Fuji Electric¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-01-29

0x00 ·ì϶¸ÅÊö

2021Äê01ÔÂ26ÈÕ £¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©°ä²¼°²È«²¼¸æ £¬Åû¶Á˹¤Òµ×éÖ¯ÈÕ±¾µçÆøÉ豸¹«Ë¾Fuji Electric³ö²úµÄ²¿ÃÅSCADA / HMI²úÆ·TellusºÍV-ServerÖеĶà¸ö°²È«·ì϶¡£

 

0x01 ·ì϶ÏêÇé

image.png

TellusºÍV-Server ²úÆ·¿ÉÔ¶³Ì¼à¿ØºÍ½ÚÔ칤³§µÄÉ豸 £¬ËüÃÇÔڹؼüµÄÔì×÷ÒµÖб»¿í·ºÑ¡È¡¡£

ÕâЩ·ì϶ÊǶÔÓû§ÌṩµÄÊý¾Ý²»×ãÕýÈ·ÑéÖ¤µ¼Ö嵀 £¬¿ÉÄÜ´¥·¢»º³åÇøÒç³ö²¢Òò¶øµ¼ÖÂËÁÒâ´úÂëÖ´ÐС£ÀûÓÃÕâЩ·ì϶±ØÒªÓû§½»»¥ £¬¹¥»÷ÕßÄܹ»Í¨¹ýÓÕÆ­Ö¸±êÓû§´ò¿ª¶ñÒâÏîÄ¿ÎļþÀ´´¥·¢·ì϶ £¬×îÖÕÖ´ÐÐËÁÒâ´úÂë¡£

±¾´ÎÅû¶µÄ·ì϶ÈçÏ£º

CVE

ÀàÐÍ

CVSSÆÀ·Ö

ÑϳÁˮƽ

CVE-2021-22637

»ùÓڶѵĻº³åÇøÒç³ö

7.8

¸ßΣ

CVE-2021-22655

Ô½½ç¶ÁÈ¡

7.8

¸ßΣ

CVE-2021-22653

Ô½½çдÈë

7.8

¸ßΣ

CVE-2021-22639

´úÂëÖ´ÐÐ

7.8

¸ßΣ

CVE-2021-22641

»ùÓڶѵĻº³åÇøÒç³ö

7.8

¸ßΣ

 

 

Fuji Electric»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¨CVE-2021-22637£©

ÔÚÀûÓ÷¨Ê½´¦ÖÃÏîÄ¿ÎļþµÄ·½Ê½ÖдæÔÚÒ»¸ö»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å £¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»Ôì×÷Ö´ÐÐËÁÒâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ £¬ÆäCVSSÆÀ·Ö7.8¡£

 

Fuji ElectricÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2021-22655£©

ÔÚÀûÓ÷¨Ê½´¦ÖÃÏîÄ¿ÎļþµÄ·½Ê½ÖдæÔÚÒ»¸öÔ½½ç¶ÁÈ¡·ì϶ £¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»Ôì×÷Ö´ÐÐËÁÒâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ £¬ÆäCVSSÆÀ·Ö7.8¡£

 

Fuji ElectricÔ½½çдÈë·ì϶£¨CVE-2021-22653£©

¸Ã·ì϶´æÔÚÓÚÀûÓ÷¨Ê½´¦ÖÃÏîÄ¿ÎļþµÄ·½Ê½ÖÐ £¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ôì×÷¶ñÒâµÄÏîÄ¿Îļþ £¬×îÖÕÖ´ÐÐËÁÒâ´úÂë £¬ÆäCVSSÆÀ·Ö7.8¡£

 

Fuji Electric´úÂëÖ´Ðзì϶£¨CVE-2021-22639£©

ÔÚÀûÓ÷¨Ê½´¦ÖÃÏîÄ¿ÎļþµÄ·½Ê½ÖдæÔÚδ³õʼ»¯µÄÖ¸ÕëÎÊÌâ £¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»Ôì×÷Ö´ÐÐËÁÒâ´úÂëµÄ¶ñÒâÏîÄ¿Îļþ £¬ÆäCVSSÆÀ·Ö7.8¡£

 

Fuji Electric»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¨CVE-2021-22641£©

ÔÚÀûÓ÷¨Ê½´¦ÖÃÏîÄ¿ÎļþµÄ·½Ê½Öз¢ÏÖÁË»ùÓڶѵĻº³åÇøÒç¶Âí½Å £¬¹¥»÷ÕßÄܹ»Í¨¹ýÔì×÷¶ñÒâµÄÏîÄ¿ÎļþÀ´Ö´ÐÐËÁÒâ´úÂë £¬ÆäCVSSÆÀ·Ö7.8¡£

 

Ó°ÏìÁìÓò

Tellus Lite V-Simulator£ºv4.0.10.0֮ǰµÄ°æ±¾

V-Server Lite£ºv4.0.10.0֮ǰµÄ°æ±¾


0x02 ´ëÖý¨Òé

½¨ÒéÉý¼¶ÖÁv4.0.10.0°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://felib.fujielectric.co.jp/download/details.htm?dataid=43821668&site=global&lang=en

 

 

0x03 ²Î¿¼Á´½Ó

https://securityaffairs.co/wordpress/113950/ics-scada/fuji-electric-hmi-flaws.html?utm_source=rss&utm_medium=rss&utm_campaign=fuji-electric-hmi-flaws

https://us-cert.cisa.gov/ics/advisories/icsa-21-026-01

https://felib.fujielectric.co.jp/download/details.htm?dataid=43821669&site=global&lang=en

 

0x04 ¹¦·òÏß

2021-01-26  CISA°ä²¼°²È«²¼¸æ

2021-01-29  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png