Rockwell Automation¿É±à³ÌÂß¼¿ØÖÆÆ÷Çå¾²Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-03-18Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-6990£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-6984£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-6988£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-6980£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º4.0£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001¼°Ö®Ç°°æ±¾ºÍSeries AËùÓа汾
MicroLogix 1100 ControllerËùÓа汾
RSLogix 500 Software v12.001¼°Ö®Ç°°æ±¾
Îó²î¸ÅÊö
ÃÀ¹úRockwell Automation¹«Ë¾ÊÇÈ«Çò×î´óµÄ×Ô¶¯»¯ºÍÐÅÏ¢»¯¹«Ë¾Ö®Ò»¡£¡£¡£¡£¡£¡£¡£MicroLogix 1400 ControllersºÍMicroLogix 1100 ControllersÊÇRockwell Automation¹«Ë¾³öÆ·µÄ¿É±à³ÌÂß¼¿ØÖÆÆ÷¡£¡£¡£¡£¡£¡£¡£RSLogix 500 SoftwareÊÇÒ»Ì×ÓÃÓÚ¹¤Òµ¿ØÖÆÏµÍ³µÄ±à³ÌÈí¼þ¡£¡£¡£¡£¡£¡£¡£
ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕÐû²¼ÁËÒ»ÔòÇ徲ͨ¸æ£¬£¬£¬£¬£¬Åû¶ÃÀ¹úRockwell Automation¹«Ë¾MicroLogix 1400 Controllers£¬£¬£¬£¬£¬MicroLogix1100 ControllersºÍRSLogix 500 SoftwareÖеĶà¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÅÊöÈçÏ£º
CVE-2020-6990£¬£¬£¬£¬£¬ RSLogix 500¶þ½øÖÆÎļþʹÓÃÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬¶ø¸Ã¼ÓÃÜÃÜÔ¿ÓÃÓÚ±£»£»£»£»£»¤ÕË»§ÃÜÂë¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýʶ±ð¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬²¢½«ÆäÓÃÓÚºóÐøµÄÃÜÂë¹¥»÷£¬£¬£¬£¬£¬×îÖո濢ԽȨ»á¼û¿ØÖÆÆ÷¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6984£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚʹÓÃÁ˱»ÆÆ½âµÄ»òÓÐΣº¦µÄËã·¨£¬£¬£¬£¬£¬MicroLogixÖÐÓÃÓÚ±£»£»£»£»£»¤ÃÜÂëµÄ¼ÓÃܺ¯ÊýÈÝÒ×±»·¢Ã÷¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÆÆ½âËã·¨²¢ÈëÇÖÊܱ£»£»£»£»£»¤µÄÊý¾Ý£¬£¬£¬£¬£¬×îÖÕй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6988£¬£¬£¬£¬£¬Î´¾Éí·ÝÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õ߿ɴÓRSLogix 500 SoftwareÏòÊܺ¦ÕßµÄMicroLogix¿ØÖÆÆ÷·¢ËÍÒ»¸öÇëÇ󣬣¬£¬£¬£¬¿ØÖÆÆ÷»á½ÓÄÉÒÑÓùýµÄÃÜÂëÖµÏìÓ¦¿Í»§¶Ë£¬£¬£¬£¬£¬¶ÔÔÚ¿Í»§¶ËÉϵÄÓû§¾ÙÐÐÉí·ÝÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÖÖÉí·ÝÈÏÖ¤ÒªÁìÈÆ¹ýÉí·ÝÈÏÖ¤£¬£¬£¬£¬£¬Ð¹Â¶Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬»òй¶ƾ֤¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6980£¬£¬£¬£¬£¬RSLogix 500ÖÐÉúÑÄÁËSMTPÕË»§Êý¾Ý£¬£¬£¬£¬£¬ÓÉÓÚ¸ÃÊý¾ÝÒÔÃ÷ÎÄÐÎʽдÈëµ½ÏîÄ¿ÎļþÖУ¬£¬£¬£¬£¬ÍâµØ¹¥»÷ÕßÈôÊÇ¿ÉÒÔ»á¼ûÊܺ¦ÕßµÄÏîÄ¿£¬£¬£¬£¬£¬ÔòÄܹ»ÍøÂçSMTP serverµÄÉí·ÝÈÏÖ¤Êý¾Ý¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
¹ØÓÚʹÓÃMicroLogix 1400 Controllers Series BµÄÓû§£¬£¬£¬£¬£¬Rockwell½¨Òé¸üа汾ÖÁ21.002»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬²¢Ê¹ÓÃÔöÇ¿µÄÃÜÂëÇå¾²¹¦Ð§£¬£¬£¬£¬£¬Á´½Ó£ºhttps://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx?crumb=112&refSoft=1&toggleState=&versions=56181,56502,56710,57096,58298¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚRSLogix 500Èí¼þ£¬£¬£¬£¬£¬Rockwell Automation½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹ÓÃv11»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬²¢ÓëÊÊÓÃÓÚMicrologix 1400ϵÁÐB×°±¸µÄFRN 21.001»ò¸ü¸ß°æ±¾Ò»ÆðʹÓ㬣¬£¬£¬£¬Á´½Ó£ºhttps://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx?crumb=112&refSoft=1&toggleState=&versions=57415,56006¡£¡£¡£¡£¡£¡£¡£
¶ø¹ØÓÚMicroLogix 1400 Series A¿ØÖÆÆ÷»òMicroLogix 1100¿ØÖÆÆ÷£¬£¬£¬£¬£¬Rockwell AutomationÏòCISAÌåÏÖÏÖÔÚÉÐδÓлº½â²½·¥¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-070-06


¾©¹«Íø°²±¸11010802024551ºÅ