GE URϵÁжà¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-03-240x00 Îó²î¸ÅÊö
2021Äê03ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬CISAÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬¹ûÕæÁËGE£¨Í¨ÓÃµçÆø¹«Ë¾£©URϵÁУ¨µçÔ´ÖÎÀí×°±¸£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚ¿ØÖƺͱ£»£»£»£»£»£»£»£»¤ÖÖÖÖ×°±¸µÄ¹¦ºÄ£©ÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓÃÕâЩÎó²îµÄ¹¥»÷ÕßÄܹ»»á¼ûÃô¸ÐÐÅÏ¢¡¢ÖØÆôUR¡¢ÌáÉýȨÏÞ»òµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé

±¾´Î¹ûÕæµÄUR×°±¸ÖеÄÎó²îÈçÏ£º
CVE-ID | CVSSÆÀ·Ö | ÀàÐÍ | ÏêÇé |
CVE-2016-2183 CVE-2013-2566 | 7.5 | ¼ÓÃÜÇ¿¶Èȱ·¦ | ÔÚUR¹Ì¼þ°æ±¾8.1x֮ǰ£¬£¬£¬£¬£¬£¬£¬£¬UR SSHͨѶʹÓÃÈõ¼ÓÃܺÍMACËã·¨¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-1999-1085 | 5.3 | »á»°Àο¿ | ÔÚ7.4x¹Ì¼þ°æ±¾Ö®Ç°£¬£¬£¬£¬£¬£¬£¬£¬UR½öÖ§³ÖSSHv2¡£¡£¡£¡£¡£¡£¡£¡£´Ó¹Ì¼þ°æ±¾7.4x×îÏÈ£¬£¬£¬£¬£¬£¬£¬£¬URÖ§³Ö¾ßÓÐÒÑÖªÎó²îµÄSSHv1£¨SSHÐÒé»á»°ÃÜÔ¿¼ìË÷ºÍ²åÈë¹¥»÷£©¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27422 | 7.5 | ÐÅϢй¶ | UR over HTTPÐÒéÖ§³ÖWebЧÀÍÆ÷½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬£¬ËüÄܹ»µ¼ÖÂδ¾Éí·ÝÑé֤й¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27418 | 5.3 | ÊäÈëÑéÖ¤²»×¼È· | URÖ§³Ö¾ßÓÐÖ»¶Á»á¼ûȨÏÞµÄWeb½çÃæ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ×°±¸ÎÞ·¨×¼È·ÑéÖ¤ÊäÈ룬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂXSS¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷¿ÉÓÃÓÚ·¢ËͶñÒâ¾ç±¾¡£¡£¡£¡£¡£¡£¡£¡£ÁíÍ⣬£¬£¬£¬£¬£¬£¬£¬UR¹Ì¼þWebЧÀÍÆ÷²î³ØÓû§ÌṩµÄ×Ö·û´®Ö´ÐÐHTML±àÂë¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27420 | 5.3 | ÊäÈëÑéÖ¤²»×¼È· | UR Firmware WebЧÀÍÆ÷ʹÃüûÓÐ׼ȷ´¦Öóͷ£ÎüÊÕ²»Ö§³ÖµÄHTTP verbs£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂWebЧÀÍÆ÷ÔÚÎüÊÕµ½Ò»ÏµÁв»Ö§³ÖµÄHTTPÇëÇóºóÔÝʱ²»ÏìÓ¦¡£¡£¡£¡£¡£¡£¡£¡£µ±ÎÞÏìӦʱ£¬£¬£¬£¬£¬£¬£¬£¬WebЧÀÍÆ÷ÊDz»¿É»á¼ûµÄ¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27428 | 7.5 | ÎļþÉÏ´« | UR IEDÖ§³ÖʹÓÃUR SetupÉèÖù¤¾ß--Enervista UR SetupÉý¼¶¹Ì¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃUR Setup¹¤¾ßÔÚÉÏ´«UR IED֮ǰÑéÖ¤¹Ì¼þÎļþµÄÕæÊµÐÔºÍÍêÕûÐÔ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚûÓÐÊʵ±È¨ÏÞµÄÇéÐÎÏÂÉý¼¶¹Ì¼þ¡£¡£¡£¡£¡£¡£¡£¡££¨¹Ì¼þ8.10°æ±¾ÖÐÓ¦Óûº½â²½·¥¡£¡£¡£¡£¡£¡£¡£¡££© |
CVE-2021-27426 | 9.8 | ²»Çå¾²µÄĬÈϱäÁ¿³õʼ»¯ | ¾ßÓС°Basic¡±Çå¾²ÐÔ±äÌåµÄUR IED²»ÔÊÐí½ûÓá°Factory Mode¡±£¬£¬£¬£¬£¬£¬£¬£¬¸ÃģʽÓÃÓÚΪ¡°Factory¡±Óû§Î¬ÐÞIED¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27424 | 5.3 | ÐÅϢй¶ | ×÷ΪͨѶָÄϵÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬£¬£¬UR¹²ÏíMODBUSÄÚ´æÓ³Éä¡£¡£¡£¡£¡£¡£¡£¡£GEÊÕµ½ ¡°Last-key pressed¡±µÄMODBUS¼Ä´æÆ÷¿ÉÒÔ±»ÓÃÀ´»ñȡδ¾ÊÚȨµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-27430 | 8.4 | Ó²±àÂëÆ¾Ö¤ | UR bootloader¶þ½øÖư汾7.00¡¢7.01ºÍ7.02°üÀ¨Î´Ê¹ÓõÄÓ²±àÂëÆ¾Ö¤¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»ÎïÆÊÎö¼ûUR IEDµÄÓû§¿ÉÒÔͨ¹ýÖØÐÂÆô¶¯URÀ´ÖÐÖ¹Æô¶¯ÐòÁС£¡£¡£¡£¡£¡£¡£¡£ |
Ó°Ïì¹æÄ£
GE URϵÁУ¨B30¡¢B90¡¢C30¡¢C60¡¢C70¡¢C95¡¢D30¡¢D60¡¢F35¡¢F60¡¢G30¡¢G60¡¢L30¡¢L60¡¢L90¡¢M60¡¢N60¡¢T35¡¢T60£©£º
SSHÏà¹ØµÄÎó²î£º¹Ì¼þ°æ±¾7.4x-08.0x£¨CyberSentryÑ¡Ï
WebЧÀÍÆ÷Îó²î£º8.1x֮ǰµÄËùÓй̼þ°æ±¾
¹Ì¼þÉÏ´«£º¾ßÓлù±¾Çå¾²ÐÔÑ¡ÏîµÄ8.1x֮ǰµÄËùÓй̼þ°æ±¾
½ûÓóö³§Ä£Ê½£º¾ßÓлù±¾Çå¾²ÐÔÑ¡ÏîµÄ8.1x֮ǰµÄËùÓй̼þ°æ±¾
»á¼û¡°Last-key pressed¡±µÄ¼Ä´æÆ÷£º¾ßÓлù±¾Çå¾²ÐÔÑ¡ÏîµÄ8.1x֮ǰµÄËùÓй̼þ°æ±¾
UR Bootloader¶þ½øÖÆÎļþ£º7.03/7.04֮ǰµÄËùÓÐBootloader°æ±¾
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬£¬½¨Ò齫UR×°±¸¸üÐÂΪUR¹Ì¼þ°æ±¾8.10»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£¸ü¶àÐÅÏ¢Çë²Î¿¼CISA¹Ù·½Í¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£
Ïà¹ØÁ´½Ó£º
https://www.gegridsolutions.com/Passport/Login.aspx
0x03 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ics/advisories/icsa-21-075-02
https://securityaffairs.co/wordpress/115881/security/cisa-ge-power-management-devices-flaws.html?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27426
0x04 ʱ¼äÏß
2021-03-16 CISAÐû²¼Ç徲ͨ¸æ
2021-03-24 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ