CVE-2020-6994| ºÕ˹ÂüHiOSºÍHiSecOS²úÆ·Çå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-010x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-6994 |
ʱ ¼ä |
2020-04-01 |
|
Àà ÐÍ |
»º³åÇøÒç³ö |
µÈ ¼¶ |
ÑÏÖØ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
HiOS <= 07.0.02 Ó°Ïì²úÆ·£ºRSP£¬RSPE£¬RSPS£¬RSPL£¬MSP£¬EES£¬ EESX£¬GRS£¬OS£¬RED½»Á÷»ú£» HiSecOS0 <= 3.2.00 Ó°Ïì²úÆ·£ºEAGLE 20/30·À»ðǽ |
x01 Îó²îÏêÇé
µÂ¹úºÕ˹Âü×Ô¶¯»¯ºÍ¿ØÖƹ«Ë¾½¨ÉèÓÚ1924Ä꣬ӪҵÂþÑÜÔÚ×Ô¶¯»¯Í¨Ñ¶ÁìÓò£¬²úÆ·¹æÄ£°üÀ¨½ÓÄÉÄ£ÄâºÍÊý×ֹ㲥µçÊÓ´«ÊäÊÖÒÕµÄÒÆ¶¯·¢ÉäºÍÎüÊÕϵͳ£¬ÆóÒµºÍ¹¤ÒµÍøÂç½â¾ö¼Æ»®ÒÔ¼°ÏÖ³¡×ÜÏßϵͳ¡£ºÕ˹ÂüÔÚ2007Äê±»ÃÀ¹ú°Ùͨ£¨Belden£©¹«Ë¾ÊÕ¹º¡£ºÕ˹ÂüHiOSºÍHiSecOS¶¼ÊǰÙÍ¨ÍÆ³öµÄÇå¾²²Ù×÷ϵͳ¡£
HiOSºÍHiSecOSµÄHTTP(S)web serverÖб£´æÒ»¸ö»º³åÇøÒç³öÎó²î¡£¸ÃÎó²îÔ´ÓÚ¶ÔURL²ÎÊýµÄÆÊÎö²»µ±ÒýÆðµÄ¡£¹¥»÷Õß¿ÉÒÔ½èÖúÌØÖÆµÄHTTPÇëÇóÈëÇÖÄ¿µÄ×°±¸£¬Ôì³ÉÄÚ²¿»º³åÇøÒç³ö¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐÞ¸´¸ÃÎó²î£¬½¨ÒéHiOSÓû§¾¡¿ì¸üÐÂÖÁ07.0.03»ò¸ü¸ß°æ±¾£¬HiSecOSÓû§¸üÐÂÖÁ03.3.00»ò¸ü¸ß°æ±¾¡£
ÔÝʱ²½·¥¿ÉʹÓá°IP»á¼ûÏÞÖÆ¡±¹¦Ð§£¬ÏÞÖÆHTTPºÍHTTPS¶Ô¿ÉÐÅIPµØµãµÄ»á¼û£¬»òÕß½ûÓÃHTTPºÍHTTPS·þÎñÆ÷¡£
https://www.belden.com/hubfs/support/security/bulletins/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf?hsLang=en
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-091-01
0x05 ʱ¼äÏß
2020-02-14 Ðû²¼Îó²î
2020-02-26 ÍÆ³ö½â¾ö¼Æ»®
2020-03-24 »ñµÃCVE±àºÅ


¾©¹«Íø°²±¸11010802024551ºÅ