ºáºÓµç»úSTARDOM½ÚÔìÆ÷ÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-05

·ì϶±àºÅ

 

CVE-2018-10592


·ì϶¼¶±ð


ÑϳÁ  ICS-CERTÆÀ·Ö£º9.8   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


¸Ã·ì϶ӰÏìÈÕ±¾ºáºÓµç»úµÄSTARDOM¶à¿î½ÚÔìÆ÷£¬¹Ù·½°ä²¼µÄÊÜÓ°Ïì½ÚÔìÆ÷ÓÐFCJ (R4.02 and prior)¡¢FCN-100 (R4.02 and prior)¡¢FCN-RTU (R4.02 and prior)¡¢FCN-500 (R4.02 and prior)¡£ÓÉÓÚSTARDOM½ÚÔìÆ÷ÀûÓü«¶È¿í·º£¬Éæ¼°ÄÜÔ´¡¢¹Ø¼üÔì×÷¡¢Ê³Æ·ºÍũҵµÈÐÐÒµ£¬¿ÉÔì³ÉÑϳÁ·çÏÕ£¬ÓйØÓû§¼°³§ÉÌÓ¦ÒýÆð¸ß¶ÈÆ÷³Á¡£


·ìϼûèÊö


2018Äê5ÔÂ21ÈÕ£¬ÈÕ±¾ºáºÓµç»ú°ä²¼5Ô·ݰ²È«²¼¸æ£¬²¼¸æÖн¨¸´ÁËÒ»¸ö¸ßΣ·ì϶¡£¹¥»÷ÕßÀûÓø÷ì϶Äܹ»¶ÔSTARDOM½ÚÔìÆ÷ÌáÒéÔ¶³Ì¹¥»÷£¬²¢Ö´ÐÐËÁÒâ´úÂ룬»ñÈ¡½ÚÔìÆ÷ËùÓÐȨÏÞ¡£


2018Äê5ÔÂ31ÈÕ£¬ICS-CERTÕýʽ°ä²¼¸Ã·ì϶°²È«²¼¸æ£¬²¢ÎªÆäÊÚÓè±àºÅCVE-2018-10592£¬È϶¨·ì϶µÈ¼¶ÎªÑϳÁ£¬CVSS V3ÆÀ·Ö9.8¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


 

CVE-2018-10592·ì϶ÊǶ«·½µçÆø-GA»Æ½ð¼×¹¤¿ØÐÅÏ¢°²È«½áºÏ³¢ÊÔÊÒ£¨VDLab£©ÔÚ2017Äê8Ô·¢ÏÖ²¢Éϱ¨¹ú¶ÈÓйØÖ÷¹Ü»ú¹¹¡¢CVEºÍÓÐ¹ØÆóÒµ¡£ÈÕ±¾ºáºÓµç»úÈ·Èϸ÷ì϶ºó£¬Ñ¸¿ì·¢Õ¹½¨¸´¹¤×÷£¬²¢ÊµÊ±ÏòVDLabÌṩÁ˽¨²¹´ëÊ©¡£VDLabÔÚ»ñµÃ²¹¶¡ºóµÄµÚÒ»¹¦·ò£¬Ð­Í¬ÓÐ¹ØÆóÒµ½øÐÐÁËÄÚ²¿²âÊÔ£¬²¢¶ÔÓйؽÚÔìϵͳ½øÐÐÁËÏÖ³¡Éý¼¶£¬ÒÔ±£ÏÕµçÁ¦»ù´¡ÉèÊ©ÍøÂ簲ȫ¡£
ʱ¸ô°ëÄê¶à£¬³§É̽«¸Ã·ì϶½øÐй«¿ª£¬ÔÚ´ËÌáÐÑʹÓøÃϵÁнÚÔìÆ÷µÄÓû§£¬ÉÐδʵÏÖ½¨²¹¹¤×÷µÄ£¬Ð辡¿ì¶Ôϵͳ½øÐÐÉý¼¶¡£


½â¾ö´ëÊ©


ºáºÓµç»ú¹Ù·½ÒÑÓÚ5ÔÂ21ÈÕ¶Ô±íÕýʽ°ä²¼Õë¶Ô¸Ã·ì϶µÄ²¹¶¡£¬¿É¸üйٷ½×îеIJ¹¶¡¡£Óû§Ò²¿É×·ÇóºáºÓµç»úµÄ¼¼ÊõÖ§³ÖÈËÔ±¶ÔÉ豸½øÐÐÉý¼¶¸üС£


²Î¿¼×ÊÁÏ


https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03


https://mp.weixin.qq.com/s/Wxr8Mk6WxTVBe6iHMgjN5w