Ê©Ä͵ÂModicon M221ȫϵPLC·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-11-20·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-7789£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.5
Ó°Ïì°æ±¾
Modicon M221 PLC£¬£¬£¬£¬£¬£¬£¬£¬È«ÏµËùÓа汾
·ì϶¸ÅÊö
Modicon M221 ϵÁÐPLC»ùÓÚSoMachine BasicÈí¼þƽ̨£¬£¬£¬£¬£¬£¬£¬£¬×¨Îªµ¥Ò»»úеÉ豸Éè¼Æ£¬£¬£¬£¬£¬£¬£¬£¬±íÐξ«²Ê£¬£¬£¬£¬£¬£¬£¬£¬²Ù×÷µ¥Ò»£¬£¬£¬£¬£¬£¬£¬£¬±¾ÌåÄÚÖøßËÙ¼ÆÊý£¬£¬£¬£¬£¬£¬£¬£¬Ñ¡È¡Âö³åÊä³ö¡¢Ä£ÄâÁ¿ÊäÈ뷽ʽ£¬£¬£¬£¬£¬£¬£¬£¬Ö§³ÖÒÔÌ«Íø¼°ModbusͨѶ¡£¡£¡£¡£¡£¡£¡£
Êý¾ÝÕæÊµÐÔÑéÖ¤²»¼°CWE-345£¨CVE-2018-7798£©ÔÚUMASºÍ̸Öв»ÕýÈ·µØÖ´ÐÐÍøÂçÅäÖÃÄ£¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÔÊÐí¹¥»÷ÕßÔ¶³ÌÅú¸ÄÅäÖòÎÊýÀ´À¹½ØÖ¸±êPLCµÄÍøÂçÁ÷Á¿¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õ߳ɹ¦ÀûÓ÷ì϶£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔ¶³Ì¸ü¸ÄPLCµÄIPv4ÅäÖã¨IPµØÖ·£¬£¬£¬£¬£¬£¬£¬£¬ÑÚÂëºÍÍø¹Ø£©£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø×èÄÓPLCµÄÍøÂçÁ÷Á¿µ¼ÖÂͨѶÒì³£¡£¡£¡£¡£¡£¡£¡£
¸Ã·ì϶ÔÚ2018Äê8ÔÂ28ÈÕ°ä²¼£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖֵΪ4.8£¬£¬£¬£¬£¬£¬£¬£¬2018Äê11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Eduard Kovacs°ä·¢ÎÄÕ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ì϶ÆÀ·ÖÔÚ¹¤Òµ½ÚÔìϵͳÖдøÀ´Îóµ¼£¬£¬£¬£¬£¬£¬£¬£¬Ìá¼°ÁËCVE-2018-7789·ì϶£¬£¬£¬£¬£¬£¬£¬£¬CVSS¹Ù·½½«·ÖÖµ¸üÐÂΪ7.5·Ö¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP
½¨¸´½¨Òé
ÉèÖ÷À»ðǽ£¬£¬£¬£¬£¬£¬£¬£¬×èÖ¹502¶Ë¿ÚµÄËùÓÐÔ¶³Ì/±í²¿½Ó¼û
ÔÚModicon M221ÀûÓ÷¨Ê½ÖнûÓÃËùÓÐδʹÓõĺÍ̸£¬£¬£¬£¬£¬£¬£¬£¬³ö¸ñÊDZà³ÌºÍ̸£¬£¬£¬£¬£¬£¬£¬£¬Õ⽫×èÖ¹M221 PLCµÄÔ¶³Ì±à³Ì¡£¡£¡£¡£¡£¡£¡£
È·±£¿£¿£¿£¿£¿£¿£¿£½ÚÔìÆ÷´¦ÓÚËø¶¨µÄ»ú¹ñÖУ¬£¬£¬£¬£¬£¬£¬£¬ÈçÎÞ±ØÒª²»ÒªÆôÓá°Program¡±Ä£Ê½
Ô¤·À½«½ÚÔìÉ豸»ò²Ù×÷վ¶³öÔÚ»¥ÁªÍøÖУ¬£¬£¬£¬£¬£¬£¬£¬È·±£¹¤Òµ½ÚÔìϵͳÓëÐÅÏ¢ÍøÂçÆëÈ«¸ôÀë
±íÁª¹Ü¿Ø£¬£¬£¬£¬£¬£¬£¬£¬Ô¤·À²»°²È«µÄÒÆ¶¯É豸½ÓÈë¸ôÀëÍøÂç
µ±±ØÐë½øÐÐÔ¶³Ì½Ó¼ûʱ£¬£¬£¬£¬£¬£¬£¬£¬ÇëʹÓð²È«²½Ö裬£¬£¬£¬£¬£¬£¬£¬ÀýÈçʹÓÃÐ鹹רÓÃÍøÂ磨VPN£©£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¬Ê±È·±£VPN×ÔÉíµÄ°²È«ÐÔ
Ê©ÄÍµÂµçÆø»ã±¨³Æ£¬£¬£¬£¬£¬£¬£¬£¬´Ë·ì϶µÄ½¨¸´·¨Ê½ÊÇÔÚModicon M221¹Ì¼þv1.6.2.0ÖÐʵÏֵ쬣¬£¬£¬£¬£¬£¬£¬ÔÚSoMachine Basic v1.6 SP2ÖÐÌṩ£¬£¬£¬£¬£¬£¬£¬£¬»òÕßʹÓÃSchneider ElectricÈí¼þ¸üй¤¾ß¡£¡£¡£¡£¡£¡£¡£
https://www.schneider-electric.com/en/download/document/SoMachineBasicV1.6SP2/
²Î¿¼Á´½Ó
https://www.securityweek.com/flaw-schneider-plc-allows-significant-disruption-ics
https://nvd.nist.gov/vuln/detail/CVE-2018-7789
https://www.securityweek.com/cvss-scores-often-misleading-ics-vulnerabilities-experts


¾©¹«Íø°²±¸11010802024551ºÅ