Emerson OpenEnterprise SCADA | ¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-05-29

0x00 Îó²î¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Ó°Ïì¹æÄ£

Emerson OpenEnterprise SCADA

CVE-2020-6970

BO

ÑÏÖØ

ÊÇ

Emerson OpenEnterprise SCADA Server 3.1-3.3.3,2.83°æ±¾

CVE-2020-10640

MA

ÑÏÖØ

ÊÇ

Emerson OpenEnterprise SCADA <= 3.3.4

CVE-2020-10632

IOM

¸ßΣ

·ñ

CVE-2020-10636

IES

ÖÐΣ

·ñ


0x01 Îó²îÏêÇé


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Emerson Electric OpenEnterpriseÊÇÃÀ¹ú°¬Ä¬ÉúµçÆø£¨Emerson Electric£©¹«Ë¾µÄÒ»Ì×Ö÷ÒªÓÃÓÚÔ¶³ÌʯÓͺÍ×ÔÈ»ÆøÓ¦ÓõÄÊý¾ÝÊÕÂÞÓë¼à¿ØÏµÍ³£¨SCADA£©¡£¡£¡£¡£¡£

¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¿¨°Í˹»ùµÄÑо¿Ö°Ô±Roman Lozko·¢Ã÷ÁËEmerson OpenEnterpriseÖеÄËĸöÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÕâËĸöÎó²î»®·ÖΪ»ùÓڶѵĻº³åÇøÒç³ö¡¢È±ÉÙÉí·ÝÑéÖ¤¡¢ËùÓÐȨÖÎÀí²»µ±ºÍÈõ¼ÓÃÜÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º

CVE-2020-6970ÊÇEmerson Electric OpenEnterprise SCADA ServerÖб£´æµÄ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬CVE-2020-10640ÊÇEmerson Electric OpenEnterpriseÖб£´æµÄÇå¾²Îó²î¡£¡£¡£¡£¡£ÒÔÉÏÁ½¸öÎó²î¶¼±»ÆÀ¼¶Îª¡°ÑÏÖØ¡±£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹ¹¥»÷ÕßÔÚÔËÐÐOpenEnterpriseµÄ×°±¸ÉÏÒÔÌáÉýµÄÌØÈ¨Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

CVE-2020-10632ÊÇEmerson Electric OpenEnterpriseÖб£´æµÄÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòΪÎļþ¼ÐÉèÖÃÁ˲»Çå¾²µÄȨÏÞ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÐÞ¸ÄÖ÷ÒªµÄÉèÖÃÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Ôì³Éϵͳ¹ÊÕÏ»òÒì³£¡£¡£¡£¡£¡£

CVE-2020-10636ÊÇEmerson Electric OpenEnterpriseÖб£´æµÄ¼ÓÃÜÎÊÌâÎó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡OpenEnterpriseÓû§ÕÊ»§µÄÃÜÂë¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.emerson.com/


0x03 Ïà¹ØÐÂÎÅ


https://www.securityweek.com/vulnerabilities-found-emerson-scada-product-made-oil-and-gas-industry


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-049-02

https://www.us-cert.gov/ics/advisories/icsa-20-140-02


0x05 ʱ¼äÏß


2020-05-29 VSRCÐû²¼Îó²îͨ¸æ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾