Î÷ÃÅ×ÓSPPA-T3000¶à¸öÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-16Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-18283£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18315£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18316£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18314£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-18313£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÂþÑÜʽ¿ØÖÆÏµÍ³SPPA-T3000
Îó²î¸ÅÊö
Î÷ÃÅ×Ó¹¤Òµ×°±¸Öб»ÆØ±£´æ¶à¸öÇå¾²Îó²î£¬ ÊÜÓ°Ïì²úÆ·ÊÇÂþÑÜʽ¿ØÖÆÏµÍ³SPPA-T3000£¬±é²¼ÓÚÃÀ¹ú¡¢µÂ¹ú¡¢¶íÂÞ˹ºÍÆäËü¹ú¼ÒµÄÖ÷Òª·¢µç³§ÖУ¬ÓÃÓÚÐе÷¼àÊÓ·¢µç¡£
ʹÓÃÆäÖеÄһЩÎó²î¿ÉÔÚÓ¦ÓóÌÐò·þÎñÆ÷ÉÏÔËÐÐí§Òâ´úÂ룬´Ó¶ø¿ØÖƲÙ×÷²¢ÊµÑ鯯Ëð¡£ÕâÑù×ö¿ÉÄÜ×èÖ¹×°ÖÃÒ×Êܹ¥»÷ϵͳµÄ·¢µç³§·¢µç²¢Òý·¢¹ÊÕÏ¡£
ÕâЩÎó²î±£´æÓÚ¸ÃÆ½Ì¨µÄÁ½¸öÏêϸ×é¼þÖУºÓ¦ÓóÌÐò·þÎñÆ÷»ººÍ½â·þÎñÆ÷¡£
ÆäÖÐ×îÑÏÖØµÄÎó²î¿É´¥·¢Ó¦ÓóÌÐòÉϵÄÔ¶³Ì´úÂëÖ´ÐÐÎÊÌâ¡£ÀýÈ磬һ¸öÑÏÖØµÄ²»ÊÜÐÅÍеÄÊý¾Ý·´ÐòÁл¯Îó²î CVE-2019-18283¿Éµ¼Ö¹¥»÷Õßͨ¹ýÏòÆäÖÐÒ»¸öº¯Êý·¢ËÍÌØÊâ½á¹¹¹¤¾ßµÄÒªÁì»ñȡԶ³Ì´úÂëÖ´ÐÐȨÏÞ¡£
ÁíÍâÁ½¸öÑÏÖØÎó²îCVE-2019-18315 ºÍ CVE-2019-18316 ¿Éµ¼ÖÂÓµÓÐÓ¦ÓóÌÐò·þÎñÆ÷ÍøÂç»á¼ûȨÏ޵Ĺ¥»÷Õß̫ͨ¹ý±ðÏò 8888/TCP ºÍ1099/TCP ¶Ë¿Ú·¢ËÍÌØÊâ½á¹¹Êý¾Ý°üµÄ·½·¨»ñȡԶ³Ì´úÂë»á¼ûȨÏÞ¡£
ÁíÍâÒ»¸öÑÏÖØµÄÈÏÖ¤²»µ±È±ÏÝ CVE-2019-18314 ¿Éµ¼ÖÂÕâÀ๥»÷Õßͨ¹ý Remote Method Invocation (RMI) ·¢ËÍÌØÊâ½á¹¹µÄ¹¤¾ß»ñȡԶ³Ì´úÂëÖ´ÐÐȨÏÞ¡£
MS-3000 »º½â·þÎñÆ÷Öб£´æÆäËü¶à¸öÎó²î¡£ÆäÖÐÁ½¸ö¿Éµ¼ÖÂÔ¶³Ì¶ÁÈ¡ºÍдÈëí§ÒâÎļþ¡£ÀýÈ磬¹¥»÷ÕßÄܹ»¶ÁÈ¡ /etc/shadow£¬´ËºóÕß°üÀ¨¿É±»ÓÃÓÚ±©Á¦ÆÆ½âÓû§ÃÜÂëµÄ¹þÏ£¡£ÁíÍ⻹·¢Ã÷¶à¸ö¶ÑÒç³öÎó²î£¬¿É±»ÓÃÓÚÕë¶Ô»º½â·þÎñÆ÷·¢¶¯¾Ü¾ø·þÎñ¹¥»÷µÈ¡£
ÆäÖÐÒ»¸öÖµµÃ×¢ÖØµÄÎó²îÊÇCVE-2019-18313£¬ËüÊÇÒ»¸öÑÏÖØµÄ²»ÊÜÏÞÉÏ´«Îó²î£¬ÎÞÐèÈÏÖ¤¼´¿É̻¶±¾ÎªÖÎÀíÔ±Éè¼ÆµÄÔ¶³Ì³ÌÐòŲÓà (RPCs)¡£Ëü¿Éµ¼Ö¾ßÓÐ MS-3000 ·þÎñÆ÷×é¼þÍøÂç»á¼ûȨÏ޵Ĺ¥»÷Õßͨ¹ýÏòÆäÖÐÒ»ÖÖ RPC ·þÎñ·¢ËÍÌØÊâ½á¹¹µÄ¹¤¾ß¡£
Î÷ÃÅ×Ó¹«Ë¾ÌåÏÖ£¬Ê¹ÓÃÆäÖÐÈκÎÒ»ÖÖÎó²î¾ùÐè»ñÈ¡¶Ô Application »ò Automation Highway£¨ÅþÁ¬×é¼þµÄÍøÂ磩µÄ»á¼ûȨÏÞ¡£ÈôÊÇÆ¾Ö¤Î÷ÃÅ×ӵIJÙ×÷Ö¸ÄÏÉèÖÃÇéÐεϰ²»»á̻¶ÕâÐ©ÍøÂç¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£
ÐÞ¸´½¨Òé
Î÷ÃÅ×ÓÌåÏÖÕýÔÚÍÆ³ö¸üУ¬Í¬Ê±Ö¸³öµçÁ¦³§Ó¦¸ÃÏÞÖÆ¶ÔʹÓà SPPA-T3000 ·À»ðǽµÄ Application Highway µÄ»á¼ûȨÏÞ£¬Í¬Ê±Ó¦¸ÃûÓÐÔÚ Application »òAutomation highwaysÉÏÇŽÓÍâ²¿ÍøÂç¡£
²Î¿¼Á´½Ó
https://threatpost.com/critical-remote-code-execution-global-power-plants/151087/


¾©¹«Íø°²±¸11010802024551ºÅ