CVE-2020-6994| ºÕ˹ÂüHiOSºÍHiSecOS²úÆ·°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-01

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-6994

ʱ    ¼ä

2020-04-01

Àà    ÐÍ

»º³åÇøÒç³ö

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

HiOS <= 07.0.02 Ó°Ïì²úÆ·£ºRSP£¬RSPE£¬RSPS£¬RSPL£¬MSP£¬EES£¬ EESX£¬GRS£¬OS£¬RED»¥»»»ú£»

HiSecOS0 <= 3.2.00 Ó°Ïì²úÆ·£ºEAGLE 20/30·À»ðǽ

x01 ·ì϶ÏêÇé


µÂ¹úºÕ˹Âü×Ô¶¯»¯ºÍ½ÚÔ칫˾µÞÔìÓÚ1924Ä꣬ҵÎñÉ¢²¼ÔÚ×Ô¶¯»¯Í¨Ñ¶ÁìÓò£¬²úÆ·ÁìÓòÔ̺¬Ñ¡È¡·ÂÕÕºÍÊý×ֹ㲥µçÊÓ´«Êä¼¼ÊõµÄÒÆ¶¯·¢ÉäºÍ½Ó¹Üϵͳ£¬ÆóÒµºÍ¹¤ÒµÍøÂç½â¾ö¹æ»®ÒÔ¼°ÏÖ³¡×ÜÏßϵͳ¡£ºÕ˹ÂüÔÚ2007Äê±»ÃÀ¹ú°Ùͨ£¨Belden£©¹«Ë¾ÊÕ¹º¡£ºÕ˹ÂüHiOSºÍHiSecOS¶¼ÊǰÙÍ¨ÍÆ³öµÄ°²È«²Ù×÷ϵͳ¡£


HiOSºÍHiSecOSµÄHTTP(S)web serverÖдæÔÚÒ»¸ö»º³åÇøÒç¶Âí½Å¡£¸Ã·ì϶ԴÓÚ¶ÔURL²ÎÊýµÄ½âÎö²»µ±ÒýÆðµÄ¡£¹¥»÷ÕßÄܹ»½èÖúÌØÔìµÄHTTPÒªÇóÈëÇÖÖ¸±êÉ豸£¬Ôì³ÉÄÚ²¿»º³åÇøÒç³ö¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѽ¨¸´¸Ã·ì϶£¬½¨ÒéHiOSÓû§¾¡¿ì¸üÐÂÖÁ07.0.03»ò¸ü¸ß°æ±¾£¬HiSecOSÓû§¸üÐÂÖÁ03.3.00»ò¸ü¸ß°æ±¾¡£

һʱ´ëÊ©¿ÉʹÓá°IP½Ó¼ûÏÞ¶È¡±Ö°ÄÜ£¬ÏÞ¶ÈHTTPºÍHTTPS¶Ô¿ÉÐÅIPµØÖ·µÄ½Ó¼û£¬»òÕß½ûÓÃHTTPºÍHTTPS·þÎñÆ÷¡£


https://www.belden.com/hubfs/support/security/bulletins/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf?hsLang=en


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-091-01


0x05 ¹¦·òÏß


2020-02-14 °ä²¼·ì϶

2020-02-26 ÍÆ³ö½â¾ö¹æ»®

2020-03-24 »ñµÃCVE±àºÅ