Î÷ÃÅ×ÓS7-1200 PLC²úÆ·°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2019-12-05·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-13945£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.8 £¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
S7-1200ËùÓа汾
·ì϶¸ÅÊö
Siemens S7-1200 CPUÖдæÔÚ°²È«·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼ûÆäËûÕï¶ÏÖ°ÄÜ£¬Ó°ÏìϵͳµÄÆëÈ«ÐÔ¡¢¿ÉÓÃÐԺͱ£ÃÜÐÔ¡£
Î÷ÃÅ×Ó×î½ü°ä²¼ÁËÒ»·Ý°²È«²¼¸æ£¬ÆäÖÐÔ̺¬Õë¶Ô×êÑÐÈËÔ±ÔÚÆäS7-1200¿É±à³ÌÂß¼½ÚÔìÆ÷£¨PLC£©Öз¢Ïֵķì϶µÄ±äͨ·¨×Ó»ººÍ½â´ëÊ©£¬¸Ã·ì϶¿ÉÓÃÓÚÈÆ¹ý¹Ì¼þÆëÈ«ÐÔ²é³ÒÔ¼ÓÔØ¶ñÒâÈí¼þ»ò½Ù³ÖÉ豸µÄ¹¤ÒµÁ÷³Ì¡£Î÷ÃÅ×Ó°µÊ¾£º¡°ÎÒÃÇÔÚÉó²éGA»Æ½ð¼×²úÆ·Ä£ÐÍ£¬²¢½«ÔÚSSA-686531Éϰ䲼¸üУ¬ÒÔ·ÀÆäËûÄ£ÐÍÊܵ½Ó°Ïì¡£×êÑÐÈËÔ±»¹·¢ÏÖ£¬¿É±à³ÌÂß¼½ÚÔìÆ÷£¨PLC£©ÖеÄÌØÊâ½Ó¼ûÖ°ÄÜÒ²Äܹ»ºÜºÃµØÓÃ×÷£º×÷Ϊ·ÀÓùÕßµÄȡ֤¹¤¾ß¡£ËûÃÇÀûÓøÃÖ°Äܲ鿴PLC´æ´¢Æ÷µÄÄÚÈÝ£¬Òò¶ø¹¤³§²Ù×÷Ô±Ò²Äܹ»Ê¹ÓÃËüÀ´²éÕÒÉ豸ÉϵĶñÒâ´úÂë¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://www.siemens.com£»
S7-122 CPUµÄÓû§Äܹ»Ñ¡È¡ÕâЩ±äͨ·¨×Ó»ººÍ½â´ëÊ©À´½µµÍ·çÏÕ£º
1.È·±£ÎïÀí½Ó¼û±£»¤£»
2.ÀûÓÃÉî¶È·ÀÓù¡£
²Î¿¼Á´½Ó
https://www.darkreading.com/vulnerabilities---threats/siemens-offers-workarounds-for-newly-found-plc-vulnerability/d/d-id/1336503


¾©¹«Íø°²±¸11010802024551ºÅ