CVE-2020-6994| ºÕ˹ÂüHiOSºÍHiSecOS²úÆ·°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-010x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-6994 |
ʱ ¼ä |
2020-04-01 |
|
Àà ÐÍ |
»º³åÇøÒç³ö |
µÈ ¼¶ |
ÑϳÁ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
HiOS <= 07.0.02 Ó°Ïì²úÆ·£ºRSP£¬RSPE£¬RSPS£¬RSPL£¬MSP£¬EES£¬ EESX£¬GRS£¬OS£¬RED»¥»»»ú£» HiSecOS0 <= 3.2.00 Ó°Ïì²úÆ·£ºEAGLE 20/30·À»ðǽ |
x01 ·ì϶ÏêÇé
µÂ¹úºÕ˹Âü×Ô¶¯»¯ºÍ½ÚÔ칫˾µÞÔìÓÚ1924Ä꣬ҵÎñÉ¢²¼ÔÚ×Ô¶¯»¯Í¨Ñ¶ÁìÓò£¬²úÆ·ÁìÓòÔ̺¬Ñ¡È¡·ÂÕÕºÍÊý×ֹ㲥µçÊÓ´«Êä¼¼ÊõµÄÒÆ¶¯·¢ÉäºÍ½Ó¹Üϵͳ£¬ÆóÒµºÍ¹¤ÒµÍøÂç½â¾ö¹æ»®ÒÔ¼°ÏÖ³¡×ÜÏßϵͳ¡£ºÕ˹ÂüÔÚ2007Äê±»ÃÀ¹ú°Ùͨ£¨Belden£©¹«Ë¾ÊÕ¹º¡£ºÕ˹ÂüHiOSºÍHiSecOS¶¼ÊǰÙÍ¨ÍÆ³öµÄ°²È«²Ù×÷ϵͳ¡£
HiOSºÍHiSecOSµÄHTTP(S)web serverÖдæÔÚÒ»¸ö»º³åÇøÒç¶Âí½Å¡£¸Ã·ì϶ԴÓÚ¶ÔURL²ÎÊýµÄ½âÎö²»µ±ÒýÆðµÄ¡£¹¥»÷ÕßÄܹ»½èÖúÌØÔìµÄHTTPÒªÇóÈëÇÖÖ¸±êÉ豸£¬Ôì³ÉÄÚ²¿»º³åÇøÒç³ö¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѽ¨¸´¸Ã·ì϶£¬½¨ÒéHiOSÓû§¾¡¿ì¸üÐÂÖÁ07.0.03»ò¸ü¸ß°æ±¾£¬HiSecOSÓû§¸üÐÂÖÁ03.3.00»ò¸ü¸ß°æ±¾¡£
һʱ´ëÊ©¿ÉʹÓá°IP½Ó¼ûÏÞ¶È¡±Ö°ÄÜ£¬ÏÞ¶ÈHTTPºÍHTTPS¶Ô¿ÉÐÅIPµØÖ·µÄ½Ó¼û£¬»òÕß½ûÓÃHTTPºÍHTTPS·þÎñÆ÷¡£
https://www.belden.com/hubfs/support/security/bulletins/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf?hsLang=en
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-091-01
0x05 ¹¦·òÏß
2020-02-14 °ä²¼·ì϶
2020-02-26 ÍÆ³ö½â¾ö¹æ»®
2020-03-24 »ñµÃCVE±àºÅ


¾©¹«Íø°²±¸11010802024551ºÅ