Î÷ÃÅ×Ó¶à¿î²úÆ·°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-16

? ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10942£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-6568£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.5


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


CVE-2019-10942

SCALANCE X-200: All versions
SCALANCE X-200IRT: All versions
SCALANCE X-200RNA: All versions


CVE-2019-6568

SINAMICS GH150 V4.7 (Control Unit):All versions

SINAMICS GH150 V4.8 (Control Unit):All versions < V4.8 SP2 HF6
SINAMICS GL150 V4.7 (Control Unit):All versions
SINAMICS GL150 V4.8 (Control Unit):All versions < V4.8 SP2 HF7
SINAMICS GM150 V4.7 (Control Unit):All versions
SINAMICS GM150 V4.8 (Control Unit):All versions < V4.8 SP2 HF9
SINAMICS SL150 V4.7 (Control Unit):All versions
SINAMICS SL150 V4.8 (Control Unit):All versions
SINAMICS SM120 V4.7 (Control Unit):All versions
SINAMICS SM120 V4.8 (Control Unit):All versions
SINAMICS SM150 V4.8 (Control Unit):All versions


·ì϶¸ÅÊö


Î÷ÃÅ×Ó°ä²¼Á˸ßÑϳÁÐÔ²úÆ··ì϶Ԥ¾¯£¬Ô̺¬Ó°ÏìSCALANCE X¹¤Òµ»¥»»»úµÄ»Ø¾ø·þÎñ£¨DoS£©·ì϶CVE-2019-10942ºÍÓ°ÏìSINAMICSת»»Æ÷Web·þÎñÆ÷µÄ»Ø¾ø·þÎñ£¨DoS£©·ì϶CVE-2019-6568 ¡£·ì϶ÐÅÏ¢ÈçÏ£º


CVE-2019-10942

¸Ã·ì϶ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·´¸´ÏòTelnet·þÎñ·¢ËÍ´óÁ¿ÐÂÎŰü£¬µ¼ÖÂÉ豸½øÈëDoS״̬ ¡£×êÑÐÈËÔ±°µÊ¾¹¥»÷Õßͨ¹ýÏòTCP 23¶Ë¿Ú·¢ËÍ´óÁ¿Êý¾Ý°üÀ´·ÛËételnet·þÎñ£¬É豸±ÀÀ£ºó»á×Ô¶¯³ÁÆô£¬Õâ¿ÉÄܵ¼ÖÂDZÔÚµÄÁ÷³ÌÖжÏ ¡£¹¥»÷ÕßÀûÓø÷ì϶±ØÒª½Ó¼ûÖ¸±ê»¥»»»úµÄÍøÂ磬²¢ÇÒÖ»±ØÒªÏàʶһЩ³ß¶ÈµÄtelnetºÍ̸ ¡£×êÑÐÈËÔ±ÒѾ­È·¶¨ÁËһЩ¿ÉÄÜÖ±½ÓÊܵ½À´×Ô»¥ÁªÍø¹¥»÷µÄÉ豸£¬µ«¸Ã·ì϶²¢²»ÈÝÒ×ÀûÓã¬ÓÉÓÚËü¿ÉÄÜÓÐÒ»¸ö·ÇÈ·¶¨ÐԵĸ´Ôì²½Öè±»´¥·¢ ¡£


CVE-2019-6568

¸Ã·ì϶ÔÊÐíÓµÓжÔÊÜÓ°ÏìϵͳµÄÍøÂç½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÔÚ²»±ØÒªÉí·ÝÑéÖ¤»òÓû§½»»¥µÄÇé¿öϵ¼Ö»ؾø·þÎñ£¬µ¼Ö³ÁÐÂÆô¶¯Web·þÎñÆ÷ ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP ¡£


½¨¸´½¨Òé


CVE-2019-10942

ĿǰÎ÷ÃÅ×ÓÉÐδÕë¶Ô¸Ã·ì϶°ä²¼Èκβ¹¶¡·¨Ê½£¬ÓйØÓû§¿Éͨ¹ýÔÚÊÜÓ°ÏìµÄÉ豸ÉϽûÓÃTelnet·þÎñ£¨½¨ÒéʹÓÃSSH£©ÒÔ¼°Ï޶ȶÔTCP¶Ë¿Ú23µÄÍøÂç½Ó¼û£¬À´Ô¤·ÀDZÔÚ¹¥»÷ ¡£


CVE-2019-6568

Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬¼û²Î¿¼Á´½Ó ¡£


²Î¿¼Á´½Ó


https://cert-portal.siemens.com/productcert/pdf/ssa-100232.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-530931.pdf