Rockwell Automation¿É±à³ÌÂß¼­½ÚÔìÆ÷°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-18

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-6990 £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-6984 £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-6988 £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-6980 £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º4.0 £¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Rockwell Automation MicroLogix 1400 Controllers Series B v21.001¼°Ö®Ç°°æ±¾ºÍSeries AËùÓа汾

MicroLogix 1100 ControllerËùÓа汾

RSLogix 500 Software v12.001¼°Ö®Ç°°æ±¾


·ì϶¸ÅÊö


ÃÀ¹úRockwell Automation¹«Ë¾ÊÇÈ«Çò×î´óµÄ×Ô¶¯»¯ºÍÐÅÏ¢»¯¹«Ë¾Ö®Ò»¡£¡£¡£¡£¡£ ¡£¡£¡£MicroLogix 1400 ControllersºÍMicroLogix 1100 ControllersÊÇRockwell Automation¹«Ë¾³öÆ·µÄ¿É±à³ÌÂß¼­½ÚÔìÆ÷¡£¡£¡£¡£¡£ ¡£¡£¡£RSLogix 500 SoftwareÊÇÒ»Ì×ÓÃÓÚ¹¤Òµ½ÚÔìϵͳµÄ±à³ÌÈí¼þ¡£¡£¡£¡£¡£ ¡£¡£¡£


ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼ÁËÒ»Ôò°²È«²¼¸æ £¬£¬£¬£¬£¬£¬£¬Åû¼ûÀ¹úRockwell Automation¹«Ë¾MicroLogix 1400 Controllers £¬£¬£¬£¬£¬£¬£¬MicroLogix1100 ControllersºÍRSLogix 500 SoftwareÖеĶà¸ö·ì϶¡£¡£¡£¡£¡£ ¡£¡£¡£¸ÅÊöÈçÏ£º

CVE-2020-6990 £¬£¬£¬£¬£¬£¬£¬ RSLogix 500¶þ½øÔìÎļþʹÓÃÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿ £¬£¬£¬£¬£¬£¬£¬¶ø¸Ã¼ÓÃÜÃÜÔ¿ÓÃÓÚ±£»£»£»£»£»£»£»£»¤ÕË»§ÃÜÂë¡£¡£¡£¡£¡£ ¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¼ø±ð¼ÓÃÜÃÜÔ¿ £¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÓÃÓÚºóÐøµÄÃÜÂë¹¥»÷ £¬£¬£¬£¬£¬£¬£¬×îÖÕ´ï³ÉԽȨ½Ó¼û½ÚÔìÆ÷¡£¡£¡£¡£¡£ ¡£¡£¡£


CVE-2020-6984 £¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚʹÓÃÁ˱»ÆÆ½âµÄ»òÓзçÏÕµÄËã·¨ £¬£¬£¬£¬£¬£¬£¬MicroLogixÖÐÓÃÓÚ±£»£»£»£»£»£»£»£»¤ÃÜÂëµÄ¼ÓÃܺ¯ÊýÈÝÒ×±»·¢ÏÖ¡£¡£¡£¡£¡£ ¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÆÆ½âËã·¨²¢ÈëÇÖÊܱ£»£»£»£»£»£»£»£»¤µÄÊý¾Ý £¬£¬£¬£¬£¬£¬£¬×îÖÕй¼ûô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£¡£


CVE-2020-6988 £¬£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õ߿ɴÓRSLogix 500 SoftwareÏòÊܺ¦ÕßµÄMicroLogix½ÚÔìÆ÷·¢ËÍÒ»¸öÒªÇó £¬£¬£¬£¬£¬£¬£¬½ÚÔìÆ÷»áѡȡÒÑÓùýµÄÃÜÂëÖµÏìÓ¦¿Í»§¶Ë £¬£¬£¬£¬£¬£¬£¬¶ÔÔÚ¿Í»§¶ËÉϵÄÓû§½øÐÐÉí·ÝÈÏÖ¤¡£¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß¿ÉÀûÓôËÖÖÉí·ÝÈÏÖ¤²½ÖèÈÆ¹ýÉí·ÝÈÏÖ¤ £¬£¬£¬£¬£¬£¬£¬Ð¹Â¼ûô¸ÐÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬»òй¶ʹ´¦¡£¡£¡£¡£¡£ ¡£¡£¡£


CVE-2020-6980 £¬£¬£¬£¬£¬£¬£¬RSLogix 500Öб£ÁôÁËSMTPÕË»§Êý¾Ý £¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¸ÃÊý¾ÝÒÔÃ÷ÎÄ´ó¾ÖдÈëµ½ÏîÄ¿ÎļþÖÐ £¬£¬£¬£¬£¬£¬£¬±¾µØ¹¥»÷ÕßÈôÊÇÄܹ»½Ó¼ûÊܺ¦ÕßµÄÏîÄ¿ £¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÄÜÍøÂçSMTP serverµÄÉí·ÝÈÏÖ¤Êý¾Ý¡£¡£¡£¡£¡£ ¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£ ¡£¡£¡£


½¨¸´½¨Òé


¶ÔÓÚʹÓÃMicroLogix 1400 Controllers Series BµÄÓû§ £¬£¬£¬£¬£¬£¬£¬Rockwell½¨Òé¸üа汾ÖÁ21.002»ò¸ü¸ß°æ±¾ £¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓüÓÇ¿µÄÃÜÂ밲ȫְÄÜ £¬£¬£¬£¬£¬£¬£¬Á´½Ó£ºhttps://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx?crumb=112&refSoft=1&toggleState=&versions=56181,56502,56710,57096,58298¡£¡£¡£¡£¡£ ¡£¡£¡£


¶ÔÓÚRSLogix 500Èí¼þ £¬£¬£¬£¬£¬£¬£¬Rockwell Automation½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹ÓÃv11»ò¸ü¸ß°æ±¾ £¬£¬£¬£¬£¬£¬£¬²¢ÓëºÏÓÃÓÚMicrologix 1400ϵÁÐBÉ豸µÄFRN 21.001»ò¸ü¸ß°æ±¾Ò»Â·Ê¹Óà £¬£¬£¬£¬£¬£¬£¬Á´½Ó£ºhttps://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx?crumb=112&refSoft=1&toggleState=&versions=57415,56006¡£¡£¡£¡£¡£ ¡£¡£¡£


¶ø¶ÔÓÚMicroLogix 1400 Series A½ÚÔìÆ÷»òMicroLogix 1100½ÚÔìÆ÷ £¬£¬£¬£¬£¬£¬£¬Rockwell AutomationÏòCISA°µÊ¾Ä¿Ç°ÉÐδÓлº½â´ëÊ©¡£¡£¡£¡£¡£ ¡£¡£¡£


²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-070-06