¡¾Îó²îͨ¸æ¡¿ICEFALL £ºOT×°±¸¶à¸öÎó²î
Ðû²¼Ê±¼ä 2022-06-220x00 Îó²î¸ÅÊö
2022Äê6ÔÂ20ÈÕ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±¹ûÕæÅû¶Á˲Ù×÷ÊÖÒÕ (OT) ×°±¸ÖÐÓÉÓÚ²»Çå¾²Éè¼Æµ¼ÖµÄ56¸öÎó²î£¬£¬£¬£¬£¬ÕâЩÎó²îͳ³ÆÎªOT:ICEFALL£¬£¬£¬£¬£¬Ó°ÏìÁËÀ´×Ô10¼ÒOT¹©Ó¦É̵Ä×°±¸¡£¡£¡£¡£
0x01 Îó²îÏêÇé
OT:ICEFALLÎó²îÖ÷ÒªÊÇÓÉÓÚOTµÄÉè¼Æ²»Çå¾²¡¢Çå¾²¿ØÖÆÈ±·¦µ¼Öµģ¬£¬£¬£¬£¬ÆäÖÐÐí¶àÊÜÓ°Ïì×°±¸Ê¹ÓÃÃ÷ÎÄÆ¾Ö¤¡¢ÈõÃÜÂë»òËð»µÃÜÂë¡¢Ó²±àÂëÃÜÔ¿ºÍ¿Í»§¶ËÉí·ÝÑéÖ¤¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬ÆäÖÐ74%µÄÒ×Êܹ¥»÷²úƷϵÁÐÒÑͨ¹ýÇå¾²ÈÏÖ¤¡£¡£¡£¡£
ÀÖ³ÉʹÓÃÕâЩÎó²î¿ÉÄܵ¼Ö£ºÆ¾Ö¤Ð¹Â¶¡¢Éí·ÝÑéÖ¤ÈÆ¹ý¡¢Îļþ/¹Ì¼þ/ÉèÖõĸ͝¡¢¾Ü¾øÐ§ÀÍ(DoS)»òÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£¡£¡£¡£

IcefallÎó²îµÄÀàÐÍ£¨ÈªÔ´£ºForescout£©
OT:ICEFALLÎó²îÓ°ÏìµÄ¹©Ó¦Ḛ́üÀ¨Honeywell¡¢Motorola¡¢Omron¡¢Siemens¡¢Emerson¡¢JTEKT¡¢Bentley Nevada¡¢Phoenix Contract¡¢ProConOS ºÍ Yokogawa¡£¡£¡£¡££¨»ôÄáΤ¶û¡¢Ä¦ÍÐÂÞÀ¡¢Å·Ä·Áú¡¢Î÷ÃÅ×Ó¡¢°¬Ä¬É¡¢JTEKT¡¢±¾ÌØÀûÄÚ»ª´ï¡¢·ÆÄá¿Ë˹µçÆø¹«Ë¾¡¢ProConOSºÍºáºÓ£©¡£¡£¡£¡£ÆäÖÐÓ°ÏìHoneywell×°±¸µÄÎó²î°üÀ¨£ºCVE-2022-30312µ½CVE-2022-30320µÈ9¸öÎó²î£¬£¬£¬£¬£¬Ó°ÏìBently Nevada×°±¸µÄÎó²î°üÀ¨£ºCVE-2022-29952ºÍCVE-2022-29953£¬£¬£¬£¬£¬Ó°ÏìJTEKT×°±¸µÄÎó²î°üÀ¨CVE-2022-29951ºÍCVE-2022-29958£¬£¬£¬£¬£¬Ó°ÏìSiemens×°±¸µÄÎó²î°üÀ¨CVE-2022-33139£¬£¬£¬£¬£¬Ó°ÏìEmerson×°±¸µÄÎó²î°üÀ¨CVE-2022-29957ºÍCVE-2022-29962µÈ15¸öÎó²î¡£¡£¡£¡£
ÊÜOT:ICEFALLÎó²îÓ°ÏìµÄ²úÆ·ÆÕ±éÓ¦ÓÃÓÚʯÓͺÍ×ÔÈ»Æø¡¢»¯¹¤¡¢ºËÄÜ¡¢·¢µçºÍÅäµç¡¢ÖÆÔ졢ˮ´¦Öóͷ£ºÍ·ÖÅÉ¡¢²É¿óºÍÐÞ½¨×Ô¶¯»¯µÈÒªº¦»ù´¡ÉèÊ©ÐÐÒµ£¬£¬£¬£¬£¬ÀÄÓÃÕâЩÎó²î¿ÉÄÜÔì³ÉÔÖÄÑÐÔЧ¹û¡£¡£¡£¡£
ºÃ±È£¬£¬£¬£¬£¬½üÆÚÕë¶ÔÒªº¦»ù´¡ÉèÊ©£¨ÈçIndustroyer2¡¢TritonºÍINCONTROLLERµÈ£©µÄ¶ñÒâÈí¼þµÄÉú³¤Åú×¢£¬£¬£¬£¬£¬ÍþвÕßÒѾÒâʶµ½OT×°±¸µÄ²»Çå¾²Éè¼ÆÈ±ÏÝ£¬£¬£¬£¬£¬²¢ÊÔͼͨ¹ýʹÓÃÕâЩÎÊÌâÀ´Ôì³ÉÑÏÖØÆÆË𡣡£¡£¡£
Ó°Ïì¹æÄ£
ÊÜÓ°ÏìÖÆÔìÉÌ | Ä£×Ó | ×°±¸ÀàÐÍ |
Bently Nevada | 3700, TDI equipment | ״̬¼àÊÓÆ÷ |
Emerson | DeltaV | ÂþÑÜʽ¿ØÖÆÏµÍ³ |
Emerson | Ovation | ÂþÑÜʽ¿ØÖÆÏµÍ³ |
Emerson | OpenBSI | ¹¤³ÌÊÂÇéÕ¾ |
Emerson | ControlWave, BB 33xx, ROC | Ô¶³ÌÖն˵¥Î» |
Emerson | Fanuc, PACsystems | ¿É±à³ÌÂß¼¿ØÖÆÆ÷ |
Honeywell | Trend IQ* | Â¥Óî¿ØÖÆÆ÷ |
Honeywell | Safety Manager FSC | Çå¾²ÒDZíϵͳ |
Honeywell | Experion LX | ÂþÑÜʽ¿ØÖÆÏµÍ³ |
Honeywell | ControlEdge | Ô¶³ÌÖն˵¥Î» |
Honeywell | Saia Burgess PCD | ¿É±à³ÌÂß¼¿ØÖÆÆ÷ |
JTEKT | Toyopuc | ¿É±à³ÌÂß¼¿ØÖÆÆ÷ |
Motorola | MOSCAD, ACE IP gateway | Ô¶³ÌÖն˵¥Î» |
Motorola | MDLC | ÐÒé |
Motorola | ACE1000 | Ô¶³ÌÖն˵¥Î» |
Motorola | MOSCAD Toolbox STS | ¹¤³ÌÊÂÇéÕ¾ |
Omron | SYSMAC Cx series, Nx series | ¿É±à³ÌÂß¼¿ØÖÆÆ÷ |
Phoenix Contact | ProConOS | ÔËÐÐÂß¼ |
Siemens | WinCC OA | ¼à¿ØºÍÊý¾ÝÊÕÂÞ (SCADA) |
Yokogawa | STARDOM | ¿É±à³ÌÂß¼¿ØÖÆÆ÷ |
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ²¿·Ö¹©Ó¦ÉÌÒѾÐû²¼ÁËÊÜÓ°Ïì×°±¸µÄ¹Ì¼þ¸üУ¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÔڹ̼þ¸üпÉÓÃʱʵʱӦÓ㬣¬£¬£¬£¬¹©Ó¦ÉÌÉÐδÐû²¼¹Ì¼þ¸üеÄÓû§¿ÉÑ¡ÔñÓ¦ÓÃÒÔÏ»º½â²½·¥£º
l ·¢Ã÷ºÍÇåµãÍøÂçÖÐÒ×Êܹ¥»÷µÄ×°±¸£»£»£»£»£»£»£»
l ʵÑéÍøÂç·Ö¶Î¿ØÖÆ£¬£¬£¬£¬£¬ÒÔ¼õÈÝÒ×Êܹ¥»÷×°±¸µÄΣº¦£»£»£»£»£»£»£»
l Ó¦ÓÃ×°±¸¹©Ó¦ÉÌÐû²¼µÄ²¹¶¡;
l ¼à¿ØÍøÂçÁ÷Á¿ÖÐÊÇ·ñ±£´æÊÔͼʹÓÃÎó²îµÄ¶ñÒâÊý¾Ý°ü¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.forescout.com/blog/ot-icefall-56-vulnerabilities-caused-by-insecure-by-design-practices-in-ot/
https://www.forescout.com/resources/ot-icefall-report/
https://www.bleepingcomputer.com/news/security/icefall-56-flaws-impact-thousands-of-exposed-industrial-devices/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-06-22 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¿·¢k8¼ò½é
¿·¢k8½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¿·¢k8´óÏ㬣¬£¬£¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬¿·¢k8ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£
¹ØÓÚ¿·¢k8
¿·¢k8Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ