Ê©ÄÍµÂµçÆø²úÆ·¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-12

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2018-7846 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.3 £¬ £¬£¬ £¬£¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7849 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7843 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7844 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7848 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.9 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7842 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7847 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬ £¬£¬ £¬£¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7850 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º5.3
CVE±àºÅ£ºCVE-2018-7845 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7852 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7853 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7854 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7855 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7856 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7857 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-6806 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½£º6.5
CVE±àºÅ£ºCVE-2018-6807 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬ £¬£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-6808 £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10.0 £¬ £¬£¬ £¬£¬¹Ù·½£º7.5



Ó°Ïì°æ±¾



ÊÜÓ°ÏìµÄ°æ±¾


Modicon M580ËùÓа汾
Modicon M340ËùÓа汾
Modicon QuantumËùÓа汾

Modicon PremiumËùÓа汾



·ì϶¸ÅÊö



Schneider Electric Modicon M580µÈ¶¼ÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£ ¡£¡£Schneider Electric Modicon M580ÊÇÒ»¿î¿É±à³Ì×Ô¶¯»¯½ÚÔìÆ÷¡£¡£¡£¡£¡£ ¡£¡£Schneider Electric Modicon PremiumÊÇÒ»¿îÓÃÓÚÀëÉ¢»ò¹ý³ÌÀûÓõĴóÐͿɱà³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©¡£¡£¡£¡£¡£ ¡£¡£Schneider Electric Modicon QuantumÊÇÒ»¿îÓÃÓÚ¹ý³ÌÀûÓᢸ߿ÉÓÃÐԺͰ²È«½â¾ö¹æ»®µÄ´óÐͿɱà³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©¡£¡£¡£¡£¡£ ¡£¡£¶à¿îSchneider Electric²úÆ·ÖдæÔÚÈçÏ·ì϶£º


CVE-2018-7846

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸ÔÚ²»ÑéÖ¤·¢¼þÈËÕæÊµÐÔµÄÇé¿öÏÂʹ»á»°ÎÞЧ £¬ £¬£¬ £¬£¬´Ó¶øµ¼ÖºϷ¨É豸¶Ï¿ªÏνӡ£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7849

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë¿É¸´Ô­µÄ¹ÊÕÏ״̬ £¬ £¬£¬ £¬£¬´Ó¶øµ¼ÖÂÉ豸Õý³£Ö´ÐÐÖÕ³¡¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7843

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬ £¬ £¬£¬ £¬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7844

´Ë·ì϶ΪÐÅϢй¶·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸·µ»ØÄÚ´æ¿é £¬ £¬£¬ £¬£¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁÈ¡ £¬ £¬£¬ £¬£¬Ð´ÈëºÍ²¶»ñSNMPÉçÇø×Ö·û´®¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7848

´Ë·ì϶ΪÐÅϢй¶·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸·µ»Ø±à³ÌÕ½ÊõµÄ¿é £¬ £¬£¬ £¬£¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁд £¬ £¬£¬ £¬£¬Ð´ÈëºÍÏÝÚåSNMPÉçÇø×Ö·û´®µÄй¶¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7842

´Ë·ì϶Ϊ²»ÕýÈ·ÈÏÖ¤·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁîÄܹ»ÔÊÐí¹¥»÷Õß¼Ù×°³É¾­¹ýÉí·ÝÑéÖ¤µÄÓû§ £¬ £¬£¬ £¬£¬´Ó¶øÄܹ»ÈƹýÉ豸ÉϵÄÃÜÂë± £»£»£»£»£»£»¤¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7847

´Ë·ì϶Ϊδ¾­Éí·ÝÑéÖ¤µÄÎļþдÈë·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁîÐòÁпÉÄܻᵼÖÂÉ豸¸²¸ÇÆä±à³ÌÕ½Êõ £¬ £¬£¬ £¬£¬´Ó¶ø²úÉú¸÷ÀàÓ°Ïì £¬ £¬£¬ £¬£¬Ô̺¬ÅäÖÃÅú¸Ä £¬ £¬£¬ £¬£¬ÔËÐйý³ÌÖжϺÍDZÔڵĴúÂëÖ´ÐÓ×£¡£¡£¡£¡£ ¡£¡£ ¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7850

Schneider Electric UnityProL±à³ÌÈí¼þµÄÕ½Êõ´«ÊäÖ°ÄÜÖдæÔÚ¿ÉÀûÓõĶԲ»³ÉÐÅÊäÈë·ì϶µÄÒÀÀµ¡£¡£¡£¡£¡£ ¡£¡£½«ÌØÔìÕ½Êõ±à³Ìµ½Modicon M580¿É±à³Ì×Ô¶¯»¯½ÚÔìÆ÷ £¬ £¬£¬ £¬£¬²¢Ê¹ÓÃUnityProL¶ÁÈ¡¸ÃÕ½Êõʱ £¬ £¬£¬ £¬£¬»áÏòÓû§ÏÔʾÓëÉ豸·ÖÆçµÄÅäÖᣡ£¡£¡£¡£ ¡£¡£Õâµ¼ÖÂUnityProLÓû§ÎÞ·¨ÑéÖ¤É豸ÊÇ·ñ°´Ô¤ÆÚÔËÐÓ×£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7845

´Ë·ì϶ΪÐÅϢй¶·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASÒªÇó¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡ £¬ £¬£¬ £¬£¬´Ó¶øµ¼ÖÂÃô¸ÐÐÅÏ¢µÄй¶¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7852

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬ £¬ £¬£¬ £¬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢ÕâЩ·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7853

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬ £¬ £¬£¬ £¬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7854

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬ £¬ £¬£¬ £¬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7855

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬ £¬ £¬£¬ £¬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7856

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬ £¬ £¬£¬ £¬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-7857

´Ë·ì϶Ϊ»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬ £¬ £¬£¬ £¬£¬µ¼ÖÂÓëÉ豸µÄÔ¶³ÌͨѶÆëÈ«ÖÕ³¡¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-6806

´Ë·ì϶ΪÐÅϢй¶·ì϶¡£¡£¡£¡£¡£ ¡£¡£ ÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸·µ»ØÄÚ´æ¿é £¬ £¬£¬ £¬£¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁÈ¡ £¬ £¬£¬ £¬£¬Ð´ÈëºÍ²¶»ñSNMPÉçÇø×Ö·û´®¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-6807

¿É±à³ÌµÄ»Ø¾ø·þÎñ·ì϶´æÔÚÓÚSchneider Electric Modicon M580¿É±à³Ì×Ô¶¯»¯½ÚÔìÆ÷µÄ¹Ì¼þ°æ±¾SV2.70µÄUMASдÈëϵͳλºÍ¿éÖ°ÄÜÖÓ×£¡£¡£¡£¡£ ¡£¡£Ò»×éÌØÔìµÄUMASºÅÁî¿ÉÄܵ¼ÖÂÉ豸½øÈë²»³É¸´Ô­µÄ¹ÊÕÏ״̬ £¬ £¬£¬ £¬£¬´Ó¶øµ¼ÖÂÉ豸Զ³ÌͨѶÆëÈ«ÖÕ³¡¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


CVE-2018-6808

Schneider Electric Unity Pro±à³ÌÈí¼þPLCÄ£ÄâÆ÷µÄUMASÕ½Êõ±à³ÌÖ°ÄÜÖдæÔÚ¿ÉÀûÓõÄÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£ ¡£¡£·¢Ë͵½Èí¼þPLC·ÂÕæÆ÷µÄÌØÔìUMASºÅÁîÐòÁÐÄܹ»µ¼ÖÂÅú¸ÄÕ½Êõ±à³Ì £¬ £¬£¬ £¬£¬´Ó¶øÔÚ·ÂÕæÆ÷Çл»µ½Æô¶¯Ä£Ê½Ê±Ö´ÐдúÂë¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£ ¡£¡£



·ì϶ÑéÖ¤



ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£ ¡£¡£



½¨¸´½¨Òé



¹Ù·½ÒÑÍÆ³ö¸üв¹¶¡ £¬ £¬£¬ £¬£¬Çëʵʱ¸üУºhttps://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-11+-+Modicon+Controller.pdf&p_Doc_Ref=SEVD-2019-134-11¡£¡£¡£¡£¡£ ¡£¡£



²Î¿¼Á´½Ó



https://blog.talosintelligence.com/2019/06/vulnerability-spotlight-multiple.html