Î÷ÃÅ×ÓÁ½¿î²úÆ·ÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-09-13

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-13799 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.1 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-13807 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.6 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


SIMATIC WinCC OA Version <= 3.14

SCALANCE X300 Version < 4.0.0

SCALANCE X408 Version < 4.0.0

SCALANCE X414 ËùÓа汾


·ì϶¸ÅÊö


Î÷ÃÅ×Ó¹Ù·½°ä²¼¹«¸æ½¨¸´ÁËÆäÁ½¿î²úÆ·µÄ°²È«·ì϶ £¬ÊÜÓ°Ïì²úÆ·Ô̺¬SIMATIC WinCC OA¡¢SCALANCE X»¥»»»ú¡£


SIMATIC WinCC OAµÄ·ì϶CVE-2018-13799ÊÇÓÉÓÚ5678/TCP¶Ë¿ÚµÄ½Ó¼û½ÚÔì²»µ±¶ø²úÉú £¬³É¹¦ÀûÓø÷ì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚSIMATIC WinCC OA»·¾³ÖÐÌáÉýÆäȨÏÞ¡£


SCALANCE X»¥»»»úµÄ·ì϶CVE-2018-13807¿ÉÔÊÐí¹¥»÷Õßͨ¹ýÏòWeb·þÎñÆ÷·¢ËÍÌØÔìÊý¾Ý°üÀ´µ¼Ö»ؾø·þÎñ¡£Ê¹É豸×Ô¶¯³ÁÆô £¬Ó°ÏìÆäËûÉ豸µÄÍøÂç¿ÉÓÃÐÔ¡£²»Íâ¹¥»÷Õß±ØÐëÓµÓжÔ443/TCP¶Ë¿ÚµÄÍøÂç½Ó¼ûÄÜÁ¦ÄÜÁ¦ÀûÓô˷ì϶ £¬ÀûÓô˷ì϶¼È²»±ØÒªÓÐЧʹ´¦Ò²²»±ØÒªºÏ·¨Óû§µÄ½»»¥¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC\EXP


½¨¸´½¨Òé


Î÷ÃÅ×Ó¹Ù·½ÒѾ­°ä²¼ÁËSIMATIC WinCC OAÓйز¹¶¡½¨¸´ÁËÉÏÊö·ì϶ £¬¿É´ÓÒÔÏÂÁ´½Ó»ñµÃ£º

https://portal.etm.at/index.php?option=com_content&view=category&id=67&layout=blog&Itemid=80 £¨ÒªÇóµÇ¼£©


Î÷ÃÅ×Ó»¹½¨ÒéѡȡÒÔÏÂÊÖ¶¯»º½â´ëÊ©À´½µµÍ·çÏÕ£º

ÒÀÕÕÒÔÏÂÁ´½ÓÖеIJ½ÖèÊÖ¶¯½¨¸´·ì϶£º

https://portal.etm.at/patchdownload.php?fp=version_3.14/win64vc12/ReadmeP021.txt £¨ÒªÇóµÇ¼£©

×ñÑ­SIMATIC WinCC OA°²È«Ö¸ÄÏÒÔÊØ»¤°²È«µÄSIMATIC WinCC OA»·¾³£º

https://portal.etm.at/index.php?option=com_phocadownload&view=category&id=52:security&Itemid=81 £¨ÒªÇóµÇ¼£©

ÀûÓÃÉî¶È·ÀÓù£º

https://www.siemens.com/cert/operational-guidelines-industrial-security

 

Î÷ÃÅ×ÓΪSCALANCE X300ºÍSCALANCE X408Ìṩ¸üР£¬²¢ÎªSCALANCE X414Ìṩ»º½â´ëÊ©¡£

SCALANCE X300£º¸üÐÂÖÁ4.1.2°æ

https://support.industry.siemens.com/cs/us/en/view/109753720

SCALANCE X408£º¸üÐÂÖÁ4.1.2°æ

https://support.industry.siemens.com/cs/us/en/view/109753720

SCALANCE X414£º

Î÷ÃÅ×ÓÒÑÈ·¶¨Óû§Äܹ»ÀûÓÃÒÔϽâ¾ö¹æ»®»ººÍ½â´ëÊ©½µµÍ·çÏÕ£º

ʹÓÃÊʵ±µÄ»úÔì±£»¤¶Ô443/TCP¶Ë¿ÚÉϼ¯³ÉµÄWeb·þÎñÆ÷µÄÍøÂç½Ó¼û¡£

½«443/TCP¶Ë¿ÚµÄÍøÂç½Ó¼ûÏÞ¶ÈÔÚ¿ÉÐÅIPµØÖ·ÄÚ £¬²¢Ô¤·ÀÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÔËÐÐÀ´×Ô¿ÉÐÅIPµØÖ·µÄ·ì϶ɨÃ蹤¾ß¡£


²Î¿¼Á´½Ó

https://ics-cert.us-cert.gov/advisories/ICSA-18-254-05   https://www.siemens.com/global/en/home/products/services/cert.html#SecurityPublications