ModbusÍø¹Ø·ì϶(CVE-2021-4161)·ÖÎö
°ä²¼¹¦·ò 2022-01-17Ò»¡¢·ì϶¸ÅÊö
½üÆÚ£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLabÔÚ¹¤Òµ½ÚÔì·ì϶¼à¿ØÖз¢ÏÖ¹¤¿Ø³§ÉÌMoxaµÄModbusÍø¹Ø´æÔÚ¸ßΣ·ì϶£¨CVE-2021-4161£©£¬£¬£¬£¬£¬£¬£¬ICS-CERTµÄÆÀ·Ö¸ß´ï9.8¡£¡£¡£¡£¡£¡£¡£Õë¶Ô¸Ã¸ßΣ·ì϶£¬£¬£¬£¬£¬£¬£¬ADLab×êÑÐÔ±µÚÒ»¹¦·ò½øÐÐÁ˾ßÌå·ÖÎöºÍÑéÖ¤¡£¡£¡£¡£¡£¡£¡£
1.1 ¸ù»ùÐÅÏ¢
ƾ¾ÝICS-CERTµÄ·ì϶²¼¸æ£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¸ù»ùÐÅÏ¢ÈçÏ£º
ÊÜÓ°ÏìµÄÉ豸£º
MGate MB3180/MB3280/MB3480 Series Protocol Gateways
ÊÜÓ°ÏìµÄ°æ±¾£º
MGate MB3180 Series: Firmware Version 2.2 or lower
MGate MB3280 Series: Firmware Version 4.1 or lower
MGate MB3480 Series: Firmware Version 3.2 or lower
·ì϶¿ÉÀûÓÃÐÔ£ºÔ¶³Ì¡¢µÍ¸´ÔÓ¶È
CVSS v3ÆÀ·Ö£º9.8
1.2 ·ìϼûèÊö
ƾ¾ÝICS-CERT·ì϶²¼¸æµÄÃèÊö£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÀàÐÍÊôÓÚÃô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìÉ豸µÄ¹Ì¼þ´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÐáÌ½ÍøÂçÁ÷Á¿À´ÇÔÈ¡ºÍ½âÃÜÉ豸µÇ¼ʹ´¦µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñµÃ¶ÔÖ¸±êÉ豸http web serverµÄadminȨÏÞ¡£¡£¡£¡£¡£¡£¡£

ͼ1 ICS-CERT AdvisoryÖжԷì϶µÄÃèÊö
¸Ã·ì϶µÄCVSS3ÌØµãΪ(AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)¡£¡£¡£¡£¡£¡£¡£Èçͼ2Ëùʾ£¬£¬£¬£¬£¬£¬£¬ICS-CERTÒÔΪ¸Ã·ì϶¿ÉÔ¶³ÌÀûÓ㬣¬£¬£¬£¬£¬£¬Í¬Ê±¶ÔÆëÈ«ÐÔ£¨Integrity£©ºÍ¿ÉÓÃÐÔ£¨Availability£©µÄÓ°Ïì¾ùΪ¡°High¡±¡£¡£¡£¡£¡£¡£¡£

ͼ2 ICS-CERT ¶ÔCVE-2021-4161 CVSS(3.0)ÆÀ·Ö
ÔçÄêÃæµÄ·ìϼûèÊö¿ÉÖª£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÒ»¸ö²»°²È«µÄÍ´´¦´«Êäµ¼ÖÂÍ´´¦Ð¹Â¶µÄ·ì϶¡£¡£¡£¡£¡£¡£¡£ÄÇô£¬£¬£¬£¬£¬£¬£¬ÎªºÎICS-CERTÒÔΪÕâÑùÒ»¸ö·ì϶Æä¶ÔÆëÈ«ÐԺͿÉÓÃÐÔµÄÓ°ÏìΪ¡°High¡±ÄØ¡£¡£¡£¡£¡£¡£¡£´ø×ÅÕâ¸öÒɻ󣬣¬£¬£¬£¬£¬£¬ÎÒÃÇÔÚMGate MB3180É豸É϶Ը÷ì϶½øÐÐÁË·ÖÎöºÍÑéÖ¤¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢·ì϶·ÖÎö
ƾ¾ÝICS-CERT¶Ô·ì϶µÄÃèÊö£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇһ·ͷ²Â²â¸ÃϵÁÐÉ豸µÄwebµÇ¼ѡȡÁËBasicÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£BasicÈÏÖ¤ÊǵͻúÄÜÉ豸web serverËù³£ÓõIJ½Ö裬£¬£¬£¬£¬£¬£¬ÆäÏÕЩûÓа²È«ÐÔ£¬£¬£¬£¬£¬£¬£¬Ö±½Óͨ¹ýbase64½âÂëµÇ¼Á÷Á¿µÄÈÏÖ¤ÐÅÏ¢¼´¿É»ñµÃÓû§ÃûÃÜÂë¡£¡£¡£¡£¡£¡£¡£
ÒÀÕÕÉÏÊö˼·£¬£¬£¬£¬£¬£¬£¬ÎÒÃǶÔMB3180µÄµÇ¼Á÷Á¿½øÐÐÁË·ÖÎö£¬£¬£¬£¬£¬£¬£¬Èçͼ3Ëùʾ¡£¡£¡£¡£¡£¡£¡£MB3180µÄWebÈÏÖ¤²¢Ã»ÓÐѡȡBasicÈÏÖ¤·½Ê½¡£¡£¡£¡£¡£¡£¡£

ͼ3 MB3180 WebµÇ¼POSTÒªÇó
³ÖÐø¶ÔµÇ¼ҪÇó½øÐзÖÎö£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÒªÇóÖÐµÄ±íµ¥Êý¾ÝÔ̺¬ÁË¡°account¡±¡¢¡°password¡±µÈ×Ö¶ÎÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Èçͼ4Ëùʾ£º

ͼ4 MB3180 WebµÇ¼POSTÒªÇó±íµ¥Êý¾Ý£¨Óû§Ãûadmin,ÃÜÂë1234567£©
¹Û²ì±íµ¥ÖеÄÊý¾Ý¿ÉÖª£¬£¬£¬£¬£¬£¬£¬accountºÍpasswordûÓг£¼û¹þÏ£ÔËËãµÄÌØµã¡£¡£¡£¡£¡£¡£¡£ÂŴεǼµÄ±íµ¥Êý¾ÝÈçÏÂËùʾ£º

±í 1 ʹÓÃ·ÖÆçÓû§ÃûÃÜÂëµÇ¼µÄPOST±íµ¥²¿ÃÅÊý¾Ý¼Í¼
´ÓÉϱíÊý¾Ý»¹Äܹ»·¢ÏÖÈçÏÂÌØµã£º
accountºÍpasswordºÍÊäÈ볤¶ÈÊÇÓйص컣»£»£»£»
accountºÍpasswordºÍFakeChallengeÊÇÓйصġ£¡£¡£¡£¡£¡£¡£
ºóÐø¶ÔµÇÂ¼Ò³ÃæµÄÔ´Âë·ÖÎöÕÒµ½ÁËÉÏÊöÌØµã¡£¡£¡£¡£¡£¡£¡£ÔڵǼҳµÄjs´úÂëÖУ¬£¬£¬£¬£¬£¬£¬setInfoº¯ÊýÕÆ¹ÜÌìÉúµÇ¼ÐÅÏ¢²¢ÒÔ±íµ¥·½ÃæÊ½Ìá½»£¬£¬£¬£¬£¬£¬£¬ÈçÏÂËùʾ£º

ͼ5 MB3180µÄsetInfoº¯Êý
ÏÔÈ»£¬£¬£¬£¬£¬£¬£¬µÇ¼Êý¾ÝµÄ°²È«ÐÔÈ¡¾öÓÚº¯ÊýSetSHA256£¬£¬£¬£¬£¬£¬£¬Æä´úÂëÈçÏÂËùʾ£º

ͼ6 MB3180µÄSetSHA256º¯Êý
·ÖÎöSetSHA256º¯ÊýµÄÂß¼¿ÉÖª£¬£¬£¬£¬£¬£¬£¬¸Ãº¯Êý²¢Ã»ÓÐÕæÕýʵÏÖSHA256µÄÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬¶øÊÇʹÓÃÁËÒì»ò·½Ê½À´´¦ÖÃÊäÈëÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¾ßÌåÀ´½²£¬£¬£¬£¬£¬£¬£¬SetSHA256º¯ÊýµÄ·µ»ØÖµÊÇxor(m,n)Ö®ºóµÄÁ˾֣¬£¬£¬£¬£¬£¬£¬¶ømÆðÔ´ÓÚaccount/password£¬£¬£¬£¬£¬£¬£¬nÔòÆðÔ´ÓÚFakeChallenge¡£¡£¡£¡£¡£¡£¡£²»ÑÔ¶øÓ÷£¬£¬£¬£¬£¬£¬£¬ÔÚFakeChallenge±»Ð¹Â¶µÄǰÌáÏ£¬£¬£¬£¬£¬£¬£¬account/passwordÊǿɻ¹ÔµÄ¡£¡£¡£¡£¡£¡£¡£
ÖÁ´Ë£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄµÀÀí¾Í¸ù»ùÇ峺ÁË¡£¡£¡£¡£¡£¡£¡£MB3180ÔÚ´¦ÖõÇÂ¼Ò³ÃæµÄÓû§ÃûºÍÃÜÂë¼ÓÃÜʱ£¬£¬£¬£¬£¬£¬£¬Î´ÕýµÄÈ·ÏÖSHA256µÄÔËË㣬£¬£¬£¬£¬£¬£¬Í¬Ê±web serverĬÈÏʹÓÃhttpºÍ̸¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬£¬ÔÚ¿ÉÐá̽µ½¸ÃÉ豸µÇ¼µÄhttp±¨ÎÄʱ£¬£¬£¬£¬£¬£¬£¬±ã¿Éͨ¹ý½âÃÜ±íµ¥Êý¾ÝÀ´µÃµ½µÇ¼µÄÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£¡£¡£
Èý¡¢·ì϶ÑéÖ¤
ƾ¾ÝÉÏÊö·ì϶·ÖÎöÁ˾֣¬£¬£¬£¬£¬£¬£¬ÎÒÃDZàдÏàʼûܾ籾¶Ô¸Ã·ì϶½øÐÐÁËÑéÖ¤¡£¡£¡£¡£¡£¡£¡£Îª¼ò»¯ÑéÖ¤¹ý³Ì£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÖ±½ÓʹÓÃWiresharkץȡÁ˵ǼMB3180 Web ServerµÄhttpÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬¶øºó±àд¾ç±¾¶Ô¸ÃÁ÷Á¿½øÐзÖÎö²¢½âÃÜ¡£¡£¡£¡£¡£¡£¡£
ÔÚ×¥°ü¹ý³ÌÖУ¬£¬£¬£¬£¬£¬£¬ÎÒÃǽøÐÐÁËÁ½´ÎµÇ¼£¬£¬£¬£¬£¬£¬£¬Óû§Ãû¾ùΪadmin£¬£¬£¬£¬£¬£¬£¬ÃÜÂëÔòʹÓÃÁËÒ»¸öÃýÎóµÄÃÜÂ루admin£©ºÍÒ»¸öÕýÈ·µÄÃÜÂ루moxa£©¡£¡£¡£¡£¡£¡£¡£

ͼ7 ʹÓÃadmin\adminµÇ¼µÄ±íµ¥Êý¾Ý

ͼ8 ʹÓÃadmin\moxaµÇ¼µÄ±íµ¥Êý¾Ý
ÑéÖ¤Á˾ÖÈçͼ9Ëùʾ£¬£¬£¬£¬£¬£¬£¬¿É´ÓµÇ¼Á÷Á¿½âÃܵõ½Óû§ÃûºÍÃÜÂëÐÅÏ¢£º

ͼ9 ½âÃܾ籾ÑéÖ¤
ËÄ¡¢·ì϶·çÏÕ
ÔÚ¹¤Òµ½ÚÔì»·¾³ÖУ¬£¬£¬£¬£¬£¬£¬ÓдóÁ¿µÄÉ豸²¢²»¾ß±¸TCP/IPºÍ̸ջ£¬£¬£¬£¬£¬£¬£¬Òª°ÑÕâЩÉ豸½ÓÈë»ùÓÚIT¼¼ÊõµÄÊý×Ö»¯ÍøÂç¾Í±ØÒª½èÖúºÍ̸ת»»Íø¹ØÀ´ÊµÏÖ¡£¡£¡£¡£¡£¡£¡£MGate MBϵÁÐModbusÍø¹ØÉ豸µÄÖ°Äܼ´ÊǰÑRS485ÀàµÄ¹¤ÒµÉ豸½ÓÈëµ½TCP/IPÍøÂç¡£¡£¡£¡£¡£¡£¡£ÕâÀàÍø¹ØÉ豸·ì϶µÄ·çÏÕͨ³£²»½ö½öÓ°Ïì¸ÃÉ豸×ÔÉí£¬£¬£¬£¬£¬£¬£¬¸üÖ±½ÓÓ°ÏìÆä±³ºóÖ§³ÖµÄÏÖ³¡É豸¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬£¬NVD¶Ô¸Ã·ì϶¸ø³öÁËÁ½ÖÖCVSS3ÆÀ·Ö£¬£¬£¬£¬£¬£¬£¬ÈçÏÂËùʾ¡£¡£¡£¡£¡£¡£¡£

ͼ10 NVDºÍICS-CERTÆÀ·ÖÇø±ð
ÆäÖУ¬£¬£¬£¬£¬£¬£¬NVD»ùÓÚNISTµÄÊӽǸø³öÁË7.5·Ö£¬£¬£¬£¬£¬£¬£¬¶øICS-CERT»ùÓÚ¹¤ÒµÊӽǸø³öÁË9.8¸ß·Ö¡£¡£¡£¡£¡£¡£¡£ÕâÁ½ÖÔìÀ·ÖµÄ²î¾à¾ÍÔÚÓÚ£º´ÓIT½Ç¶È¿´£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶²»ÄÜÅú¸Ä¸ÃÉ豸µÄµ×²ãÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ò²²»ÄÜʹÉ豸ÖÕ³¡ÔËÐУ¬£¬£¬£¬£¬£¬£¬Òò¶ø²»Ó°Ïì¸ÃÉ豸µÄÆëÈ«ÐԺͿÉÓÃÐÔ£»£»£»£»£»µ«´Ó¹¤Òµ½Ç¶È¿´£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¸Ã·ì϶»ñµÃÖÎÀíÔ¹ØËºÅºóÄܹ»Åú¸ÄÍø¹ØµÄÅäÖ㬣¬£¬£¬£¬£¬£¬½ø¶øÊ¹µÃ¸ÃÉ豸֧³ÖµÄ¹¤Òµ½ÚÔìÒµÎñ²úÉúµ÷»»ÉõÖÁÊÇÖÕ³¡£¬£¬£¬£¬£¬£¬£¬ËùÒÔÓ°ÏìÁ˹¤Òµ½ÚÔìÒµÎñµÄÆëÈ«ÐԺͿÉÓÃÐÔ¡£¡£¡£¡£¡£¡£¡£
¿É¼û£¬£¬£¬£¬£¬£¬£¬Í¬ÑùÀàÐ͵ÄÍøÂ簲ȫ·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäÔÚ¹¤Òµ½ÚÔìϵÍÂäìÓòµÄÓ°Ïì΢·çÏÕͨ³£Òª¸ßÓÚ´«Í³ITÒµÎñÁìÓò¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬£¬ÔÚ´¦Öù¤Òµ½ÚÔìÏµÍ³ÍøÂ簲ȫ·ì϶ʱ£¬£¬£¬£¬£¬£¬£¬±ØÒªË¼¿¼µ½¹¤¿ØÒµÎñ»·¾³µÄÌØÊâÐÔ£¬£¬£¬£¬£¬£¬£¬½áºÏ¶Ô¹¤¿ØÒµÎñµÄÓ°ÏìÀ´×ÛºÏÆÀ¼Û·ì϶µÄ·çÏÕÄÜÁ¦Ô½·¢¿Í¹ÛÕæÊµµÄ·´Ó³·ì϶µÄÓ°ÏìÁ¦¡£¡£¡£¡£¡£¡£¡£
Îå¡¢½¨¸´½¨Òé
Ŀǰ£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´°ä²¼¸Ã·ì϶µÄ½¨¸´²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬µ«ÌṩÁË·ì϶»º½â½¨Ò飺
½¨Ò齫ÊÜÓ°ÏìÉ豸µÄWeb Server½Ó¼ûµÄºÍ̸ÉèÖÃΪhttps£¬£¬£¬£¬£¬£¬£¬Ô¤·ÀÃ÷ÎÄ´«Êä±íµ¥Êý¾Ý£»£»£»£»£»
½¨Òé²ÎÕÕMoxa SecurityHardening Guide for MGate MB3000 SeriesÖеķ½Ê½²¿ÊðÉ豸¡£¡£¡£¡£¡£¡£¡£
´Ë±í£¬£¬£¬£¬£¬£¬£¬Õë¶Ô¹¤Òµ½ÚÔìϵͳ£¬£¬£¬£¬£¬£¬£¬CISAÌṩÁËÈçϵÄͨÓý¨Ò飺
¾¡Á¿Ï÷¼õÔÚ¹«ÍøÂ¶³ö¹¤¿ØÉ豸»òÕßϵͳ£»£»£»£»£»
½«½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬£¬£¬£¬£¬£¬£¬²¢ºÍ°ì¹«ÍøÂç¸ôÀ룻£»£»£»£»
µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬£¬£¬£¬£¬£¬£¬Ñ¡È¡ÀàÐÍVPNµÄ°²È«½Ó¼û·½Ê½¡£¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ