Emerson OpenEnterprise SCADA | ¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-290x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
Emerson OpenEnterprise SCADA |
CVE-2020-6970 |
BO |
ÑϳÁ |
ÊÇ |
Emerson OpenEnterprise SCADA Server 3.1-3.3.3,2.83°æ±¾ |
|
CVE-2020-10640 |
MA |
ÑϳÁ |
ÊÇ |
Emerson OpenEnterprise SCADA <= 3.3.4 |
|
|
CVE-2020-10632 |
IOM |
¸ßΣ |
·ñ |
||
|
CVE-2020-10636 |
IES |
ÖÐΣ |
·ñ |
0x01 ·ì϶ÏêÇé
Emerson Electric OpenEnterpriseÊÇÃÀ¹ú°¬Ä¬ÉúµçÆø£¨Emerson Electric£©¹«Ë¾µÄÒ»Ì×ÖØÒªÓÃÓÚÔ¶³ÌʯÓͺÍÌìÈ»ÆøÀûÓõÄÊý¾Ý²É¼¯Óë¼à¿ØÏµÍ³£¨SCADA£©¡£
½üÈÕ£¬¿¨°Í˹»ùµÄ×êÑÐÈËÔ±Roman Lozko·¢ÏÖÁËEmerson OpenEnterpriseÖеÄËĸö°²È«·ì϶£¬ÕâËĸö·ì϶±ðÀëΪ»ùÓڶѵĻº³åÇøÒç³ö¡¢¶ÌȱÉí·ÝÑéÖ¤¡¢ËùÓÐȨÖÎÀí²»µ±ºÍÈõ¼ÓÃÜÎÊÌ⣬¾ßÌåÐÅÏ¢ÈçÏ£º
CVE-2020-6970ÊÇEmerson Electric OpenEnterprise SCADA ServerÖдæÔڵĻº³åÇøÒç¶Âí½Å£¬CVE-2020-10640ÊÇEmerson Electric OpenEnterpriseÖдæÔڵݲȫ·ì϶¡£ÒÔÉÏÁ½¸ö·ì϶¶¼±»ÆÀ¼¶Îª¡°ÑϳÁ¡±£¬Äܹ»Ê¹¹¥»÷ÕßÔÚÔËÐÐOpenEnterpriseµÄÉ豸ÉÏÒÔÌáÉýµÄÌØÈ¨Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£
CVE-2020-10632ÊÇEmerson Electric OpenEnterpriseÖдæÔڵݲȫ·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½ÎªÎļþ¼ÐÉèÖÃÁ˲»°²È«µÄȨÏÞ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶Åú¸Ä³ÁÒªµÄÅäÖÃÎļþ£¬Ôì³Éϵͳ¹ÊÕÏ»òÒì³£¡£
CVE-2020-10636ÊÇEmerson Electric OpenEnterpriseÖдæÔڵļÓÃÜÎÊÌâ·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡OpenEnterpriseÓû§ÕÊ»§µÄÃÜÂë¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º
https://www.emerson.com/
0x03 ÓйØÐÂÎÅ
https://www.securityweek.com/vulnerabilities-found-emerson-scada-product-made-oil-and-gas-industry
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-049-02
https://www.us-cert.gov/ics/advisories/icsa-20-140-02
0x05 ¹¦·òÏß
2020-05-29 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ