Phoenix Contact Automation Worx¶à¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-26

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12869£¬£¬£¬Î£ÏÕ¼¶±ð£ºµÍΣ£¬£¬£¬CVSS·ÖÖµ³§ÉÌ×ÔÆÀ£º3.3£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12870£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ³§ÉÌ×ÔÆÀ£º7.8£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-12871£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ³§ÉÌ×ÔÆÀ£º7.8£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚPhoenix Contact Automation Worx Software SuiteÖеÄPC Worx 1.86¼°Ö®Ç°°æ±¾¡¢PC Worx Express 1.86¼°Ö®Ç°°æ±¾ºÍConfig+ 1.86¼°Ö®Ç°°æ±¾¡£¡£ ¡£¡£


Îó²î¸ÅÊö


Phoenix Contact Automation Worx Software SuiteÊǵ¹ú·ÆÄá¿Ë˹µçÆø£¨Phoenix Contact£©¹«Ë¾µÄÒ»Ì××Ô¶¯»¯WorxÈí¼þÌ×¼þ¡£¡£ ¡£¡£PC WorxÊÇÆäÖеÄÒ»Ì׿ØÖÆÆ÷±à³ÌÈí¼þ¡£¡£ ¡£¡£Config+ÊÇÆäÖеÄÒ»Ì×ÓÃÓÚÉèÖúÍÕï¶ÏINTERBUSϵͳµÄÈí¼þ¡£¡£ ¡£¡£


Phoenix Contact Automation WorxÖб£´æ¶à¸öÎó²î£¬£¬£¬ÏêϸÈçÏ£º


CVE-2019-12869£º


¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬£¬£¬Î´×¼È·ÑéÖ¤Êý¾Ý½çÏߣ¬£¬£¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æÎ»ÖÃÉÏÖ´ÐÐÁ˹ýʧµÄ¶Áд²Ù×÷¡£¡£ ¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£¡£ ¡£¡£


CVE-2019-12870£º


¸ÃÎó²îÔ´ÓÚÔÚ»á¼ûÖ¸Õë֮ǰȱÉÙÊʵ±µÄÖ¸Õë³õʼ»¯¡£¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÄ¿½ñÀú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë

¡£¡£ ¡£¡£

CVE-2019-12871£º


¸ÃÎó²îÔ´ÓÚÔÚ¶Ô¹¤¾ßÖ´ÐвÙ×÷֮ǰȱ·¦ÑéÖ¤¹¤¾ßÊÇ·ñ±£´æ¡£¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÄ¿½ñÀú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£¡£ ¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£ ¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.phoenixcontact.com/


²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/ZDI-19-579/
https://www.zerodayinitiative.com/advisories/ZDI-19-575/
https://www.zerodayinitiative.com/advisories/ZDI-19-576/