¸»Ê¿µç»úËÅ·þϵͳºÍÇý¶¯0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-09-30

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-14794£¬ £¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬ £¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8£¬ £¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-14788£¬ £¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬ £¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ5.3£¬ £¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Alpha5 Smart Loader Versions 3.7¼°Ö®Ç°°æ±¾


·ì϶¸ÅÊö


ICS-CERT ºÍÇ÷Ïò¿Æ¼¼ ZDI ÍŶӱ¾ÖÜÅû¶³Æ£¬ £¬£¬£¬ £¬ÈÕ±¾¸»Ê¿µç»ú¹«Ë¾µÄËÅ·þϵͳºÍÇý¶¯ÖдæÔÚ¶à¸ö佨¸´µÄ·ì϶ ¡£¡£¡£¡£¡£¡£×êÑÐÔ± Michael Flanders ÔÚ¸»Ê¿µç»úµÄ Alpha 5 ÖÇÄÜËÅ·þϵͳLoader Èí¼þÖз¢ÏÖÁËÁ½¸ö·ì϶ ¡£¡£¡£¡£¡£¡£


ÊÜÓ°Ïì²úÆ·ÖØÒªÓÃÓÚÅ·ÖÞºÍÑÇÖÞµÄóÒ×ÉèÊ©ºÍ¹Ø¼üÔì×÷ÐÐÒµÖУ¬ £¬£¬£¬ £¬×÷ÓÃÊÇͨ¹ýµ÷Õû£¬ £¬£¬£¬ £¬Ê¹Çý¶¯¶àÖÖ»úеµÄµç¶¯»ú¿ÉÄÜÕýÈ·ÔËÐÐ ¡£¡£¡£¡£¡£¡£


ÆäÖÐÒ»¸ö·ì϶ÊÇÑϳÁµÄ¶Ñ»º³åÇøÒç³ö (CVE-2018-14794) ·ì϶£¬ £¬£¬£¬ £¬Äܵ¼ÖÂÔ¶³Ì¹¥»÷ÕßÓÕÆ­Ö¸±ê´ò¿ªÒ»¸ö³ö¸ñ»ú¹ØµÄ C5V Îļþ£¬ £¬£¬£¬ £¬´Ó¶øÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£ZDI ÔÚ°²È«²¼¸æÖÐÖ¸³ö£¬ £¬£¬£¬ £¬¡°Õâ¸öÎÊÌâ²úÉúµÄÔ­ÒòÊÇÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´Ôìµ½Ò»¸ö³¤¶È¹Ì¶¨ÇÒ»ùÓڶѵĻº³å֮ǰ£¬ £¬£¬£¬ £¬²»×ã¶Ô¸ÃÊý¾ÝµÄÕýÈ·ÑéÖ¤ ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâ¸ö·ì϶ÔÚÖÎÀíÔ±¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡±

Ó°ÏìËÅ·þϵͳµÄµÚ¶þ¸ö·ì϶ÊÇÒ»¸öÖÐΣµÄ»º³åÇøÒç¶Âí½Å£¬ £¬£¬£¬ £¬¿Éµ¼ÖÂÔÚ´¦ÖÃÌØÊâ»ú¹ØµÄ A5P Îļþʱ£¬ £¬£¬£¬ £¬Ãô¸ÐÐÅÏ¢Ôâ¶³ö ¡£¡£¡£¡£¡£¡£µ±½áºÏÆäËü·ì϶ʹÓÃʱ£¬ £¬£¬£¬ £¬¹¥»÷Õß¿ÉÄÜÒÔÖÎÀíԱȨÏÞÀûÓøà bug Ö´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC\EXP


½¨¸´½¨Òé


ZDI ´ÍÓ븻ʿµç»ú120ÌìµÄ¹¦·ò½¨¸´¸Ã·ì϶ ¡£¡£¡£¡£¡£¡£¸»Ê¿µç»ú±¾Öܹ²°ä²¼5ƪ°²È«²¼¸æ£¬ £¬£¬£¬ £¬Ä¿Ç°ÓÉÓÚÉÐÎ´ÍÆ³ö²¹¶ ¡£¡£¡£¡£¡£¡£¬ £¬£¬£¬ £¬Òò¶øËüÃǾùÊôÓÚ 0day ·ì϶״̬ ¡£¡£¡£¡£¡£¡£


¸»Ê¿µç»ú¹«Ë¾°µÊ¾ÔÚÍÆ³ö²¹¶¡¹æ»® ¡£¡£¡£¡£¡£¡£ÔÚ´Ë֮ǰ£¬ £¬£¬£¬ £¬¸Ã¹«Ë¾½¨ÒéÓû§Ô¤·ÀÔÚÊÜÓ°ÏìÀûÓ÷¨Ê½Öв»ÊÜÐÅÀµµÄÎļþ ¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-270-02
https://www.securityweek.com/no-patches-critical-flaws-fuji-electric-servo-system-drives