Rockwell Automation¿É±à³ÌÂß¼½ÚÔìÆ÷°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-03-18·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-6990£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-6984£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-6988£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-6980£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º4.0£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001¼°Ö®Ç°°æ±¾ºÍSeries AËùÓа汾
MicroLogix 1100 ControllerËùÓа汾
RSLogix 500 Software v12.001¼°Ö®Ç°°æ±¾
·ì϶¸ÅÊö
ÃÀ¹úRockwell Automation¹«Ë¾ÊÇÈ«Çò×î´óµÄ×Ô¶¯»¯ºÍÐÅÏ¢»¯¹«Ë¾Ö®Ò»¡£¡£¡£¡£¡£¡£¡£¡£MicroLogix 1400 ControllersºÍMicroLogix 1100 ControllersÊÇRockwell Automation¹«Ë¾³öÆ·µÄ¿É±à³ÌÂß¼½ÚÔìÆ÷¡£¡£¡£¡£¡£¡£¡£¡£RSLogix 500 SoftwareÊÇÒ»Ì×ÓÃÓÚ¹¤Òµ½ÚÔìϵͳµÄ±à³ÌÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£
ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼ÁËÒ»Ôò°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬Åû¼ûÀ¹úRockwell Automation¹«Ë¾MicroLogix 1400 Controllers£¬£¬£¬£¬£¬£¬£¬MicroLogix1100 ControllersºÍRSLogix 500 SoftwareÖеĶà¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸ÅÊöÈçÏ£º
CVE-2020-6990£¬£¬£¬£¬£¬£¬£¬ RSLogix 500¶þ½øÔìÎļþʹÓÃÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬¶ø¸Ã¼ÓÃÜÃÜÔ¿ÓÃÓÚ±£»£»£»£»£»£»£»£»¤ÕË»§ÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¼ø±ð¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÓÃÓÚºóÐøµÄÃÜÂë¹¥»÷£¬£¬£¬£¬£¬£¬£¬×îÖÕ´ï³ÉԽȨ½Ó¼û½ÚÔìÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6984£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚʹÓÃÁ˱»ÆÆ½âµÄ»òÓзçÏÕµÄËã·¨£¬£¬£¬£¬£¬£¬£¬MicroLogixÖÐÓÃÓÚ±£»£»£»£»£»£»£»£»¤ÃÜÂëµÄ¼ÓÃܺ¯ÊýÈÝÒ×±»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÆÆ½âËã·¨²¢ÈëÇÖÊܱ£»£»£»£»£»£»£»£»¤µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬×îÖÕй¼ûô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6988£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õ߿ɴÓRSLogix 500 SoftwareÏòÊܺ¦ÕßµÄMicroLogix½ÚÔìÆ÷·¢ËÍÒ»¸öÒªÇ󣬣¬£¬£¬£¬£¬£¬½ÚÔìÆ÷»áѡȡÒÑÓùýµÄÃÜÂëÖµÏìÓ¦¿Í»§¶Ë£¬£¬£¬£¬£¬£¬£¬¶ÔÔÚ¿Í»§¶ËÉϵÄÓû§½øÐÐÉí·ÝÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓôËÖÖÉí·ÝÈÏÖ¤²½ÖèÈÆ¹ýÉí·ÝÈÏÖ¤£¬£¬£¬£¬£¬£¬£¬Ð¹Â¼ûô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬»òй¶ʹ´¦¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6980£¬£¬£¬£¬£¬£¬£¬RSLogix 500Öб£ÁôÁËSMTPÕË»§Êý¾Ý£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¸ÃÊý¾ÝÒÔÃ÷ÎÄ´ó¾ÖдÈëµ½ÏîÄ¿ÎļþÖУ¬£¬£¬£¬£¬£¬£¬±¾µØ¹¥»÷ÕßÈôÊÇÄܹ»½Ó¼ûÊܺ¦ÕßµÄÏîÄ¿£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÄÜÍøÂçSMTP serverµÄÉí·ÝÈÏÖ¤Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
¶ÔÓÚʹÓÃMicroLogix 1400 Controllers Series BµÄÓû§£¬£¬£¬£¬£¬£¬£¬Rockwell½¨Òé¸üа汾ÖÁ21.002»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓüÓÇ¿µÄÃÜÂ밲ȫְÄÜ£¬£¬£¬£¬£¬£¬£¬Á´½Ó£ºhttps://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx?crumb=112&refSoft=1&toggleState=&versions=56181,56502,56710,57096,58298¡£¡£¡£¡£¡£¡£¡£¡£
¶ÔÓÚRSLogix 500Èí¼þ£¬£¬£¬£¬£¬£¬£¬Rockwell Automation½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹ÓÃv11»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬£¬²¢ÓëºÏÓÃÓÚMicrologix 1400ϵÁÐBÉ豸µÄFRN 21.001»ò¸ü¸ß°æ±¾Ò»Â·Ê¹Ó㬣¬£¬£¬£¬£¬£¬Á´½Ó£ºhttps://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx?crumb=112&refSoft=1&toggleState=&versions=57415,56006¡£¡£¡£¡£¡£¡£¡£¡£
¶ø¶ÔÓÚMicroLogix 1400 Series A½ÚÔìÆ÷»òMicroLogix 1100½ÚÔìÆ÷£¬£¬£¬£¬£¬£¬£¬Rockwell AutomationÏòCISA°µÊ¾Ä¿Ç°ÉÐδÓлº½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-070-06


¾©¹«Íø°²±¸11010802024551ºÅ