ÈýÁâ±äƵÆ÷Mitsubishi FR Configurator2Èí¼þ¶à¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-25

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºÔÝÎÞ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.5 £¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºÔÝÎÞ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.2 £¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Mitsubishi FR Configurator2 version 1.16S and 1.10L¼°Ö®Ç°°æ±¾


Îó²î¸ÅÊö


Mitsubishi FR Configurator2ÊÇÈÕ±¾ÈýÁâµç»ú£¨Mitsubishi Electric£©¹«Ë¾µÄÒ»¿î±äƵÆ÷Çý¶¯ÉèÖÃÓ¦ÓóÌÐò¡£¡£¡£¡£¡£


Mitsubishi FR Configurator2±£´æÈçÏÂÈý¸öÎó²î£º


XMLÍⲿʵÌ壨XXE£©×¢ÈëÎó²î


¸ÃÓ¦ÓóÌÐòʹÓÃDTD²ÎÊýʵÌåÊÖÒÕÔâÊÜXMLÍⲿʵÌ壨XXE£©Îó²îµÄÓ°Ïì £¬£¬£¬£¬£¬¸ÃÊÖÒÕÔÊÐíͨ¹ý´øÍ⣨OOB£©¹¥»÷ÔÚÊÜÓ°ÏìµÄ½ÚµãÉϹûÕæºÍ¼ìË÷í§ÒâÊý¾Ý¡£¡£¡£¡£¡£µ±ÊäÈëת´ï¸øÆÊÎöXMLÏîÄ¿ºÍ/»òÄ£°åÎļþ£¨.frc2£©Ê± £¬£¬£¬£¬£¬²»»áÕûÀíXMLÆÊÎöÆ÷¡£¡£¡£¡£¡£´Ë¹¥»÷»¹¿ÉÓÃÓÚÖ´ÐÐí§Òâ´úÂ루ÔÚijЩÇéÐÎÏ £¬£¬£¬£¬£¬Ïêϸȡ¾öÓÚÆ½Ì¨£©¡£¡£¡£¡£¡£


¾Ü¾øÐ§ÀÍÎó²î


¸ÃÓ¦ÓóÌÐòÔâÊܾܾøÐ§ÀÍ£¨DoS£©Îó²î £¬£¬£¬£¬£¬µ¼ÖÂAppHangB1ÊÂÎñÐèÒªÖØÐÂÆô¶¯Ó¦ÓóÌÐò¡£¡£¡£¡£¡£ µ±¹¥»÷ÕßÏòÊܺ¦ÕßÌṩ¶ñÒâÏîÄ¿Îļþ£¨.frc2£©Ê± £¬£¬£¬£¬£¬¿ÉÒÔ´¥·¢Îó²î¡£¡£¡£¡£¡£Ò»µ©Êܺ¦Õß·­¿ª¶ñÒâÏîÄ¿ £¬£¬£¬£¬£¬¾Í»á·ºÆð100£¥µÄCPUºÄ¾¡ £¬£¬£¬£¬£¬µ¼ÖÂÈí¼þ¹ÒÆð£¨Ã»ÓÐÏìÓ¦£© £¬£¬£¬£¬£¬Ö±µ½Ç¿ÐÐÖØÆô¡£¡£¡£¡£¡£


ÍâµØÈ¨ÏÞÌáÉýÎó²î


δ¾­Éí·ÝÑéÖ¤µÄÓû§£¨°üÀ¨À´±öÕÊ»§£©¿ÉÒÔʹÓóÌÐòµÄ¶þ½øÖƶÁÈ¡ £¬£¬£¬£¬£¬Ð´ÈëºÍÖ´ÐÐȨÏÞÖеÄÈõµãÀ´ÌáȨ¡£¡£¡£¡£¡£Õýµ±Óû§Æô¶¯FR Configurator2Èí¼þʱ»á´¥·¢´ËÎó²î £¬£¬£¬£¬£¬Ö´ÐжñÒâ¶þ½øÖÆÎļþ¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î £¬£¬£¬£¬£¬Çë¸üÐÂÖÁversion 1.17T£ºhttps://www.mitsubishielectric.com/en/index.html¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.applied-risk.com/assets/uploads/whitepapers/Mitsubishi-FR_Configurator2-Advisory-2019.pdf