ModbusÍø¹ØÎó²î(CVE-2021-4161)ÆÊÎö
Ðû²¼Ê±¼ä 2022-01-17Ò»¡¢Îó²î¸ÅÊö
½üÆÚ£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøADLabÔÚ¹¤Òµ¿ØÖÆÎó²î¼à¿ØÖз¢Ã÷¹¤¿Ø³§ÉÌMoxaµÄModbusÍø¹Ø±£´æ¸ßΣÎó²î£¨CVE-2021-4161£©£¬£¬£¬£¬£¬£¬ICS-CERTµÄÆÀ·Ö¸ß´ï9.8¡£¡£¡£¡£¡£¡£Õë¶Ô¸Ã¸ßΣÎó²î£¬£¬£¬£¬£¬£¬ADLabÑо¿Ô±µÚһʱ¼ä¾ÙÐÐÁËÏêϸÆÊÎöºÍÑéÖ¤¡£¡£¡£¡£¡£¡£
1.1 »ù±¾ÐÅÏ¢
ƾ֤ICS-CERTµÄÎó²îͨ¸æ£¬£¬£¬£¬£¬£¬¸ÃÎó²î»ù±¾ÐÅÏ¢ÈçÏ£º
ÊÜÓ°ÏìµÄ×°±¸£º
MGate MB3180/MB3280/MB3480 Series Protocol Gateways
ÊÜÓ°ÏìµÄ°æ±¾£º
MGate MB3180 Series: Firmware Version 2.2 or lower
MGate MB3280 Series: Firmware Version 4.1 or lower
MGate MB3480 Series: Firmware Version 3.2 or lower
Îó²î¿ÉʹÓÃÐÔ£ºÔ¶³Ì¡¢µÍÖØÆ¯ºó
CVSS v3ÆÀ·Ö£º9.8
1.2 Îó²îÐÎò
ƾ֤ICS-CERTÎó²îͨ¸æµÄÐÎò£¬£¬£¬£¬£¬£¬¸ÃÎó²îÀàÐÍÊôÓÚÃô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä¡£¡£¡£¡£¡£¡£ÊÜÓ°Ïì×°±¸µÄ¹Ì¼þ±£´æÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐáÌ½ÍøÂçÁ÷Á¿À´ÇÔȡϢÕùÃÜ×°±¸µÇ¼ƾ֤µÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬´Ó¶ø»ñµÃ¶ÔÄ¿µÄ×°±¸http web serverµÄadminȨÏÞ¡£¡£¡£¡£¡£¡£

ͼ1 ICS-CERT AdvisoryÖжÔÎó²îµÄÐÎò
¸ÃÎó²îµÄCVSS3ÌØÕ÷Ϊ(AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)¡£¡£¡£¡£¡£¡£Èçͼ2Ëùʾ£¬£¬£¬£¬£¬£¬ICS-CERTÒÔΪ¸ÃÎó²î¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬£¬£¬Í¬Ê±¶ÔÍêÕûÐÔ£¨Integrity£©ºÍ¿ÉÓÃÐÔ£¨Availability£©µÄÓ°Ïì¾ùΪ¡°High¡±¡£¡£¡£¡£¡£¡£

ͼ2 ICS-CERT ¶ÔCVE-2021-4161 CVSS(3.0)ÆÀ·Ö
ÒÔÇ°ÃæµÄÎó²îÐÎò¿ÉÖª£¬£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÒ»¸ö²»Çå¾²µÄƾ֤´«Êäµ¼ÖÂÆ¾Ö¤Ð¹Â¶µÄÎó²î¡£¡£¡£¡£¡£¡£ÄÇô£¬£¬£¬£¬£¬£¬ÎªºÎICS-CERTÒÔΪÕâÑùÒ»¸öÎó²îÆä¶ÔÍêÕûÐԺͿÉÓÃÐÔµÄÓ°ÏìΪ¡°High¡±ÄØ¡£¡£¡£¡£¡£¡£´ø×ÅÕâ¸öÒɻ󣬣¬£¬£¬£¬£¬ÎÒÃÇÔÚMGate MB3180×°±¸É϶ԸÃÎó²î¾ÙÐÐÁËÆÊÎöºÍÑéÖ¤¡£¡£¡£¡£¡£¡£
¶þ¡¢Îó²îÆÊÎö
ƾ֤ICS-CERT¶ÔÎó²îµÄÐÎò£¬£¬£¬£¬£¬£¬ÎÒÃÇÒ»×îÏÈÍÆ²â¸ÃϵÁÐ×°±¸µÄwebµÇ¼½ÓÄÉÁËBasicÈÏÖ¤¡£¡£¡£¡£¡£¡£BasicÈÏÖ¤ÊǵÍÐÔÄÜ×°±¸web serverËù³£ÓõÄÒªÁ죬£¬£¬£¬£¬£¬ÆäÏÕЩûÓÐÇå¾²ÐÔ£¬£¬£¬£¬£¬£¬Ö±½Óͨ¹ýbase64½âÂëµÇ¼Á÷Á¿µÄÈÏÖ¤ÐÅÏ¢¼´¿É»ñµÃÓû§ÃûÃÜÂë¡£¡£¡£¡£¡£¡£
ƾ֤ÉÏÊö˼Ð÷£¬£¬£¬£¬£¬£¬ÎÒÃǶÔMB3180µÄµÇ¼Á÷Á¿¾ÙÐÐÁËÆÊÎö£¬£¬£¬£¬£¬£¬Èçͼ3Ëùʾ¡£¡£¡£¡£¡£¡£MB3180µÄWebÈÏÖ¤²¢Ã»ÓнÓÄÉBasicÈÏÖ¤·½·¨¡£¡£¡£¡£¡£¡£

ͼ3 MB3180 WebµÇ¼POSTÇëÇó
¼ÌÐø¶ÔµÇ¼ÇëÇó¾ÙÐÐÆÊÎö£¬£¬£¬£¬£¬£¬·¢Ã÷ÇëÇóÖÐµÄ±íµ¥Êý¾Ý°üÀ¨ÁË¡°account¡±¡¢¡°password¡±µÈ×Ö¶ÎÐÅÏ¢¡£¡£¡£¡£¡£¡£Èçͼ4Ëùʾ£º

ͼ4 MB3180 WebµÇ¼POSTÇëÇó±íµ¥Êý¾Ý£¨Óû§Ãûadmin,ÃÜÂë1234567£©
ÊÓ²ì±íµ¥ÖеÄÊý¾Ý¿ÉÖª£¬£¬£¬£¬£¬£¬accountºÍpasswordûÓг£¼û¹þÏ£ÔËËãµÄÌØÕ÷¡£¡£¡£¡£¡£¡£¶à´ÎµÇ¼µÄ±íµ¥Êý¾ÝÈçÏÂËùʾ£º

±í 1 ʹÓòî±ðÓû§ÃûÃÜÂëµÇ¼µÄPOST±íµ¥²¿·ÖÊý¾Ý¼Í¼
´ÓÉϱíÊý¾Ý»¹¿ÉÒÔ·¢Ã÷ÈçÏÂÌØÕ÷£º
accountºÍpasswordºÍÊäÈ볤¶ÈÊÇÏà¹ØµÄ£»£»£»£»£»
accountºÍpasswordºÍFakeChallengeÊÇÏà¹ØµÄ¡£¡£¡£¡£¡£¡£
ºóÐø¶ÔµÇÂ¼Ò³ÃæµÄÔ´ÂëÆÊÎöÕÒµ½ÁËÉÏÊöÌØÕ÷¡£¡£¡£¡£¡£¡£ÔڵǼҳµÄjs´úÂëÖУ¬£¬£¬£¬£¬£¬setInfoº¯ÊýÈÏÕæÌìÉúµÇ¼ÐÅÏ¢²¢ÒÔ±íµ¥·½·¨Ìá½»£¬£¬£¬£¬£¬£¬ÈçÏÂËùʾ£º

ͼ5 MB3180µÄsetInfoº¯Êý
ÏÔÈ»£¬£¬£¬£¬£¬£¬µÇ¼Êý¾ÝµÄÇå¾²ÐÔÈ¡¾öÓÚº¯ÊýSetSHA256£¬£¬£¬£¬£¬£¬Æä´úÂëÈçÏÂËùʾ£º

ͼ6 MB3180µÄSetSHA256º¯Êý
ÆÊÎöSetSHA256º¯ÊýµÄÂß¼¿ÉÖª£¬£¬£¬£¬£¬£¬¸Ãº¯Êý²¢Ã»ÓÐÕæÕýʵÏÖSHA256µÄ¹¦Ð§£¬£¬£¬£¬£¬£¬¶øÊÇʹÓÃÁËÒì»ò·½·¨À´´¦Öóͷ£ÊäÈëÊý¾Ý¡£¡£¡£¡£¡£¡£ÏêϸÀ´½²£¬£¬£¬£¬£¬£¬SetSHA256º¯ÊýµÄ·µ»ØÖµÊÇxor(m,n)Ö®ºóµÄЧ¹û£¬£¬£¬£¬£¬£¬¶ømȪԴÓÚaccount/password£¬£¬£¬£¬£¬£¬nÔòȪԴÓÚFakeChallenge¡£¡£¡£¡£¡£¡£ÏÔ¶øÒ×¼û£¬£¬£¬£¬£¬£¬ÔÚFakeChallenge±»Ð¹Â¶µÄÌõ¼þÏ£¬£¬£¬£¬£¬£¬account/passwordÊǿɻ¹ÔµÄ¡£¡£¡£¡£¡£¡£
ÖÁ´Ë£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄÔÀí¾Í»ù±¾ÇåÎúÁË¡£¡£¡£¡£¡£¡£MB3180ÔÚ´¦Öóͷ£µÇÂ¼Ò³ÃæµÄÓû§ÃûºÍÃÜÂë¼ÓÃÜʱ£¬£¬£¬£¬£¬£¬Î´×¼È·ÊµÏÖSHA256µÄÔËË㣬£¬£¬£¬£¬£¬Í¬Ê±web serverĬÈÏʹÓÃhttpÐÒé¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬ÔÚ¿ÉÐá̽µ½¸Ã×°±¸µÇ¼µÄhttp±¨ÎÄʱ£¬£¬£¬£¬£¬£¬±ã¿Éͨ¹ý½âÃÜ±íµ¥Êý¾ÝÀ´»ñµÃµÇ¼µÄÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£¡£
Èý¡¢Îó²îÑéÖ¤
ƾ֤ÉÏÊöÎó²îÆÊÎöЧ¹û£¬£¬£¬£¬£¬£¬ÎÒÃDZàдÏàʶÃܾ籾¶Ô¸ÃÎó²î¾ÙÐÐÁËÑéÖ¤¡£¡£¡£¡£¡£¡£Îª¼ò»¯ÑéÖ¤Àú³Ì£¬£¬£¬£¬£¬£¬ÎÒÃÇÖ±½ÓʹÓÃWiresharkץȡÁ˵ǼMB3180 Web ServerµÄhttpÁ÷Á¿£¬£¬£¬£¬£¬£¬È»ºó±àд¾ç±¾¶Ô¸ÃÁ÷Á¿¾ÙÐÐÆÊÎö²¢½âÃÜ¡£¡£¡£¡£¡£¡£
ÔÚ×¥°üÀú³ÌÖУ¬£¬£¬£¬£¬£¬ÎÒÃǾÙÐÐÁËÁ½´ÎµÇ¼£¬£¬£¬£¬£¬£¬Óû§Ãû¾ùΪadmin£¬£¬£¬£¬£¬£¬ÃÜÂëÔòʹÓÃÁËÒ»¸ö¹ýʧµÄÃÜÂ루admin£©ºÍÒ»¸ö׼ȷµÄÃÜÂ루moxa£©¡£¡£¡£¡£¡£¡£

ͼ7 ʹÓÃadmin\adminµÇ¼µÄ±íµ¥Êý¾Ý

ͼ8 ʹÓÃadmin\moxaµÇ¼µÄ±íµ¥Êý¾Ý
Ñé֤Ч¹ûÈçͼ9Ëùʾ£¬£¬£¬£¬£¬£¬¿É´ÓµÇ¼Á÷Á¿½âÃÜ»ñµÃÓû§ÃûºÍÃÜÂëÐÅÏ¢£º

ͼ9 ½âÃܾ籾ÑéÖ¤
ËÄ¡¢Îó²îΣº¦
ÔÚ¹¤Òµ¿ØÖÆÇéÐÎÖУ¬£¬£¬£¬£¬£¬Óдó×ÚµÄ×°±¸²¢²»¾ß±¸TCP/IPÐÒéÕ»£¬£¬£¬£¬£¬£¬Òª°ÑÕâЩװ±¸½ÓÈë»ùÓÚITÊÖÒÕµÄÊý×Ö»¯ÍøÂç¾ÍÐèÒª½èÖúÐÒéת»»Íø¹ØÀ´Íê³É¡£¡£¡£¡£¡£¡£MGate MBϵÁÐModbusÍø¹Ø×°±¸µÄ¹¦Ð§¼´ÊǰÑRS485ÀàµÄ¹¤Òµ×°±¸½ÓÈëµ½TCP/IPÍøÂç¡£¡£¡£¡£¡£¡£ÕâÀàÍø¹Ø×°±¸Îó²îµÄΣº¦Í¨³£²»µ«½öÓ°Ïì¸Ã×°±¸×ÔÉí£¬£¬£¬£¬£¬£¬¸üÖ±½ÓÓ°ÏìÆä±³ºóÖ§³ÖµÄÏÖ³¡×°±¸¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬NVD¶Ô¸ÃÎó²î¸ø³öÁËÁ½ÖÖCVSS3ÆÀ·Ö£¬£¬£¬£¬£¬£¬ÈçÏÂËùʾ¡£¡£¡£¡£¡£¡£

ͼ10 NVDºÍICS-CERTÆÀ·ÖÇø±ð
ÆäÖУ¬£¬£¬£¬£¬£¬NVD»ùÓÚNISTµÄÊӽǸø³öÁË7.5·Ö£¬£¬£¬£¬£¬£¬¶øICS-CERT»ùÓÚ¹¤ÒµÊӽǸø³öÁË9.8¸ß·Ö¡£¡£¡£¡£¡£¡£ÕâÁ½ÖÖÆÀ·ÖµÄ²î±ð¾ÍÔÚÓÚ£º´ÓIT½Ç¶È¿´£¬£¬£¬£¬£¬£¬¸ÃÎó²î²»¿ÉÐ޸ĸÃ×°±¸µÄµ×²ãÊý¾Ý£¬£¬£¬£¬£¬£¬Ò²²»¿Éʹװ±¸×èÖ¹ÔËÐУ¬£¬£¬£¬£¬£¬Òò´Ë²»Ó°Ïì¸Ã×°±¸µÄÍêÕûÐԺͿÉÓÃÐÔ£»£»£»£»£»µ«´Ó¹¤Òµ½Ç¶È¿´£¬£¬£¬£¬£¬£¬Í¨¹ý¸ÃÎó²î»ñµÃÖÎÀíÔ±Õ˺źó¿ÉÒÔÐÞ¸ÄÍø¹ØµÄÉèÖ㬣¬£¬£¬£¬£¬½ø¶øÊ¹µÃ¸Ã×°±¸Ö§³ÖµÄ¹¤Òµ¿ØÖÆÓªÒµ±¬·¢±ä»»ÉõÖÁÊÇ×èÖ¹£¬£¬£¬£¬£¬£¬ÒÔÊÇÓ°ÏìÁ˹¤Òµ¿ØÖÆÓªÒµµÄÍêÕûÐԺͿÉÓÃÐÔ¡£¡£¡£¡£¡£¡£
¿É¼û£¬£¬£¬£¬£¬£¬Í¬ÑùÀàÐ͵ÄÍøÂçÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÆäÔÚ¹¤Òµ¿ØÖÆÏ½µµÍìÓòµÄÓ°ÏìºÍΣº¦Í¨³£Òª¸ßÓڹŰåITÓªÒµÁìÓò¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬ÔÚ´¦Öóͷ£¹¤Òµ¿ØÖÆÏµÍ³ÍøÂçÇå¾²Îó²îʱ£¬£¬£¬£¬£¬£¬ÐèҪ˼Á¿µ½¹¤¿ØÓªÒµÇéÐεÄÌØÊâÐÔ£¬£¬£¬£¬£¬£¬Á¬Ïµ¶Ô¹¤¿ØÓªÒµµÄÓ°ÏìÀ´×ÛºÏÆÀÅÐÎó²îµÄΣº¦²Å»ªÔ½·¢¿Í¹ÛÕæÊµµÄ·´Ó¦Îó²îµÄÓ°ÏìÁ¦¡£¡£¡£¡£¡£¡£
Îå¡¢ÐÞ¸´½¨Òé
ÏÖÔÚ£¬£¬£¬£¬£¬£¬¹Ù·½Î´Ðû²¼¸ÃÎó²îµÄÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬£¬µ«ÌṩÁËÎó²î»º½â½¨Ò飺
½¨Ò齫ÊÜÓ°Ïì×°±¸µÄWeb Server»á¼ûµÄÐÒéÉèÖÃΪhttps£¬£¬£¬£¬£¬£¬×èÖ¹Ã÷ÎÄ´«Êä±íµ¥Êý¾Ý£»£»£»£»£»
½¨Òé²ÎÕÕMoxa SecurityHardening Guide for MGate MB3000 SeriesÖеķ½·¨°²ÅÅ×°±¸¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬Õë¶Ô¹¤Òµ¿ØÖÆÏµÍ³£¬£¬£¬£¬£¬£¬CISAÌṩÁËÈçϵÄͨÓý¨Ò飺
Ö»¹ÜïÔÌÔÚ¹«ÍøÌ»Â¶¹¤¿Ø×°±¸»òÕßϵͳ£»£»£»£»£»
½«¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸ÖÃÓÚ·À»ðǽ֮ºó£¬£¬£¬£¬£¬£¬²¢ºÍ°ì¹«ÍøÂç¸ôÀ룻£»£»£»£»
µ±ÐèÒªÔ¶³Ì»á¼ûʱ£¬£¬£¬£¬£¬£¬½ÓÄÉÀàÐÍVPNµÄÇå¾²»á¼û·½·¨¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ