¡¾Îó²îͨ¸æ¡¿OPCЭÒé¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-01-26

0x00 Îó²î¸ÅÊö

¿ª·Åƽ̨ͨѶ£¨OPC£©ÍøÂçЭÒéÊDzÙ×÷ÊÖÒÕ£¨OT£©ÍøÂçµÄÖÐÐÄÈË £¬£¬£¬£¬È·±£¹¤Òµ¿ØÖÆÏµÍ³£¨ICS£©ºÍרÓÐ×°±¸Ö®¼äµÄ¿É²Ù×÷ÐÔ £¬£¬£¬£¬ÈçÈÏÕæÏÖ³¡×°±¸×¼È·²Ù×÷µÄ¿É±à³ÌÂß¼­¿ØÖÆÆ÷(PLC)¡£¡£¡£¡£¡£OPC½ÓÄɱê×¼»¯µÄͨѶЭÒé¼°Æä¹æ·¶£¨OPC DA¡¢AE¡¢HDA¡¢XML DA¡¢DXºÍOPC UA£© £¬£¬£¬£¬°ü¹ÜÁ˶Ô×°±¸ºÍÀú³ÌµÄÖÎÀíºÍ¼àÊÓ¿ÉÒÔ´ÓÒ»¸ö¼¯ÖеÄЧÀÍÆ÷ÉϾÙÐÐ £¬£¬£¬£¬Æäͨ³£×÷ΪһÖÖÔÚICSÓòÖеÄ×°±¸ÖÐÔËÐеÄǶÈëʽЭÒé¶ø±»ÆÕ±éʹÓᣡ£¡£¡£¡£

2021Äê01ÔÂ25ÈÕ £¬£¬£¬£¬ClarotyÑо¿Ð¡×éÅû¶ÁËMatrikon Honeywell ¡¢ Softing Industrial Automation GmbH ºÍPTC KepwareµÄOPCÖб£´æµÄ¶à¸öÇå¾²Îó²î¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

±»Åû¶µÄOPCÎó²îÈçÏ£º

²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ó°Ïì

£¨Softing Industrial Automation GmbH£©

OPC

CVE-2020-14524

»ùÓڶѵĻº³åÇøÒç³ö

ÑÏÖØ

ЧÀÍÍ߽⡢´úÂëÖ´ÐÐ

CVE-2020-14522

×ÊÔ´ÏûºÄ

¸ßΣ

¾Ü¾øÐ§ÀÍ

£¨Honeywell£©

OPC UA Tunneller

CVE-2020-27297

»ùÓڶѵĻº³åÇøÒç³ö

ÑÏÖØ

RCE

CVE-2020-27299

Ô½½ç¶ÁÈ¡

¸ßΣ

ÐÅϢй¶¡¢×°±¸Íß½â

CVE-2020-27274

¼ì²é²»µ±

¸ßΣ

¾Ü¾øÐ§ÀÍ

CVE-2020-27295

×ÊÔ´ÏûºÄ

¸ßΣ

¾Ü¾øÐ§ÀÍ

£¨PTC£©

Kepware KEPServerEX

CVE-2020-27265

»ùÓڶѵĻº³åÇøÒç³ö

ÑÏÖØ

ЧÀÍÍ߽⡢RCE

CVE-2020-27263

»ùÓڶѵĻº³åÇøÒç³ö

ÑÏÖØ

ЧÀÍÍ߽⡢Êý¾Ýй¶

CVE-2020-27267

Use-after-free

¸ßΣ

ЧÀÍÍß½â

 

Softing OPC»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2020-14524£©

Softing OPC DA XML¿âÖб£´æ»ùÓڶѵĻº³åÇøÒç³öÎó²î £¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔì³ÉЧÀͱÀÀ£»£»£»£»£»£»£»òÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

Softing WebЧÀÍÆ÷ûÓÐÏÞÖÆSOAP±êÍ·µÄ³¤¶È £¬£¬£¬£¬Ò²Ã»Óо»»¯SOAP±êÍ·µÄÖµ £¬£¬£¬£¬ÓÉÓÚËüͨ¹ýSOAPÆÊÎöΪOPC DA XML¡£¡£¡£¡£¡£

Òì³£³¤µÄ±êÍ·½«µ¼ÖÂЧÀÍÆ÷ÎÞÐÝÖ¹µØ·ÖÅÉÄÚ´æ £¬£¬£¬£¬ÄÚ´æ·ÖÅÉ×îÖÕ»áÓÉÓÚ¶ÑÄÚ´æµÄ×ÊÔ´ÏûºÄ¶øÊ§°Ü¡£¡£¡£¡£¡£¿ÉÊÇWebЧÀÍÆ÷²»»á¼ì²éÄÚ´æ·ÖÅɵķµ»ØÂë £¬£¬£¬£¬¶øÊÇʵÑ齫Êý¾Ý¸´ÖƵ½·µ»ØµÄÖ¸Õë¡£¡£¡£¡£¡£¿ÉÊÇÓÉÓÚ·µ»ØµÄÖ¸ÕëΪNULL £¬£¬£¬£¬¹¥»÷ÕßµÄÊý¾Ý½«±»¸´ÖƵ½Î´³õʼ»¯µÄÄÚ´æÖÐ £¬£¬£¬£¬×îÖÕµ¼Ö»á¼ûÒì³£²¢Ê¹Ð§ÀÍÍ߽⡣¡£¡£¡£¡£

Ó°Ïì¹æÄ££¨ËùÓÐÎó²î£©

Softing Industrial Automation GmbH OPC < 4.47.0

 

Honeywell OPC UA Tunneller»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2020-27297£©

ÔÚHoneywell OPC Tunneller×é¼þÖз¢Ã÷Á˶à¸öÇå¾²Îó²î £¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÑÏÖØµÄ¶ÑÒç³öÎó²î£¨CVE-2020-27297£© £¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÄÚ´æ²¢Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ££¨ËùÓÐÎó²î£©

OPC UA Tunneller < 6.3.0.8233

 

 

PTC Kepware KEPServerEX»ùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2020-27265£©

¸ÃÎó²îÊÇKEPServerEXÖеÄÒ»¸ö»º³åÇøÒç³öÎó²î £¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµÄOPC UAÐÂÎÅÀ´Ê¹ÓôËÎó²î £¬£¬£¬£¬×îÖÕµ¼ÖÂЧÀͱÀÀ£»£»£»£»£»£»£»òÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ££¨ËùÓÐÎó²î£©

KEPServerEX: v6.0-v6.9

ThingWorx Kepware Server: v6.8¡¢v6.9

ThingWorx Industrial Connectivity: ËùÓа汾

OPC-Aggregator: ËùÓа汾

×é¼þ£º

Rockwell Automation KEPServer Enterprise: v6.6.504.0 ¡¢ v6.9.572.0

GE Digital Industrial Gateway Server: v7.68.804 ¡¢ v7.66

Software Toolbox TOP Server: ËùÓÐ 6.x °æ±¾

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ £¬£¬£¬£¬Ïà¹ØÎó²îÒѱ»ÐÞ¸´ £¬£¬£¬£¬½¨Òé²Î¿¼Í¨¸æÊµÊ±Éý¼¶¡£¡£¡£¡£¡£

Softing Industrial Automation OPC

https://us-cert.cisa.gov/ics/advisories/icsa-20-210-02

 

Honeywell OPC UA Tunneller

https://us-cert.cisa.gov/ics/advisories/icsa-21-021-03

 

PTC Kepware KEPServerEX

https://us-cert.cisa.gov/ics/advisories/icsa-20-352-02

 

 

0x03 ²Î¿¼Á´½Ó

https://www.claroty.com/2021/01/25/blog-research-critical-flaws-in-opc-protocol/

https://www.darkreading.com/attacks-breaches/claroty-discloses-multiple-critical-vulns-in-vendor-implementations-of-key-ot-protocol/d/d-id/1339973

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27265

 

 

0x04 ʱ¼äÏß

2021-01-25  CLAROTYÅû¶Îó²î

2021-01-26  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png