó²î£©
KEPServerEX: v6.0-v6.9
ThingWorx Kepware Server: v6.8¡¢v6.9
ThingWorx Industrial Connectivity: ËùÓа汾
OPC-Aggregator: ËùÓа汾
×é¼þ£º
Rockwell Automation KEPServer Enterprise: v6.6.504.0 ¡¢ v6.9.572.0
GE Digital Industrial Gateway Server: v7.68.804 ¡¢ v7.66
Software Toolbox TOP Server: ËùÓÐ 6.x °æ±¾
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ£¬£¬£¬£¬Ïà¹ØÎó²îÒѱ»ÐÞ¸´£¬£¬£¬£¬½¨Òé²Î¿¼Í¨¸æÊµÊ±Éý¼¶¡£¡£¡£¡£
Softing Industrial Automation OPC
https://us-cert.cisa.gov/ics/advisories/icsa-20-210-02
Honeywell OPC UA Tunneller
https://us-cert.cisa.gov/ics/advisories/icsa-21-021-03
PTC Kepware KEPServerEX
https://us-cert.cisa.gov/ics/advisories/icsa-20-352-02
0x03 ²Î¿¼Á´½Ó
https://www.claroty.com/2021/01/25/blog-research-critical-flaws-in-opc-protocol/
https://www.darkreading.com/attacks-breaches/claroty-discloses-multiple-critical-vulns-in-vendor-implementations-of-key-ot-protocol/d/d-id/1339973
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27265
0x04 ʱ¼äÏß
2021-01-25 CLAROTYÅû¶Îó²î
2021-01-26 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/