Î÷ÃÅ×Ó¶à¿î²úÆ·Çå¾²Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-08-16? Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-6568£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.5
? Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
CVE-2019-10942
SCALANCE X-200: All versionsSCALANCE X-200IRT: All versions
SCALANCE X-200RNA: All versions
CVE-2019-6568
SINAMICS GH150 V4.7 (Control Unit):All versions
SINAMICS GH150 V4.8 (Control Unit):All versions < V4.8 SP2 HF6SINAMICS GL150 V4.7 (Control Unit):All versions
SINAMICS GL150 V4.8 (Control Unit):All versions < V4.8 SP2 HF7
SINAMICS GM150 V4.7 (Control Unit):All versions
SINAMICS GM150 V4.8 (Control Unit):All versions < V4.8 SP2 HF9
SINAMICS SL150 V4.7 (Control Unit):All versions
SINAMICS SL150 V4.8 (Control Unit):All versions
SINAMICS SM120 V4.7 (Control Unit):All versions
SINAMICS SM120 V4.8 (Control Unit):All versions
SINAMICS SM150 V4.8 (Control Unit):All versions
? Îó²î¸ÅÊö
Î÷ÃÅ×ÓÐû²¼Á˸ßÑÏÖØÐÔ²úÆ·Îó²îÔ¤¾¯£¬°üÀ¨Ó°ÏìSCALANCE X¹¤Òµ½»Á÷»úµÄ¾Ü¾ø·þÎñ£¨DoS£©Îó²îCVE-2019-10942ºÍÓ°ÏìSINAMICSת»»Æ÷Web·þÎñÆ÷µÄ¾Ü¾ø·þÎñ£¨DoS£©Îó²îCVE-2019-6568¡£Îó²îÐÅÏ¢ÈçÏ£º
¸ÃÎó²îÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÖØ¸´ÏòTelnet·þÎñ·¢ËÍ´ó×ÚÐÂÎŰü£¬µ¼ÖÂ×°±¸½øÈëDoS״̬¡£Ñо¿Ö°Ô±ÌåÏÖ¹¥»÷Õßͨ¹ýÏòTCP 23¶Ë¿Ú·¢ËÍ´ó×ÚÊý¾Ý°üÀ´ÆÆËðtelnet·þÎñ£¬×°±¸Íß½âºó»á×Ô¶¯ÖØÆô£¬Õâ¿ÉÄܵ¼ÖÂDZÔÚµÄÁ÷³ÌÖÐÖ¹¡£¹¥»÷ÕßʹÓøÃÎó²îÐèÒª»á¼ûÄ¿µÄ½»Á÷»úµÄÍøÂ磬²¢ÇÒÖ»ÐèÒªÏàʶһЩ±ê×¼µÄtelnetÐÒé¡£Ñо¿Ö°Ô±ÒѾȷ¶¨ÁËһЩ¿ÉÄÜÖ±½ÓÊܵ½À´×Ô»¥ÁªÍø¹¥»÷µÄ×°±¸£¬µ«¸ÃÎó²î²¢½ûÖ¹Ò×ʹÓã¬ÓÉÓÚËü¿ÉÄÜÓÐÒ»¸ö·ÇÈ·¶¨ÐԵĸ´Öư취±»´¥·¢¡£
¸ÃÎó²îÔÊÐí¾ßÓжÔÊÜÓ°ÏìϵͳµÄÍøÂç»á¼ûȨÏ޵Ĺ¥»÷ÕßÔÚ²»ÐèÒªÉí·ÝÑéÖ¤»òÓû§½»»¥µÄÇéÐÎϵ¼Ö¾ܾø·þÎñ£¬µ¼ÖÂÖØÐÂÆô¶¯Web·þÎñÆ÷¡£
? Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£
? ÐÞ¸´½¨Òé
ÏÖÔÚÎ÷ÃÅ×ÓÉÐδÕë¶Ô¸ÃÎó²îÐû²¼Èκβ¹¶¡³ÌÐò£¬Ïà¹ØÓû§¿Éͨ¹ýÔÚÊÜÓ°ÏìµÄ×°±¸ÉϽûÓÃTelnet·þÎñ£¨½¨ÒéʹÓÃSSH£©ÒÔ¼°ÏÞÖÆ¶ÔTCP¶Ë¿Ú23µÄÍøÂç»á¼û£¬À´±ÜÃâDZÔÚ¹¥»÷¡£
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬¼û²Î¿¼Á´½Ó¡£
? ²Î¿¼Á´½Ó
https://cert-portal.siemens.com/productcert/pdf/ssa-530931.pdf


¾©¹«Íø°²±¸11010802024551ºÅ