Rockwell Automation»Ø¾ø·þÎñ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-12-11

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£º CVE-2018-17924£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.6£¬¹Ù·½Î´ÆÀ¶¨



Ó°Ïì°æ±¾



MicroLogix 1400 Controllers Series A£¨È«Êý°æ±¾£©£¬Series B 21.003¼°Ö®Ç°°æ±¾£¬Series C 21.003¼°Ö®Ç°°æ±¾£»1756-ENBT£¨È«Êý°æ±¾£©£¬1756-EWEB Series A£¨È«Êý°æ±¾£©£¬1756-EWEB Series B£¨È«Êý°æ±¾£©£¬1756-EN2F Series A£¨È«Êý°æ±¾£©£¬1756-EN2F Series B£¨È«Êý°æ±¾£©£¬1756-EN2F Series C 10.10¼°Ö®Ç°°æ±¾£¬1756-EN2T Series A£¨È«Êý°æ±¾£©£¬1756-EN2T Series B£¨È«Êý°æ±¾£©£¬1756-EN2T Series C£¨È«Êý°æ±¾£©£¬1756-EN2T 10.10¼°Ö®Ç°°æ±¾£¬1756-EN2TR Series A£¨È«Êý°æ±¾£©£¬1756-EN2TR Series B£¨È«Êý°æ±¾£©£¬Series C 10.10¼°Ö®Ç°°æ±¾£¬1756-EN3TR Series A£¨È«Êý°æ±¾£©£¬1756-EN3TR Series B 10.10¼°Ö®Ç°°æ±¾£¨1756 ControlLogix EtherNet/IPͨѶÄ£¿é£© ¡£



·ì϶¸ÅÊö



ÉÏÖÜËÄ£¬ICS-CERT °ä²¼°²È«²¼¸æÏêÊö¸Ã·ì϶Çé¿ö£¬²»ÍâÂÞ¿ËΤ¶û×Ô¶¯»¯¹«Ë¾ÔÚÊýÖÜǰ¾Í֪ͨ¿Í»§ÓйØÇé¿ö£¬¶øÂÞ¿ËΤ¶û°²È«²¼¸æ½öÏò×¢²áÓû§¹«¿ª ¡£



ÂÞ¿ËΤ¶û¹«Ë¾ºÍ ICS-CERT ¹«Ë¾°µÊ¾£¬¸Ã·ì϶ (CVE-2018-1792) µÄ CVSSv3ÆÀ·ÖΪ8.6£¬Ó°ÏìA¡¢B¡¢CϵÁÐµÄ MicroLogix 1400 ½ÚÔìÆ÷ ¡£Ëü»¹Ó°Ïì1756 ControlLogix ÒÔÌ«Íø/IP ͨѶÄ£¿éµÄ¶à¸ö°æ±¾£¬Ô̺¬A¡¢B¡¢CºÍDϵÁÐ ¡£



ICS-CERT °µÊ¾ÊÜÓ°Ïì²úÆ·ÓÃÓÚÈ«Çò¸÷µØ¶à¸öÐÐÒµ£¬È罻ͨ¡¢¹Ø¼üÔì×÷Òµ¡¢Ê³Æ·ºÍũҵ¡¢ÒÔ¼°Ë®ºÍ·ÏË®ÐÐÒµ ¡£



¸Ã·ì϶¿Éµ¼ÖÂÔ¶³Ìδ¾­ÈÏÖ¤µÄ¹¥»÷Õßµ¼ÖÂÊÜÓ°ÏìÉ豸½øÈë DoS ǰÌá ¡£ÂÞ¿ËΤ¶û¹«Ë¾Ú¹ÊͳÆ£¬Î´¾­ÈÏÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÄÜÏòÊÜÓ°ÏìÉ豸·¢ËÍ CIP ÏνÓÒªÇó²¢Ôڳɹ¦ÏνӺóÏòÊÜÓ°ÏìÉ豸·¢ËÍÐ嵀 IP ÅäÏàÐÅÏ¢£¬¼´±ãϵͳÖеĽÚÔìÆ÷±»ÉèÖÃΪ¡°Hard Run¡±Ä£Ê½ ¡£µ±ÊÜÓ°ÏìÉ豸½ÓÊÜÁËÕâ¸öÐ嵀 IP ÅäÏàÐÅÏ¢ºó£¬É豸ºÍϵͳÆäËü²¿ÃÅÖ®¼ä¾ÍȱʧÁËͨѶ£¬Ô­ÒòÊÇϵÍÂä÷Á¿ÒÀÈ»ÔÚÊÔͼͨ¹ý±»¸²Ð´µÄ IP µØÖ·ºÍÉ豸ͨѶ ¡£



ÂÞ¿ËΤ¶û¹«Ë¾ÒÑΪÊÜÓ°Ïì½ÚÔìÆ÷ºÍͨѶÄ£¿é°ä²¼¹Ì¼þ¸üУ¬µ«¶ÔÆäÖкöà½ö°ä²¼»º½â´ëÊ© ¡£ÕâЩ´ëÊ©Ô̺¬Ê¹Ó÷À»ðǽ×èÖ¹Ô´×ÔԽȨÆðÔ´µÄÒÔÌ«Íø/IP ÐÅÏ¢¡¢Ê¹ÓÃÓ²¼þ°´¼ü¿ª¹ØÉèÖÃ×èÖ¹¶ÔÉ豸½øÐÐԽȨ¸ü¸Ä²¢½«½ÚÔìϵͳµÄÍøÂç¶³ö×îÓ×»¯ ¡£



DoS ·ì϶¿É¶Ô¹¤Òµ»·¾³´øÀ´ÑϳÁ·çÏÕ ¡£¹¤¿Ø»·¾³¿É±»ÓÃÓÚ¶Ô³ö²úϵͳÔì³ÉÑϳÁÇÖº¦ ¡£ºÍ»úÃÜÐÔΪ×î³ÁÒªµÄ IT ÍøÂ粻ͨ£¬²Ù×÷¼¼Êõ (OT) ÍøÂçÔËÓªÈËÔ±×î´óµÄÓÇÓôÊÇ¿ÉÓÃÐÔÎÊÌâ ¡£



·ì϶ÑéÖ¤



ÔÝÎÞPOC/EXP ¡£



½¨¸´½¨Òé



¹Ù·½ÒѾ­°ä²¼ÁËа汾½¨¸´Á˸÷ì϶£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¸üУ¬ÐγɶԴ˷ì϶³Ö¾ÃÓÐЧµÄ·À»¤ ¡£



²Î¿¼Á´½Ó



https://ics-cert.us-cert.gov/advisories/ICSA-18-310-02

https://www.securityfocus.com/bid/106132/solution

https://www.securityweek.com/vulnerability-exposes-rockwell-controllers-dos-attacks