EZAutomation¶à¸ö»º³åÇøÃýÎó·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-06¡ñ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-13522£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.8
CVE±àºÅ£ºCVE-2019-13518£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.8
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
CVE-2019-13522
EZ PLC Editor Versions 1.8.41 and prior
CVE-2019-13518
EZ Touch Editor Versions 2.1.0 and prior
¡ñ·ì϶¸ÅÊö
EZAutomationÊÇAVGÆìϵÄÒ»¸öϵÁС£AVGÊÇÒ»¼Ò×ö¹¤Òµ´¥ÃþÆÁºÍ¿É±à³Ì½ÚÔìÆ÷µÄÃÀ¹úµçÆø¹«Ë¾¡£EZAutomationϵÁÐÏÂÓÐPLC²úÆ·£¬´¥ÃþÆÁ£¬±àÂëÆ÷£¬ÅÜÂíµÆ£¬²Ù×÷½çÃæ¸÷Àà¸ßÐÔ¼Û²úÆ·¡£½üÈÕEZAutomation°ä²¼Á½¸ö»º³åÇøÃýÎó·ì϶ÈçÏ£º
CVE-2019-13522
EZAutomation EZ PLC EditorÊÇÃÀ¹úEZAutomation¹«Ë¾µÄÒ»Ì×PLC£¨¿É±à³ÌÂß¼½ÚÔìÆ÷£©±à³ÌÈí¼þ¡£EZAutomation EZ PLC Editor 1.8.41¼°Ö®Ç°°æ±¾ÖдæÔÚ»º³åÇøÃýÎó·ì϶¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÏîÄ¿ÎļþÀûÓø÷ì϶°Ü»µÄÚ´æ²¢ÒÔ¸ÃÀûÓ÷¨Ê½È¨ÏÞÖ´ÐдúÂë¡£
CVE-2019-13518
EZAutomation EZ Touch EditorÊÇÃÀ¹úEZAutomation¹«Ë¾µÄÒ»Ì×HMI£¨ÈË»ú½çÃæ£©±à³ÌÈí¼þ¡£EZAutomation EZ Touch Editor 2.1.0¼°Ö®Ç°°æ±¾ÖдæÔÚ»º³åÇøÃýÎó·ì϶¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÏîÄ¿ÎļþÀûÓø÷ì϶ÒÔ¸ÃÀûÓ÷¨Ê½µÄȨÏÞÖ´ÐдúÂë¡£
¡ñ·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
¡ñ½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏÂÔØÁ´½Ó£ºhttps://www.ezautomation.net/access.php¡£
¡ñ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-19-246-01
https://www.us-cert.gov/ics/advisories/icsa-19-246-02


¾©¹«Íø°²±¸11010802024551ºÅ