ControlByWeb¹¤ÒµÐÎÏóÕ¾½ÚÔìÆ÷·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-01-21

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-18881£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.6£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-18882£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.6£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ControlByWeb ControlByWeb X-320M 1.05°æ±¾¼°ÒÔǰ°æ±¾¡£


·ì϶¸ÅÊö


Xytronix Research&Design ControlByWeb X-320MÊÇÃÀ¹úXytronix Research&Design¹«Ë¾µÄÒ»¿îÖ§³ÖÍøÂçµÄÐÎÏóÕ¾½ÚÔìÆ÷¡£¸Ã²úÆ·Äܹ»½«ÆøÏóÊý¾Ý°ä²¼µ½×¨ÃŵÄÐÎÏó·þÎñ£¬ÈôÊdz¬¹ýÖ¸¶¨µÄ²ÎÊý£¬ËüÄܹ»·¢Ë͵ç×ÓÓʼþºÍ¶ÌÐÅ֪ͨ£¬²¢ÇÒÄܹ»Ô¶³Ì¼¤»î¹«Ë¾Ôì×÷µÄÆäËû²úÆ·µÄ¼ÌµçÆ÷¡£


ControlByWebµÄÒÔÌ«ÍøI / O²úÆ·ÅäÓÐÄÚÖÃWeb·þÎñÆ÷£¬¿Éͨ¹ýWebä¯ÀÀÆ÷½øÐнӼû¡£Æä²úÆ·Äܹ»ÇáËɼ¯³Éµ½¹¤Òµ×Ô¶¯»¯ºÍSCADAϵͳÖУ¬»òÕßÄܹ»×÷Ϊ¶ÀÁ¢É豸ʹÓá£


CVE-2018-18881


Xytronix Research&Design ControlByWeb X-320MÔÚʵÏÖÖдæÔÚÉí·ÝÑéÖ¤°²È«·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶Ôì³É»Ø¾ø·þÎñ¡£


¸ÃÉ豸µÄWeb-Enabled Instrumentation-Grade Data AcquisitionÄ£¿éÊܵ½»Ø¾ø·þÎñ£¨DoS£©·ì϶µÄÓ°Ï죬¸Ã·ì϶¿É±»ÀûÓÃÀ´·ÛËéÉ豸ÉÏͨ¹ýÌØ¶¨ÍøÂçÉèÖýøÐеÄËùÓÐͨѶ¡£¾ßÌåÀ´Ëµ£¬¹¥»÷ÕßÄܹ»½«setup.htmlÒ³ÃæÖеġ°IP¹ýÂËÆ÷ÁìÓò1¡±Ñ¡Ïî´Ó255.255.255.255ÉèÖÃΪ0.0.0.0£¬Õâ»áµ¼Ö³ÖÐøµÄDoSǰÌá×èÖ¹½Ó¼ûÉ豸³ý·ÇÖ´Ðи´Ô­³ö³§ÉèÖá£


CVE-2018-18882


Xytronix Research&Design ControlByWeb X-320MÖдæÔÚ¿çÕ¾¾ç±¾·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·µØÑéÖ¤ÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐдúÂë¡£


Ëü»áÓ°ÏìͳһHTMLÒ³ÃæÉϵġ°Õ¾µãÃèÊö¡±ÊäÈë×ֶΡ£¹¥»÷Õß¿ÉÄܻὫ¶ñÒâ¾ç±¾×¢Èë´Ë×ֶΣ¬²¢ÔںϷ¨Óû§½Ó¼ûÉ豸µÄ״̬ҳʱִÐС£


½¨¸´½¨Ò飺


ControlByWeb°ä²¼ÁË1.06°æÕý±¾½¨²¹·ì϶£ºhttps://www.controlbyweb.com/firmware/X320M_V1.06_firmware.zip¡£


²Î¿¼Á´½Ó£º


https://ics-cert.us-cert.gov/advisories/ICSA-19-017-03

https://www.controlbyweb.com/firmware/X320M_V1.06_firmware.zip

https://www.securityweek.com/serious-flaws-found-controlbyweb-industrial-weather-station