GE URϵÁжà¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-03-240x00 Îó²î¸ÅÊö
2021Äê03ÔÂ16ÈÕ£¬£¬£¬£¬CISAÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬¹ûÕæÁËGE£¨Í¨ÓÃµçÆø¹«Ë¾£©URϵÁУ¨µçÔ´ÖÎÀí×°±¸£¬£¬£¬£¬Ö÷ÒªÓÃÓÚ¿ØÖƺͱ£»£»£»£»£»£»¤ÖÖÖÖ×°±¸µÄ¹¦ºÄ£©ÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓÃÕâЩÎó²îµÄ¹¥»÷ÕßÄܹ»»á¼ûÃô¸ÐÐÅÏ¢¡¢ÖØÆôUR¡¢ÌáÉýȨÏÞ»òµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
±¾´Î¹ûÕæµÄUR×°±¸ÖеÄÎó²îÈçÏ£º
CVE-ID | CVSSÆÀ·Ö | ÀàÐÍ | ÏêÇé |
CVE-2016-2183 CVE-2013-2566 | 7.5 | ¼ÓÃÜÇ¿¶Èȱ·¦ | ÔÚUR¹Ì¼þ°æ±¾8.1x֮ǰ£¬£¬£¬£¬UR SSHͨѶʹÓÃÈõ¼ÓÃܺÍMACËã·¨¡£¡£¡£¡£¡£¡£¡£ |
CVE-1999-1085 | 5.3 | »á»°Àο¿ | ÔÚ7.4x¹Ì¼þ°æ±¾Ö®Ç°£¬£¬£¬£¬UR½öÖ§³ÖSSHv2¡£¡£¡£¡£¡£¡£¡£´Ó¹Ì¼þ°æ±¾7.4x×îÏÈ£¬£¬£¬£¬URÖ§³Ö¾ßÓÐÒÑÖªÎó²îµÄSSHv1£¨SSHÐÒé»á»°ÃÜÔ¿¼ìË÷ºÍ²åÈë¹¥»÷£©¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27422 | 7.5 | ÐÅϢй¶ | UR over HTTPÐÒéÖ§³ÖWebЧÀÍÆ÷½Ó¿Ú£¬£¬£¬£¬ËüÄܹ»µ¼ÖÂδ¾Éí·ÝÑé֤й¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27418 | 5.3 | ÊäÈëÑéÖ¤²»×¼È· | URÖ§³Ö¾ßÓÐÖ»¶Á»á¼ûȨÏÞµÄWeb½çÃæ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ×°±¸ÎÞ·¨×¼È·ÑéÖ¤ÊäÈ룬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂXSS¹¥»÷£¬£¬£¬£¬¸Ã¹¥»÷¿ÉÓÃÓÚ·¢ËͶñÒâ¾ç±¾¡£¡£¡£¡£¡£¡£¡£ÁíÍ⣬£¬£¬£¬UR¹Ì¼þWebЧÀÍÆ÷²î³ØÓû§ÌṩµÄ×Ö·û´®Ö´ÐÐHTML±àÂë¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27420 | 5.3 | ÊäÈëÑéÖ¤²»×¼È· | UR Firmware WebЧÀÍÆ÷ʹÃüûÓÐ׼ȷ´¦Öóͷ£ÎüÊÕ²»Ö§³ÖµÄHTTP verbs£¬£¬£¬£¬µ¼ÖÂWebЧÀÍÆ÷ÔÚÎüÊÕµ½Ò»ÏµÁв»Ö§³ÖµÄHTTPÇëÇóºóÔÝʱ²»ÏìÓ¦¡£¡£¡£¡£¡£¡£¡£µ±ÎÞÏìӦʱ£¬£¬£¬£¬WebЧÀÍÆ÷ÊDz»¿É»á¼ûµÄ¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27428 | 7.5 | ÎļþÉÏ´« | UR IEDÖ§³ÖʹÓÃUR SetupÉèÖù¤¾ß--Enervista UR SetupÉý¼¶¹Ì¼þ¡£¡£¡£¡£¡£¡£¡£¸ÃUR Setup¹¤¾ßÔÚÉÏ´«UR IED֮ǰÑéÖ¤¹Ì¼þÎļþµÄÕæÊµÐÔºÍÍêÕûÐÔ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚûÓÐÊʵ±È¨ÏÞµÄÇéÐÎÏÂÉý¼¶¹Ì¼þ¡£¡£¡£¡£¡£¡£¡££¨¹Ì¼þ8.10°æ±¾ÖÐÓ¦Óûº½â²½·¥¡£¡£¡£¡£¡£¡£¡££© |
CVE-2021-27426 | 9.8 | ²»Çå¾²µÄĬÈϱäÁ¿³õʼ»¯ | ¾ßÓС°Basic¡±Çå¾²ÐÔ±äÌåµÄUR IED²»ÔÊÐí½ûÓá°Factory Mode¡±£¬£¬£¬£¬¸ÃģʽÓÃÓÚΪ¡°Factory¡±Óû§Î¬ÐÞIED¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27424 | 5.3 | ÐÅϢй¶ | ×÷ΪͨѶָÄϵÄÒ»²¿·Ö£¬£¬£¬£¬UR¹²ÏíMODBUSÄÚ´æÓ³Éä¡£¡£¡£¡£¡£¡£¡£GEÊÕµ½ ¡°Last-key pressed¡±µÄMODBUS¼Ä´æÆ÷¿ÉÒÔ±»ÓÃÀ´»ñȡδ¾ÊÚȨµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27430 | 8.4 | Ó²±àÂëÆ¾Ö¤ | UR bootloader¶þ½øÖư汾7.00¡¢7.01ºÍ7.02°üÀ¨Î´Ê¹ÓõÄÓ²±àÂëÆ¾Ö¤¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Äܹ»ÎïÆÊÎö¼ûUR IEDµÄÓû§¿ÉÒÔͨ¹ýÖØÐÂÆô¶¯URÀ´ÖÐÖ¹Æô¶¯ÐòÁС£¡£¡£¡£¡£¡£¡£ |
Ó°Ïì¹æÄ£
GE URϵÁУ¨B30¡¢B90¡¢C30¡¢C60¡¢C70¡¢C95¡¢D30¡¢D60¡¢F35¡¢F60¡¢G30¡¢G60¡¢L30¡¢L60¡¢L90¡¢M60¡¢N60¡¢T35¡¢T60£©£º
SSHÏà¹ØµÄÎó²î£º¹Ì¼þ°æ±¾7.4x-08.0x£¨CyberSentryÑ¡Ï
WebЧÀÍÆ÷Îó²î£º8.1x֮ǰµÄËùÓй̼þ°æ±¾
¹Ì¼þÉÏ´«£º¾ßÓлù±¾Çå¾²ÐÔÑ¡ÏîµÄ8.1x֮ǰµÄËùÓй̼þ°æ±¾
½ûÓóö³§Ä£Ê½£º¾ßÓлù±¾Çå¾²ÐÔÑ¡ÏîµÄ8.1x֮ǰµÄËùÓй̼þ°æ±¾
»á¼û¡°Last-key pressed¡±µÄ¼Ä´æÆ÷£º¾ßÓлù±¾Çå¾²ÐÔÑ¡ÏîµÄ8.1x֮ǰµÄËùÓй̼þ°æ±¾
UR Bootloader¶þ½øÖÆÎļþ£º7.03/7.04֮ǰµÄËùÓÐBootloader°æ±¾
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬½¨Ò齫UR×°±¸¸üÐÂΪUR¹Ì¼þ°æ±¾8.10»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£¸ü¶àÐÅÏ¢Çë²Î¿¼CISA¹Ù·½Í¨¸æ¡£¡£¡£¡£¡£¡£¡£
Ïà¹ØÁ´½Ó£º
https://www.gegridsolutions.com/Passport/Login.aspx
0x03 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ics/advisories/icsa-21-075-02
https://securityaffairs.co/wordpress/115881/security/cisa-ge-power-management-devices-flaws.html?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27426
0x04 ʱ¼äÏß
2021-03-16 CISAÐû²¼Ç徲ͨ¸æ
2021-03-24 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/