Î÷ÃÅ×ÓS7-1200 PLC²úÆ·°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2019-12-05

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13945£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.8 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


S7-1200ËùÓа汾


·ì϶¸ÅÊö


Siemens S7-1200 CPUÖдæÔÚ°²È«·ì϶ ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼ûÆäËûÕï¶ÏÖ°ÄÜ£¬Ó°ÏìϵͳµÄÆëÈ«ÐÔ¡¢¿ÉÓÃÐԺͱ£ÃÜÐÔ ¡£


Î÷ÃÅ×Ó×î½ü°ä²¼ÁËÒ»·Ý°²È«²¼¸æ£¬ÆäÖÐÔ̺¬Õë¶Ô×êÑÐÈËÔ±ÔÚÆäS7-1200¿É±à³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©Öз¢Ïֵķì϶µÄ±äͨ·¨×Ó»ººÍ½â´ëÊ©£¬¸Ã·ì϶¿ÉÓÃÓÚÈÆ¹ý¹Ì¼þÆëÈ«ÐԲ鳭ÒÔ¼ÓÔØ¶ñÒâÈí¼þ»ò½Ù³ÖÉ豸µÄ¹¤ÒµÁ÷³Ì ¡£Î÷ÃÅ×Ó°µÊ¾£º¡°ÎÒÃÇÔÚÉó²éGA»Æ½ð¼×²úÆ·Ä£ÐÍ£¬²¢½«ÔÚSSA-686531Éϰ䲼¸üУ¬ÒÔ·ÀÆäËûÄ£ÐÍÊܵ½Ó°Ïì ¡£×êÑÐÈËÔ±»¹·¢ÏÖ£¬¿É±à³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©ÖеÄÌØÊâ½Ó¼ûÖ°ÄÜÒ²Äܹ»ºÜºÃµØÓÃ×÷£º×÷Ϊ·ÀÓùÕßµÄȡ֤¹¤¾ß ¡£ËûÃÇÀûÓøÃÖ°Äܲ鿴PLC´æ´¢Æ÷µÄÄÚÈÝ£¬Òò¶ø¹¤³§²Ù×÷Ô±Ò²Äܹ»Ê¹ÓÃËüÀ´²éÕÒÉ豸ÉϵĶñÒâ´úÂë ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP ¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://www.siemens.com£»


S7-122 CPUµÄÓû§Äܹ»Ñ¡È¡ÕâЩ±äͨ·¨×Ó»ººÍ½â´ëÊ©À´½µµÍ·çÏÕ£º


1.È·±£ÎïÀí½Ó¼û±£»¤£»

2.ÀûÓÃÉî¶È·ÀÓù ¡£


²Î¿¼Á´½Ó


https://www.darkreading.com/vulnerabilities---threats/siemens-offers-workarounds-for-newly-found-plc-vulnerability/d/d-id/1336503