VxWorks¶à¸ö°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-30

¡ô ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12256£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12257£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12255£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12260£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12261£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12263£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12258£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12259£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.3£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12262£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12264£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-12265£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.4£¬¹Ù·½Î´ÆÀ¶¨


¡ô Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¡ô ·ì϶¸ÅÊö


VxWorksÊÇÊÀ½çÉÏʹÓÃ×î¿í·ºµÄÒ»ÖÖÔÚǶÈëʽϵͳÖв¿ÊðµÄʵʱ²Ù×÷ϵͳ£¬ÊÇÓÉÃÀ¹úWindRiver¹«Ë¾£¨¼ò³Æ·çºÓ¹«Ë¾£¬¼´WRS ¹«Ë¾£©ÓÚ1983ÄêÉè¼Æ¿ª·¢µÄ£¬VxWorks±»³¬¹ý20ÒŲ́É豸ʹÓã¬Ô̺¬¹Ø¼ü»ù´¡ÉèÊ©£¬ÍøÂçÉ豸£¬Ò½ÁÆÉ豸£¬¹¤ÒµÏµÍ³ÉõÖÁº½ÌìÆ÷ ¡£Äܹ»Ëµ´ÓPLCµ½MRI»úе£¬µ½·À»ðǽºÍ´òÓ¡»ú£¬ÔÙµ½·É»ú£¬»ð³µµÈµÈ¶¼ÓÐ¿í·ºÀûÓà ¡£


½üÈÕ£¬VxWorks¹Ù·½°ä²¼Á˰²È«·ì϶²¼¸æ³Æ½¨¸´ÁËÓÉArmis×êÑÐÍŶӷ¢ÏÖ²¢»ã±¨µÄ11¸ö°²È«·ì϶£¬ÆäÖÐÓÐ6¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶£¬CVE-2019-12256¡¢CVE-2019-12255¡¢CVE-2019-12260 CVSSÆÀ·ÖΪ9.8·Ö ¡£ÆäÓà5¸ö·ì϶¿ÉÄܵ¼Ö»ؾø·þÎñ£¬ÐÅϢй©»ò¹éÀàΪÂß¼­È±µã ¡£ÕâЩ·ì϶´æÔÚÓÚVxWorksµÄTCP/IP²Ö¿â£¨IPnet£©ÖУ¬Ó°ÏìVxWorks 7 (SR540 and SR610)¡¢VxWorks 6.5-6.9¼°Ê¹ÓÃInterpeak¶ÀÁ¢ÍøÂç²Ö¿âµÄVxWorks°æ±¾ ¡£¹¥»÷ÕßÄܹ»ÀûÓÃÆäÖзì϶ʵÏÖÎÞÐèÓû§½»»¥¼°ÈÏ֤ʵÏÖÔ¶³Ì¹¥»÷£¬×îÖÕÔÚÆëÈ«½ÚÔìÓйØÉ豸 ¡£


ÔÚÈ«Çò£¬Ê¹ÓÃVxWorksµÄÊýÁ¿ÓÐ126460¸ö£¬ÆäÖÐÖйúÓÐ25046¸ö£¬É¢²¼ÈçÏ£º

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¡ô ·ì϶ÑéÖ¤


ĿǰArmis×êÑÐÍŶӰ䲼Á˳ɹ¦ÀûÓ÷ì϶½ÚÔìÁËSonicWall·À»ðǽ¡¢Xerox´òÓ¡»ú¡¢²¡È˼໤ÒǵÄÑÝʾÊÓÆµ£¬µ«ÊÇûÓа䲼·ì϶ÓйØÏ¸½Ú»ò·ì϶ÑéÖ¤·¨Ê½ ¡£


¡ô ½¨¸´½¨Òé


SonicWall¼°Xerox¹Ù·½¾ùÒѾ­°ä²¼Óйطì϶¸üР¡£
SonicWall£ºhttps://blog.sonicwall.com/en-us/2019/07/wind-river-vxworks-and-urgent-11-patch-now/
Xerox£ºhttps://security.business.xerox.com/en-us/


¡ô ²Î¿¼Á´½Ó


https://armis.com/urgent11/ 
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/