CVE-2020-10607| Advantech WebAccess»º³åÇøÒç³öÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-220x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-10607 |
ʱ ¼ä |
2020-04-22 |
|
Àà ÐÍ |
BO |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
Advantech WebAccess <=8.4.2 |
0x01 Îó²îÏêÇé
Advantech WebAccessÊÇÖйų́ÍåÑлª£¨Advantech£©¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý¿ØÖÆ£¬£¬£¬£¬£¬²¢ÌṩԶ³Ì¿ØÖƺÍÖÎÀí×Ô¶¯»¯×°±¸µÄ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£
Advantech WebAccess 8.4.2¼°Ö®Ç°°æ±¾Öб£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷУÑéÓû§Ìá½»Êý¾ÝµÄ³¤¶È¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£CVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º
https://www.advantech.com.cn/
±ðµÄ£¬£¬£¬£¬£¬½¨ÒéÏà¹ØÓû§Ó¦½ÓÄɵįäËûÇå¾²·À»¤²½·¥ÈçÏ£º
£¨1£© ×î´óÏ޶ȵØïÔÌËùÓпØÖÆÏµÍ³×°±¸ºÍ/»òϵͳµÄÍøÂç̻¶£¬£¬£¬£¬£¬²¢È·±£ÎÞ·¨´ÓInternet»á¼û£»£»£»£»£»£»
£¨2£© ¶¨Î»·À»ðǽ·À»¤µÄ¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸£¬£¬£¬£¬£¬²¢½«ÆäÓëÓªÒµÍøÂç¸ôÀ룻£»£»£»£»£»
£¨3£© µ±ÐèÒªÔ¶³Ì»á¼ûʱ£¬£¬£¬£¬£¬ÇëʹÓÃÇå¾²ÒªÁ죬£¬£¬£¬£¬ÀýÈçÐéÄâרÓÃÍøÂ磨VPN£©£¬£¬£¬£¬£¬²¢È·ÈÏVPN¿ÉÄܱ£´æµÄÎó²î£¬£¬£¬£¬£¬Ð轫VPN¸üе½×îа汾¡£¡£¡£¡£¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
https://www.auscert.org.au/bulletins/ESB-2020.1084/
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-086-01
https://nvd.nist.gov/vuln/detail/CVE-2020-10607
https://www.cnvd.org.cn/flaw/show/CNVD-2020-19926
0x05 ʱ¼äÏß
2020-03-26 CVEÐû²¼¸ÃÎó²î


¾©¹«Íø°²±¸11010802024551ºÅ