CVE-2020-6994| ºÕ˹ÂüHiOSºÍHiSecOS²úÆ·Çå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-010x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-6994 |
ʱ ¼ä |
2020-04-01 |
|
Àà ÐÍ |
»º³åÇøÒç³ö |
µÈ ¼¶ |
ÑÏÖØ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
HiOS <= 07.0.02 Ó°Ïì²úÆ·£ºRSP£¬£¬£¬£¬£¬£¬£¬RSPE£¬£¬£¬£¬£¬£¬£¬RSPS£¬£¬£¬£¬£¬£¬£¬RSPL£¬£¬£¬£¬£¬£¬£¬MSP£¬£¬£¬£¬£¬£¬£¬EES£¬£¬£¬£¬£¬£¬£¬ EESX£¬£¬£¬£¬£¬£¬£¬GRS£¬£¬£¬£¬£¬£¬£¬OS£¬£¬£¬£¬£¬£¬£¬RED½»Á÷»ú£»£»£»£»£»£»£»£» HiSecOS0 <= 3.2.00 Ó°Ïì²úÆ·£ºEAGLE 20/30·À»ðǽ |
x01 Îó²îÏêÇé
µÂ¹úºÕ˹Âü×Ô¶¯»¯ºÍ¿ØÖƹ«Ë¾½¨ÉèÓÚ1924Ä꣬£¬£¬£¬£¬£¬£¬ÓªÒµÂþÑÜÔÚ×Ô¶¯»¯Í¨Ñ¶ÁìÓò£¬£¬£¬£¬£¬£¬£¬²úÆ·¹æÄ£°üÀ¨½ÓÄÉÄ£ÄâºÍÊý×ֹ㲥µçÊÓ´«ÊäÊÖÒÕµÄÒÆ¶¯·¢ÉäºÍÎüÊÕϵͳ£¬£¬£¬£¬£¬£¬£¬ÆóÒµºÍ¹¤ÒµÍøÂç½â¾ö¼Æ»®ÒÔ¼°ÏÖ³¡×ÜÏßϵͳ¡£¡£¡£¡£¡£ºÕ˹ÂüÔÚ2007Äê±»ÃÀ¹ú°Ùͨ£¨Belden£©¹«Ë¾ÊÕ¹º¡£¡£¡£¡£¡£ºÕ˹ÂüHiOSºÍHiSecOS¶¼ÊǰÙÍ¨ÍÆ³öµÄÇå¾²²Ù×÷ϵͳ¡£¡£¡£¡£¡£
HiOSºÍHiSecOSµÄHTTP(S)web serverÖб£´æÒ»¸ö»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ¶ÔURL²ÎÊýµÄÆÊÎö²»µ±ÒýÆðµÄ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ½èÖúÌØÖÆµÄHTTPÇëÇóÈëÇÖÄ¿µÄ×°±¸£¬£¬£¬£¬£¬£¬£¬Ôì³ÉÄÚ²¿»º³åÇøÒç³ö¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬½¨ÒéHiOSÓû§¾¡¿ì¸üÐÂÖÁ07.0.03»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬£¬HiSecOSÓû§¸üÐÂÖÁ03.3.00»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£
ÔÝʱ²½·¥¿ÉʹÓá°IP»á¼ûÏÞÖÆ¡±¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ÏÞÖÆHTTPºÍHTTPS¶Ô¿ÉÐÅIPµØµãµÄ»á¼û£¬£¬£¬£¬£¬£¬£¬»òÕß½ûÓÃHTTPºÍHTTPSЧÀÍÆ÷¡£¡£¡£¡£¡£
https://www.belden.com/hubfs/support/security/bulletins/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf?hsLang=en
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-091-01
0x05 ʱ¼äÏß
2020-02-14 Ðû²¼Îó²î
2020-02-26 ÍÆ³ö½â¾ö¼Æ»®
2020-03-24 »ñµÃCVE±àºÅ


¾©¹«Íø°²±¸11010802024551ºÅ