CVE-2020-6994| ºÕ˹ÂüHiOSºÍHiSecOS²úÆ·°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-01

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-6994

ʱ    ¼ä

2020-04-01

Àà    ÐÍ

»º³åÇøÒç³ö

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

HiOS <= 07.0.02 Ó°Ïì²úÆ·£ºRSP £¬RSPE £¬RSPS £¬RSPL £¬MSP £¬EES £¬ EESX £¬GRS £¬OS £¬RED»¥»»»ú £»

HiSecOS0 <= 3.2.00 Ó°Ïì²úÆ·£ºEAGLE 20/30·À»ðǽ

x01 ·ì϶ÏêÇé


µÂ¹úºÕ˹Âü×Ô¶¯»¯ºÍ½ÚÔ칫˾µÞÔìÓÚ1924Äê £¬ÒµÎñÉ¢²¼ÔÚ×Ô¶¯»¯Í¨Ñ¶ÁìÓò £¬²úÆ·ÁìÓòÔ̺¬Ñ¡È¡·ÂÕÕºÍÊý×ֹ㲥µçÊÓ´«Êä¼¼ÊõµÄÒÆ¶¯·¢ÉäºÍ½Ó¹Üϵͳ £¬ÆóÒµºÍ¹¤ÒµÍøÂç½â¾ö¹æ»®ÒÔ¼°ÏÖ³¡×ÜÏßϵͳ¡£ºÕ˹ÂüÔÚ2007Äê±»ÃÀ¹ú°Ùͨ£¨Belden£©¹«Ë¾ÊÕ¹º¡£ºÕ˹ÂüHiOSºÍHiSecOS¶¼ÊǰÙÍ¨ÍÆ³öµÄ°²È«²Ù×÷ϵͳ¡£


HiOSºÍHiSecOSµÄHTTP(S)web serverÖдæÔÚÒ»¸ö»º³åÇøÒç¶Âí½Å¡£¸Ã·ì϶ԴÓÚ¶ÔURL²ÎÊýµÄ½âÎö²»µ±ÒýÆðµÄ¡£¹¥»÷ÕßÄܹ»½èÖúÌØÔìµÄHTTPÒªÇóÈëÇÖÖ¸±êÉ豸 £¬Ôì³ÉÄÚ²¿»º³åÇøÒç³ö¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѽ¨¸´¸Ã·ì϶ £¬½¨ÒéHiOSÓû§¾¡¿ì¸üÐÂÖÁ07.0.03»ò¸ü¸ß°æ±¾ £¬HiSecOSÓû§¸üÐÂÖÁ03.3.00»ò¸ü¸ß°æ±¾¡£

һʱ´ëÊ©¿ÉʹÓá°IP½Ó¼ûÏÞ¶È¡±Ö°ÄÜ £¬ÏÞ¶ÈHTTPºÍHTTPS¶Ô¿ÉÐÅIPµØÖ·µÄ½Ó¼û £¬»òÕß½ûÓÃHTTPºÍHTTPS·þÎñÆ÷¡£


https://www.belden.com/hubfs/support/security/bulletins/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf?hsLang=en


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-091-01


0x05 ¹¦·òÏß


2020-02-14 °ä²¼·ì϶

2020-02-26 ÍÆ³ö½â¾ö¹æ»®

2020-03-24 »ñµÃCVE±àºÅ