ABB PLCÑϳÁ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-12-19·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-18995£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18997£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 7.1£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
GATE-E1 (EOL 2013)
GATE-E2 (EOL OCT 2018)
·ì϶¸ÅÊö
×êÑÐÈËÔ±ÔÚÈðÊ¿¹¤Òµ¼¼Êõ¹«Ë¾ ABB ³ö²úµÄÄ³Ð©Íø¹Ø²úÆ·Öз¢ÏÖÁËÑϳÁ·ì϶£¬£¬£¬£¬£¬µ«ÓÉÓÚ²úÆ·µÄÐÔÃüÖÜÆÚʵÏÖ£¬£¬£¬£¬£¬Òò¶ø³§É̽«²»»áÍÆ³ö²¹¶¡¡£¡£¡£¡£¡£¡£
Applied Risk¹«Ë¾±¾Öܰ䲼°²È«²¼¸æ°µÊ¾£¬£¬£¬£¬£¬ABB ³ö²úµÄ Pluto Íø¹Ø²úÆ·ÖдæÔÚÁ½¸öÑϳÁ·ì϶¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÍø¹ØÊÇ GATE-E1 ºÍ GATE-E2£¬£¬£¬£¬£¬ËüÃǿɵ¼Ö ABB ¹«Ë¾µÄ¿É±à³Ì°²È«½ÚÔìÆ÷£¨°²È« PLCs£©ºÍÆäËü½ÚÔìϵͳͨѶ¡£¡£¡£¡£¡£¡£
×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬£¬£¬ÕâЩÉ豸µÄÖÎÀíÔ± telnet ºÍ web ½Ó¿ÚÉ϶ÌȱÈÏÖ¤»úÔ죬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßµÈÏлñÈ¡ÊÚȨȨÏÞ¡£¡£¡£¡£¡£¡£¸Ãȱµã±» Applied Risk ¹«Ë¾ºÍ ABB ¹«Ë¾¾ùÆÀΪ¡°ÑϳÁ¡±µÈ¼¶£¬£¬£¬£¬£¬¿É±»ÓÃÓÚÅú¸ÄÉ豸ÅäÖò¢Í¨¹ý³ÖÐø³ÁÖòúÆ·µÄ²½ÖèÒý·¢»Ø¾ø·þÎñǰÌá¡£¡£¡£¡£¡£¡£
ABB ¹«Ë¾Ú¹Êͳƣ¬£¬£¬£¬£¬¡°¸Ã·ì϶ÊÇÒò²úÆ·Öв»×ãÈÏÖ¤Ö§³Öµ¼Öµġ£¡£¡£¡£¡£¡£µ±¿ª·¢²úƷʱ£¬£¬£¬£¬£¬²¢Î´Éè¼ÆÌṩ°²È«·þÎñÈçÈÏÖ¤¡£¡£¡£¡£¡£¡£¡±
Applied Risk¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÔâÔ¶³ÌÀûÓ㬣¬£¬£¬£¬²¢ÇÒÈôÊÇÍøÂçÅäÖÃÁËÕâÀà½Ó¼ûȨÏÞÔò¿ÉÄÜͨ¹ý»¥ÁªÍø±»ÀûÓᣡ£¡£¡£¡£¡£
ABB ¹«Ë¾ÎªÈÏ֤ȱʧºÍ XSS ·ì϶Çé¿ö°ä²¼°²È«²¼¸æ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾·î¸æ¿Í»§³Æ£¬£¬£¬£¬£¬²úÆ·ÒÑÊÙÖÕÕýÇÞ£¬£¬£¬£¬£¬Òò¶ø½«²»»áÍÆ³öÈκι̼þ¸üС£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬Óû§¸Ãµ±»áÊÕµ½¹ØÓÚÈôºÎ±£»£»£»£»£»¤×°Ö÷¨Ê½°²È«µÄÖ¸ÄÏÓʼþ¡£¡£¡£¡£¡£¡£
ĿǰÉÐδÓÐÖ¤¾ÝÅú×¢£¬£¬£¬£¬£¬ÕâЩȱµãÒѱ»¶ñÒâÀûÓᣡ£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
ABB½«²»»á°ä²¼¸üеĹ̼þ£¬£¬£¬£¬£¬ÓÉÓÚGATE-E1ºÍGATE-E2¶¼ÒѴﵽʹÓÃÊÙÃü£¨EOL£©¡£¡£¡£¡£¡£¡£ ABB½¨ÒéÖ´ÐÐ×ÝÉî·ÀÓù×¼Ôò£¬£¬£¬£¬£¬ÒÔ×î´óÏ޶ȵؽµµÍ·ì϶±»ÀûÓõķçÏÕ¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://ics-cert.us-cert.gov/advisories/ICSA-18-352-01
https://www.securityweek.com/serious-flaws-found-abb-safety-plc-gateways


¾©¹«Íø°²±¸11010802024551ºÅ