Î÷ÃÅ×ÓS7-1200 PLC²úÆ·Çå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-05

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13945£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.8 £¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


S7-1200ËùÓа汾


Îó²î¸ÅÊö


Siemens S7-1200 CPUÖб£´æÇå¾²Îó²î¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»á¼ûÆäËûÕï¶Ï¹¦Ð§£¬£¬£¬Ó°ÏìϵͳµÄÍêÕûÐÔ¡¢¿ÉÓÃÐԺͱ£ÃÜÐÔ¡£¡£¡£¡£


Î÷ÃÅ×Ó×î½üÐû²¼ÁËÒ»·ÝÇ徲ͨ¸æ£¬£¬£¬ÆäÖаüÀ¨Õë¶ÔÑо¿Ö°Ô±ÔÚÆäS7-1200¿É±à³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©Öз¢Ã÷µÄÎó²îµÄ±äͨ²½·¥»ººÍ½â²½·¥£¬£¬£¬¸ÃÎó²î¿ÉÓÃÓÚÈÆ¹ý¹Ì¼þÍêÕûÐÔ¼ì²éÒÔ¼ÓÔØ¶ñÒâÈí¼þ»òÐ®ÖÆ×°±¸µÄ¹¤ÒµÁ÷³Ì¡£¡£¡£¡£Î÷ÃÅ×ÓÌåÏÖ£º¡°ÎÒÃÇÕýÔÚÉó²é¿­·¢k8²úÆ·Ä£×Ó£¬£¬£¬²¢½«ÔÚSSA-686531ÉÏÐû²¼¸üУ¬£¬£¬ÒÔ·ÀÆäËûÄ£×ÓÊܵ½Ó°Ïì¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷£¬£¬£¬¿É±à³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©ÖеÄÌØÊâ»á¼û¹¦Ð§Ò²¿ÉÒԺܺõØÓÃ×÷£º×÷Ϊ·ÀÓùÕßµÄȡ֤¹¤¾ß¡£¡£¡£¡£ËûÃÇʹÓøù¦Ð§Éó²éPLC´æ´¢Æ÷µÄÄÚÈÝ£¬£¬£¬Òò´Ë¹¤³§²Ù×÷Ô±Ò²¿ÉÒÔʹÓÃËüÀ´²éÕÒÉè±¹ØÁ¬Ä¶ñÒâ´úÂë¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥½â¾ö´ËÇå¾²ÎÊÌ⣬£¬£¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö²½·¥£ºhttps://www.siemens.com£»£»£»£» £»


S7-122 CPUµÄÓû§¿ÉÒÔ½ÓÄÉÕâЩ±äͨ²½·¥»ººÍ½â²½·¥À´½µµÍΣº¦£º


1.È·±£ÎïÆÊÎö¼û±£»£»£»£» £»¤£»£»£»£» £»

2.Ó¦ÓÃÉî¶È·ÀÓù¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.darkreading.com/vulnerabilities---threats/siemens-offers-workarounds-for-newly-found-plc-vulnerability/d/d-id/1336503