Emerson OpenEnterprise SCADA | ¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-290x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
Emerson OpenEnterprise SCADA |
CVE-2020-6970 |
BO |
ÑϳÁ |
ÊÇ |
Emerson OpenEnterprise SCADA Server 3.1-3.3.3,2.83°æ±¾ |
|
CVE-2020-10640 |
MA |
ÑϳÁ |
ÊÇ |
Emerson OpenEnterprise SCADA <= 3.3.4 |
|
|
CVE-2020-10632 |
IOM |
¸ßΣ |
·ñ |
||
|
CVE-2020-10636 |
IES |
ÖÐΣ |
·ñ |
0x01 ·ì϶ÏêÇé
Emerson Electric OpenEnterpriseÊÇÃÀ¹ú°¬Ä¬ÉúµçÆø£¨Emerson Electric£©¹«Ë¾µÄÒ»Ì×ÖØÒªÓÃÓÚÔ¶³ÌʯÓͺÍÌìÈ»ÆøÀûÓõÄÊý¾Ý²É¼¯Óë¼à¿ØÏµÍ³£¨SCADA£©¡£¡£¡£¡£¡£¡£¡£
½üÈÕ£¬£¬£¬£¬£¬¿¨°Í˹»ùµÄ×êÑÐÈËÔ±Roman Lozko·¢ÏÖÁËEmerson OpenEnterpriseÖеÄËĸö°²È«·ì϶£¬£¬£¬£¬£¬ÕâËĸö·ì϶±ðÀëΪ»ùÓڶѵĻº³åÇøÒç³ö¡¢¶ÌȱÉí·ÝÑéÖ¤¡¢ËùÓÐȨÖÎÀí²»µ±ºÍÈõ¼ÓÃÜÎÊÌ⣬£¬£¬£¬£¬¾ßÌåÐÅÏ¢ÈçÏ£º
CVE-2020-6970ÊÇEmerson Electric OpenEnterprise SCADA ServerÖдæÔڵĻº³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬CVE-2020-10640ÊÇEmerson Electric OpenEnterpriseÖдæÔڵݲȫ·ì϶¡£¡£¡£¡£¡£¡£¡£ÒÔÉÏÁ½¸ö·ì϶¶¼±»ÆÀ¼¶Îª¡°ÑϳÁ¡±£¬£¬£¬£¬£¬Äܹ»Ê¹¹¥»÷ÕßÔÚÔËÐÐOpenEnterpriseµÄÉ豸ÉÏÒÔÌáÉýµÄÌØÈ¨Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
CVE-2020-10632ÊÇEmerson Electric OpenEnterpriseÖдæÔڵݲȫ·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚ·¨Ê½ÎªÎļþ¼ÐÉèÖÃÁ˲»°²È«µÄȨÏÞ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶Åú¸Ä³ÁÒªµÄÅäÖÃÎļþ£¬£¬£¬£¬£¬Ôì³Éϵͳ¹ÊÕÏ»òÒì³£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-10636ÊÇEmerson Electric OpenEnterpriseÖдæÔڵļÓÃÜÎÊÌâ·ì϶¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡OpenEnterpriseÓû§ÕÊ»§µÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º
https://www.emerson.com/
0x03 ÓйØÐÂÎÅ
https://www.securityweek.com/vulnerabilities-found-emerson-scada-product-made-oil-and-gas-industry
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-049-02
https://www.us-cert.gov/ics/advisories/icsa-20-140-02
0x05 ¹¦·òÏß
2020-05-29 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ