CVE-2020-10607| Advantech WebAccess»º³åÇøÒç³öÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-22

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-10607

ʱ   ¼ä

2020-04-22

Àà    ÐÍ

BO

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Advantech WebAccess <=8.4.2




0x01 Îó²îÏêÇé


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾




Advantech WebAccessÊÇÖйų́ÍåÑлª£¨Advantech£©¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¡£ ¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý¿ØÖÆ£¬£¬£¬£¬£¬²¢ÌṩԶ³Ì¿ØÖƺÍÖÎÀí×Ô¶¯»¯×°±¸µÄ¹¦Ð§¡£¡£ ¡£¡£¡£¡£¡£¡£

Advantech WebAccess 8.4.2¼°Ö®Ç°°æ±¾Öб£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷУÑéÓû§Ìá½»Êý¾ÝµÄ³¤¶È¡£¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐдúÂë¡£¡£ ¡£¡£¡£¡£¡£¡£CVSSÆÀ·Ö8.8¡£¡£ ¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.advantech.com.cn/

±ðµÄ£¬£¬£¬£¬£¬½¨ÒéÏà¹ØÓû§Ó¦½ÓÄɵįäËûÇå¾²·À»¤²½·¥ÈçÏ£º

£¨1£© ×î´óÏ޶ȵØïÔÌ­ËùÓпØÖÆÏµÍ³×°±¸ºÍ/»òϵͳµÄÍøÂç̻¶£¬£¬£¬£¬£¬²¢È·±£ÎÞ·¨´ÓInternet»á¼û£»£»£»£»£»£»

£¨2£© ¶¨Î»·À»ðǽ·À»¤µÄ¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸£¬£¬£¬£¬£¬²¢½«ÆäÓëÓªÒµÍøÂç¸ôÀ룻£»£»£»£»£»

£¨3£© µ±ÐèÒªÔ¶³Ì»á¼ûʱ£¬£¬£¬£¬£¬ÇëʹÓÃÇå¾²ÒªÁ죬£¬£¬£¬£¬ÀýÈçÐéÄâרÓÃÍøÂ磨VPN£©£¬£¬£¬£¬£¬²¢È·ÈÏVPN¿ÉÄܱ£´æµÄÎó²î£¬£¬£¬£¬£¬Ð轫VPN¸üе½×îа汾¡£¡£ ¡£¡£¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://www.auscert.org.au/bulletins/ESB-2020.1084/


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-086-01

https://nvd.nist.gov/vuln/detail/CVE-2020-10607

https://www.cnvd.org.cn/flaw/show/CNVD-2020-19926


0x05 ʱ¼äÏß


2020-03-26 CVEÐû²¼¸ÃÎó²î


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾