Î÷ÃÅ×ÓS7-1200 PLC²úÆ·Çå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-05

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13945£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.8 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


S7-1200ËùÓа汾


Îó²î¸ÅÊö


Siemens S7-1200 CPUÖб£´æÇå¾²Îó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»á¼ûÆäËûÕï¶Ï¹¦Ð§£¬Ó°ÏìϵͳµÄÍêÕûÐÔ¡¢¿ÉÓÃÐԺͱ£ÃÜÐÔ¡£


Î÷ÃÅ×Ó×î½üÐû²¼ÁËÒ»·ÝÇ徲ͨ¸æ£¬ÆäÖаüÀ¨Õë¶ÔÑо¿Ö°Ô±ÔÚÆäS7-1200¿É±à³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©Öз¢Ã÷µÄÎó²îµÄ±äͨ²½·¥»ººÍ½â²½·¥£¬¸ÃÎó²î¿ÉÓÃÓÚÈÆ¹ý¹Ì¼þÍêÕûÐÔ¼ì²éÒÔ¼ÓÔØ¶ñÒâÈí¼þ»òÐ®ÖÆ×°±¸µÄ¹¤ÒµÁ÷³Ì¡£Î÷ÃÅ×ÓÌåÏÖ£º¡°ÎÒÃÇÕýÔÚÉó²éÎÒÃǵIJúÆ·Ä£×Ó£¬²¢½«ÔÚSSA-686531ÉÏÐû²¼¸üУ¬ÒÔ·ÀÆäËûÄ£×ÓÊܵ½Ó°Ïì¡£Ñо¿Ö°Ô±»¹·¢Ã÷£¬¿É±à³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©ÖеÄÌØÊâ»á¼û¹¦Ð§Ò²¿ÉÒԺܺõØÓÃ×÷£º×÷Ϊ·ÀÓùÕßµÄȡ֤¹¤¾ß¡£ËûÃÇʹÓøù¦Ð§Éó²éPLC´æ´¢Æ÷µÄÄÚÈÝ£¬Òò´Ë¹¤³§²Ù×÷Ô±Ò²¿ÉÒÔʹÓÃËüÀ´²éÕÒÉè±¹ØÁ¬Ä¶ñÒâ´úÂë¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥½â¾ö´ËÇå¾²ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö²½·¥£ºhttps://www.siemens.com£»


S7-122 CPUµÄÓû§¿ÉÒÔ½ÓÄÉÕâЩ±äͨ²½·¥»ººÍ½â²½·¥À´½µµÍΣº¦£º


1.È·±£ÎïÆÊÎö¼û±£»¤£»

2.Ó¦ÓÃÉî¶È·ÀÓù¡£


²Î¿¼Á´½Ó


https://www.darkreading.com/vulnerabilities---threats/siemens-offers-workarounds-for-newly-found-plc-vulnerability/d/d-id/1336503