Ê©Ä͵¹¤ÒµÈí¼þÑϳÁ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-06-04·ì϶±àºÅ
CVE-2018-7784
CVE-2018-7785
·ì϶¼¶±ð
ÑϳÁ ³§ÉÌ×ÔÆÀ£º10 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÑϳÁ ³§ÉÌ×ÔÆÀ£º10 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£ºU.motion server 1.3.4¼°ÒÔÏ¡£
·ìϼûèÊö
Ê©Ä͵Â2018Äê5ÔÂ31ÈÕ°ä²¼°²È«²¼¸æÍ¨Öª¿Í»§£¬ÆìϲúÆ·U.motion builder´æÔÚÑϳÁµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶ӰÏ죬·ì϶±àºÅΪCVE-2018-7784¡¢CVE-2018-7785£¬Á½Ã¶·ì϶µÄÆÀ·Ö¾ùΪ10·Ö£¨Âú·Ö£©¡£½ØÖÁ´Ë¿Ì£¬Ê©Ä͵¹ٷ½ÒÑÍÆ³ö½¨¸´²¹¶¡¡£
U.motion ÊÇÒ»¿î×Ô¶¯»¯¹¹½¨½â¾ö¹æ»®£¬ÓÃÓÚÈ«ÇòóÒ×ÉèÊ©¡¢¹Ø¼üÔì×÷ÒµºÍÄÜÔ´ÐÐÒµ¡£U.motion Builder ¹¤¾ßÄÜÈÃÓû§Îª×Ô¼ºµÄ U.motion É豸´´½¨ÏîÄ¿¡£
·ì϶ϸ½Ú
1.CVE-2018-7784£º
·¨Ê½¶ÔÌá½»µÄÊý¾Ý¹ýÂ˲»ÑÏ£¬µ¼ÖÂÊäÈëµÄÊý¾Ý±»µ±×÷´úÂëÖ´ÐС£Í¨¹ýÕâ¸ö·ì϶£¬¹¥»÷ÕßÄܹ»ÔÚ´æÔÚ·ì϶µÄ»úеÉÏÔ¶³ÌÖ´ÐÐËÁÒâ´úÂ롢й¶ÐÅÏ¢»òÕßÒý·¢·¨Ê½±¨´í¡£
2.CVE-2018-7785£º
Ô¶³ÌºÅÁî×¢Èë·ì϶£¬¹¥»÷ÕßÄܹ»ÔÚÎÞÐèÈÏÖ¤µÄÇé¿öÏ£¬ÓÚ´æÔÚ·ì϶µÄÖ÷»úÖ´ÐÐËÁÒâÔ¶³ÌºÅÁî¡£
½â¾ö´ëÊ©
½¨ÒéÓйØÓû§¾¡¿ìµ½Ê©Ä͵¹ٷ½ÍøÕ¾ÏÂÔØ²¹¶¡½¨²¹·ì϶¡£
ÏÂÔØµØÖ·£º
https://www.schneider-electric.com/en/download/document/Umotion_Server_update/
²Î¿¼×ÊÁÏ
https://www.schneider-electric.com/en/download/document/Umotion_Server_update/


¾©¹«Íø°²±¸11010802024551ºÅ