¸»Ê¿µç»úËÅ·þϵͳºÍÇý¶¯0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-09-30

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-14794 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ9.8 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-14788 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ5.3 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Alpha5 Smart Loader Versions 3.7¼°Ö®Ç°°æ±¾


·ì϶¸ÅÊö


ICS-CERT ºÍÇ÷Ïò¿Æ¼¼ ZDI ÍŶӱ¾ÖÜÅû¶³Æ £¬ÈÕ±¾¸»Ê¿µç»ú¹«Ë¾µÄËÅ·þϵͳºÍÇý¶¯ÖдæÔÚ¶à¸ö佨¸´µÄ·ì϶¡£×êÑÐÔ± Michael Flanders ÔÚ¸»Ê¿µç»úµÄ Alpha 5 ÖÇÄÜËÅ·þϵͳLoader Èí¼þÖз¢ÏÖÁËÁ½¸ö·ì϶¡£


ÊÜÓ°Ïì²úÆ·ÖØÒªÓÃÓÚÅ·ÖÞºÍÑÇÖÞµÄóÒ×ÉèÊ©ºÍ¹Ø¼üÔì×÷ÐÐÒµÖÐ £¬×÷ÓÃÊÇͨ¹ýµ÷Õû £¬Ê¹Çý¶¯¶àÖÖ»úеµÄµç¶¯»ú¿ÉÄÜÕýÈ·ÔËÐС£


ÆäÖÐÒ»¸ö·ì϶ÊÇÑϳÁµÄ¶Ñ»º³åÇøÒç³ö (CVE-2018-14794) ·ì϶ £¬Äܵ¼ÖÂÔ¶³Ì¹¥»÷ÕßÓÕÆ­Ö¸±ê´ò¿ªÒ»¸ö³ö¸ñ»ú¹ØµÄ C5V Îļþ £¬´Ó¶øÖ´ÐÐËÁÒâ´úÂë¡£ZDI ÔÚ°²È«²¼¸æÖÐÖ¸³ö £¬¡°Õâ¸öÎÊÌâ²úÉúµÄÔ­ÒòÊÇÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´Ôìµ½Ò»¸ö³¤¶È¹Ì¶¨ÇÒ»ùÓڶѵĻº³å֮ǰ £¬²»×ã¶Ô¸ÃÊý¾ÝµÄÕýÈ·ÑéÖ¤¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâ¸ö·ì϶ÔÚÖÎÀíÔ±¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡±

Ó°ÏìËÅ·þϵͳµÄµÚ¶þ¸ö·ì϶ÊÇÒ»¸öÖÐΣµÄ»º³åÇøÒç¶Âí½Å £¬¿Éµ¼ÖÂÔÚ´¦ÖÃÌØÊâ»ú¹ØµÄ A5P Îļþʱ £¬Ãô¸ÐÐÅÏ¢Ôâ¶³ö¡£µ±½áºÏÆäËü·ì϶ʹÓÃʱ £¬¹¥»÷Õß¿ÉÄÜÒÔÖÎÀíԱȨÏÞÀûÓøà bug Ö´ÐÐËÁÒâ´úÂë¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC\EXP


½¨¸´½¨Òé


ZDI ´ÍÓ븻ʿµç»ú120ÌìµÄ¹¦·ò½¨¸´¸Ã·ì϶¡£¸»Ê¿µç»ú±¾Öܹ²°ä²¼5ƪ°²È«²¼¸æ £¬Ä¿Ç°ÓÉÓÚÉÐÎ´ÍÆ³ö²¹¶¡ £¬Òò¶øËüÃǾùÊôÓÚ 0day ·ì϶״̬¡£


¸»Ê¿µç»ú¹«Ë¾°µÊ¾ÔÚÍÆ³ö²¹¶¡¹æ»®¡£ÔÚ´Ë֮ǰ £¬¸Ã¹«Ë¾½¨ÒéÓû§Ô¤·ÀÔÚÊÜÓ°ÏìÀûÓ÷¨Ê½Öв»ÊÜÐÅÀµµÄÎļþ¡£


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-270-02
https://www.securityweek.com/no-patches-critical-flaws-fuji-electric-servo-system-drives