Rockwell Automation»Ø¾ø·þÎñ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-12-11

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£º CVE-2018-17924£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.6£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨



Ó°Ïì°æ±¾



MicroLogix 1400 Controllers Series A£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬Series B 21.003¼°Ö®Ç°°æ±¾£¬£¬£¬£¬£¬Series C 21.003¼°Ö®Ç°°æ±¾£»£»£»£»£»£»1756-ENBT£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬1756-EWEB Series A£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬1756-EWEB Series B£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬1756-EN2F Series A£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬1756-EN2F Series B£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬1756-EN2F Series C 10.10¼°Ö®Ç°°æ±¾£¬£¬£¬£¬£¬1756-EN2T Series A£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬1756-EN2T Series B£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬1756-EN2T Series C£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬1756-EN2T 10.10¼°Ö®Ç°°æ±¾£¬£¬£¬£¬£¬1756-EN2TR Series A£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬1756-EN2TR Series B£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬Series C 10.10¼°Ö®Ç°°æ±¾£¬£¬£¬£¬£¬1756-EN3TR Series A£¨È«Êý°æ±¾£©£¬£¬£¬£¬£¬1756-EN3TR Series B 10.10¼°Ö®Ç°°æ±¾£¨1756 ControlLogix EtherNet/IPͨѶÄ£¿£¿£¿£¿£¿£¿£¿é£©¡£¡£¡£¡£ ¡£¡£¡£



·ì϶¸ÅÊö



ÉÏÖÜËÄ£¬£¬£¬£¬£¬ICS-CERT °ä²¼°²È«²¼¸æÏêÊö¸Ã·ì϶Çé¿ö£¬£¬£¬£¬£¬²»ÍâÂÞ¿ËΤ¶û×Ô¶¯»¯¹«Ë¾ÔÚÊýÖÜǰ¾Í֪ͨ¿Í»§ÓйØÇé¿ö£¬£¬£¬£¬£¬¶øÂÞ¿ËΤ¶û°²È«²¼¸æ½öÏò×¢²áÓû§¹«¿ª¡£¡£¡£¡£ ¡£¡£¡£



ÂÞ¿ËΤ¶û¹«Ë¾ºÍ ICS-CERT ¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬¸Ã·ì϶ (CVE-2018-1792) µÄ CVSSv3ÆÀ·ÖΪ8.6£¬£¬£¬£¬£¬Ó°ÏìA¡¢B¡¢CϵÁÐµÄ MicroLogix 1400 ½ÚÔìÆ÷¡£¡£¡£¡£ ¡£¡£¡£Ëü»¹Ó°Ïì1756 ControlLogix ÒÔÌ«Íø/IP ͨѶÄ£¿£¿£¿£¿£¿£¿£¿éµÄ¶à¸ö°æ±¾£¬£¬£¬£¬£¬Ô̺¬A¡¢B¡¢CºÍDϵÁÓ×£¡£¡£¡£ ¡£¡£¡£



ICS-CERT °µÊ¾ÊÜÓ°Ïì²úÆ·ÓÃÓÚÈ«Çò¸÷µØ¶à¸öÐÐÒµ£¬£¬£¬£¬£¬È罻ͨ¡¢¹Ø¼üÔì×÷Òµ¡¢Ê³Æ·ºÍũҵ¡¢ÒÔ¼°Ë®ºÍ·ÏË®ÐÐÒµ¡£¡£¡£¡£ ¡£¡£¡£



¸Ã·ì϶¿Éµ¼ÖÂÔ¶³Ìδ¾­ÈÏÖ¤µÄ¹¥»÷Õßµ¼ÖÂÊÜÓ°ÏìÉ豸½øÈë DoS ǰÌá¡£¡£¡£¡£ ¡£¡£¡£ÂÞ¿ËΤ¶û¹«Ë¾Ú¹Êͳƣ¬£¬£¬£¬£¬Î´¾­ÈÏÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÄÜÏòÊÜÓ°ÏìÉ豸·¢ËÍ CIP ÏνÓÒªÇó²¢Ôڳɹ¦ÏνӺóÏòÊÜÓ°ÏìÉ豸·¢ËÍÐ嵀 IP ÅäÏàÐÅÏ¢£¬£¬£¬£¬£¬¼´±ãϵͳÖеĽÚÔìÆ÷±»ÉèÖÃΪ¡°Hard Run¡±Ä£Ê½¡£¡£¡£¡£ ¡£¡£¡£µ±ÊÜÓ°ÏìÉ豸½ÓÊÜÁËÕâ¸öÐ嵀 IP ÅäÏàÐÅÏ¢ºó£¬£¬£¬£¬£¬É豸ºÍϵͳÆäËü²¿ÃÅÖ®¼ä¾ÍȱʧÁËͨѶ£¬£¬£¬£¬£¬Ô­ÒòÊÇϵÍÂä÷Á¿ÒÀÈ»ÔÚÊÔͼͨ¹ý±»¸²Ð´µÄ IP µØÖ·ºÍÉ豸ͨѶ¡£¡£¡£¡£ ¡£¡£¡£



ÂÞ¿ËΤ¶û¹«Ë¾ÒÑΪÊÜÓ°Ïì½ÚÔìÆ÷ºÍͨѶÄ£¿£¿£¿£¿£¿£¿£¿é°ä²¼¹Ì¼þ¸üУ¬£¬£¬£¬£¬µ«¶ÔÆäÖкöà½ö°ä²¼»º½â´ëÊ©¡£¡£¡£¡£ ¡£¡£¡£ÕâЩ´ëÊ©Ô̺¬Ê¹Ó÷À»ðǽ×èÖ¹Ô´×ÔԽȨÆðÔ´µÄÒÔÌ«Íø/IP ÐÅÏ¢¡¢Ê¹ÓÃÓ²¼þ°´¼ü¿ª¹ØÉèÖÃ×èÖ¹¶ÔÉ豸½øÐÐԽȨ¸ü¸Ä²¢½«½ÚÔìϵͳµÄÍøÂç¶³ö×îÓ×»¯¡£¡£¡£¡£ ¡£¡£¡£



DoS ·ì϶¿É¶Ô¹¤Òµ»·¾³´øÀ´ÑϳÁ·çÏÕ¡£¡£¡£¡£ ¡£¡£¡£¹¤¿Ø»·¾³¿É±»ÓÃÓÚ¶Ô³ö²úϵͳÔì³ÉÑϳÁÇÖº¦¡£¡£¡£¡£ ¡£¡£¡£ºÍ»úÃÜÐÔΪ×î³ÁÒªµÄ IT ÍøÂ粻ͨ£¬£¬£¬£¬£¬²Ù×÷¼¼Êõ (OT) ÍøÂçÔËÓªÈËÔ±×î´óµÄÓÇÓôÊÇ¿ÉÓÃÐÔÎÊÌâ¡£¡£¡£¡£ ¡£¡£¡£



·ì϶ÑéÖ¤



ÔÝÎÞPOC/EXP¡£¡£¡£¡£ ¡£¡£¡£



½¨¸´½¨Òé



¹Ù·½ÒѾ­°ä²¼ÁËа汾½¨¸´Á˸÷ì϶£¬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¸üУ¬£¬£¬£¬£¬ÐγɶԴ˷ì϶³Ö¾ÃÓÐЧµÄ·À»¤¡£¡£¡£¡£ ¡£¡£¡£



²Î¿¼Á´½Ó



https://ics-cert.us-cert.gov/advisories/ICSA-18-310-02

https://www.securityfocus.com/bid/106132/solution

https://www.securityweek.com/vulnerability-exposes-rockwell-controllers-dos-attacks