¡¾Îó²îͨ¸æ¡¿OPCЭÒé¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-01-26

0x00 Îó²î¸ÅÊö

¿ª·Åƽ̨ͨѶ£¨OPC£©ÍøÂçЭÒéÊDzÙ×÷ÊÖÒÕ£¨OT£©ÍøÂçµÄÖÐÐÄÈË£¬£¬£¬ £¬È·±£¹¤Òµ¿ØÖÆÏµÍ³£¨ICS£©ºÍרÓÐ×°±¸Ö®¼äµÄ¿É²Ù×÷ÐÔ£¬£¬£¬ £¬ÈçÈÏÕæÏÖ³¡×°±¸×¼È·²Ù×÷µÄ¿É±à³ÌÂß¼­¿ØÖÆÆ÷(PLC)¡£¡£¡£¡£OPC½ÓÄɱê×¼»¯µÄͨѶЭÒé¼°Æä¹æ·¶£¨OPC DA¡¢AE¡¢HDA¡¢XML DA¡¢DXºÍOPC UA£©£¬£¬£¬ £¬°ü¹ÜÁ˶Ô×°±¸ºÍÀú³ÌµÄÖÎÀíºÍ¼àÊÓ¿ÉÒÔ´ÓÒ»¸ö¼¯ÖеÄЧÀÍÆ÷ÉϾÙÐУ¬£¬£¬ £¬Æäͨ³£×÷ΪһÖÖÔÚICSÓòÖеÄ×°±¸ÖÐÔËÐеÄǶÈëʽЭÒé¶ø±»ÆÕ±éʹÓᣡ£¡£¡£

2021Äê01ÔÂ25ÈÕ£¬£¬£¬ £¬ClarotyÑо¿Ð¡×éÅû¶ÁËMatrikon Honeywell ¡¢ Softing Industrial Automation GmbH ºÍPTC KepwareµÄOPCÖб£´æµÄ¶à¸öÇå¾²Îó²î¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

±»Åû¶µÄOPCÎó²îÈçÏ£º

²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ó°Ïì

£¨Softing Industrial Automation GmbH£©

OPC

CVE-2020-14524

»ùÓڶѵĻº³åÇøÒç³ö

ÑÏÖØ

ЧÀÍÍ߽⡢´úÂëÖ´ÐÐ

CVE-2020-14522

×ÊÔ´ÏûºÄ

¸ßΣ

¾Ü¾øÐ§ÀÍ

£¨Honeywell£©

OPC UA Tunneller

CVE-2020-27297

»ùÓڶѵĻº³åÇøÒç³ö

ÑÏÖØ

RCE

CVE-2020-27299

Ô½½ç¶ÁÈ¡

¸ßΣ

ÐÅϢй¶¡¢×°±¸Íß½â

CVE-2020-27274

¼ì²é²»µ±

¸ßΣ

¾Ü¾øÐ§ÀÍ

CVE-2020-27295

×ÊÔ´ÏûºÄ

¸ßΣ

¾Ü¾øÐ§ÀÍ

£¨PTC£©

Kepware KEPServerEX

CVE-2020-27265

»ùÓڶѵĻº³åÇøÒç³ö

ÑÏÖØ

ЧÀÍÍ߽⡢RCE

CVE-2020-27263

»ùÓڶѵĻº³åÇøÒç³ö

ÑÏÖØ

ЧÀÍÍ߽⡢Êý¾Ýй¶

CVE-2020-27267

Use-after-free

¸ßΣ

ЧÀÍÍß½â

 

Softing OPC»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2020-14524£©

Softing OPC DA XML¿âÖб£´æ»ùÓڶѵĻº³åÇøÒç³öÎó²î£¬£¬£¬ £¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔì³ÉЧÀͱÀÀ £»£»£»£»òÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

Softing WebЧÀÍÆ÷ûÓÐÏÞÖÆSOAP±êÍ·µÄ³¤¶È£¬£¬£¬ £¬Ò²Ã»Óо»»¯SOAP±êÍ·µÄÖµ£¬£¬£¬ £¬ÓÉÓÚËüͨ¹ýSOAPÆÊÎöΪOPC DA XML¡£¡£¡£¡£

Òì³£³¤µÄ±êÍ·½«µ¼ÖÂЧÀÍÆ÷ÎÞÐÝÖ¹µØ·ÖÅÉÄڴ棬£¬£¬ £¬ÄÚ´æ·ÖÅÉ×îÖÕ»áÓÉÓÚ¶ÑÄÚ´æµÄ×ÊÔ´ÏûºÄ¶øÊ§°Ü¡£¡£¡£¡£¿ÉÊÇWebЧÀÍÆ÷²»»á¼ì²éÄÚ´æ·ÖÅɵķµ»ØÂ룬£¬£¬ £¬¶øÊÇʵÑ齫Êý¾Ý¸´ÖƵ½·µ»ØµÄÖ¸Õë¡£¡£¡£¡£¿ÉÊÇÓÉÓÚ·µ»ØµÄÖ¸ÕëΪNULL£¬£¬£¬ £¬¹¥»÷ÕßµÄÊý¾Ý½«±»¸´ÖƵ½Î´³õʼ»¯µÄÄÚ´æÖУ¬£¬£¬ £¬×îÖÕµ¼Ö»á¼ûÒì³£²¢Ê¹Ð§ÀÍÍ߽⡣¡£¡£¡£

Ó°Ïì¹æÄ££¨ËùÓÐÎó²î£©

Softing Industrial Automation GmbH OPC < 4.47.0

 

Honeywell OPC UA Tunneller»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2020-27297£©

ÔÚHoneywell OPC Tunneller×é¼þÖз¢Ã÷Á˶à¸öÇå¾²Îó²î£¬£¬£¬ £¬ÆäÖаüÀ¨Ò»¸öÑÏÖØµÄ¶ÑÒç³öÎó²î£¨CVE-2020-27297£©£¬£¬£¬ £¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÄÚ´æ²¢Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£

Ó°Ïì¹æÄ££¨ËùÓÐÎó²î£©

OPC UA Tunneller < 6.3.0.8233

 

 

PTC Kepware KEPServerEX»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2020-27265£©

¸ÃÎó²îÊÇKEPServerEXÖеÄÒ»¸ö»º³åÇøÒç³öÎó²î£¬£¬£¬ £¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµÄOPC UAÐÂÎÅÀ´Ê¹ÓôËÎó²î£¬£¬£¬ £¬×îÖÕµ¼ÖÂЧÀͱÀÀ £»£»£»£»òÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£

Ó°Ïì¹æÄ££¨ËùÓÐÎó²î£©

KEPServerEX: v6.0-v6.9

ThingWorx Kepware Server: v6.8¡¢v6.9

ThingWorx Industrial Connectivity: ËùÓа汾

OPC-Aggregator: ËùÓа汾

×é¼þ£º

Rockwell Automation KEPServer Enterprise: v6.6.504.0 ¡¢ v6.9.572.0

GE Digital Industrial Gateway Server: v7.68.804 ¡¢ v7.66

Software Toolbox TOP Server: ËùÓÐ 6.x °æ±¾

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬ £¬Ïà¹ØÎó²îÒѱ»ÐÞ¸´£¬£¬£¬ £¬½¨Òé²Î¿¼Í¨¸æÊµÊ±Éý¼¶¡£¡£¡£¡£

Softing Industrial Automation OPC

https://us-cert.cisa.gov/ics/advisories/icsa-20-210-02

 

Honeywell OPC UA Tunneller

https://us-cert.cisa.gov/ics/advisories/icsa-21-021-03

 

PTC Kepware KEPServerEX

https://us-cert.cisa.gov/ics/advisories/icsa-20-352-02

 

 

0x03 ²Î¿¼Á´½Ó

https://www.claroty.com/2021/01/25/blog-research-critical-flaws-in-opc-protocol/

https://www.darkreading.com/attacks-breaches/claroty-discloses-multiple-critical-vulns-in-vendor-implementations-of-key-ot-protocol/d/d-id/1339973

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27265

 

 

0x04 ʱ¼äÏß

2021-01-25  CLAROTYÅû¶Îó²î

2021-01-26  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png