Ê©ÄÍµÂµçÆø²úÆ·¶à¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-12

Îó²î±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2018-7846 £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.3 £¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7849 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7843 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7844 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7848 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.9 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7842 £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7847 £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2018-7850 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º5.3
CVE±àºÅ£ºCVE-2018-7845 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7852 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7853 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7854 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7855 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7856 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-7857 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º7.5
CVE±àºÅ£ºCVE-2018-6806 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½£º6.5
CVE±àºÅ£ºCVE-2018-6807 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-6808 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10.0 £¬¹Ù·½£º7.5



Ó°Ïì°æ±¾



ÊÜÓ°ÏìµÄ°æ±¾


Modicon M580ËùÓа汾
Modicon M340ËùÓа汾
Modicon QuantumËùÓа汾

Modicon PremiumËùÓа汾



Îó²î¸ÅÊö



Schneider Electric Modicon M580µÈ¶¼ÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄ²úÆ·¡£Schneider Electric Modicon M580ÊÇÒ»¿î¿É±à³Ì×Ô¶¯»¯¿ØÖÆÆ÷¡£Schneider Electric Modicon PremiumÊÇÒ»¿îÓÃÓÚÀëÉ¢»òÀú³ÌÓ¦ÓõĴóÐͿɱà³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©¡£Schneider Electric Modicon QuantumÊÇÒ»¿îÓÃÓÚÀú³ÌÓ¦Óᢸ߿ÉÓÃÐÔºÍÇå¾²½â¾ö¼Æ»®µÄ´óÐͿɱà³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©¡£¶à¿îSchneider Electric²úÆ·Öб£´æÈçÏÂÎó²î£º


CVE-2018-7846

´ËÎó²îΪ¾Ü¾ø·þÎñÎó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸ÔÚ²»ÑéÖ¤·¢¼þÈËÕæÊµÐÔµÄÇéÐÎÏÂʹ»á»°ÎÞЧ £¬´Ó¶øµ¼ÖÂÕýµ±×°±¸¶Ï¿ªÅþÁ¬¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7849

´ËÎó²îΪ¾Ü¾ø·þÎñÎó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë¿É»Ö¸´µÄ¹ÊÕÏ״̬ £¬´Ó¶øµ¼ÖÂ×°±¸Õý³£Ö´ÐÐ×èÖ¹¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7843

´ËÎó²îΪ¾Ü¾ø·þÎñÎó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬ £¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7844

´ËÎó²îΪÐÅϢй¶Îó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸·µ»ØÄÚ´æ¿é £¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁÈ¡ £¬Ð´ÈëºÍ²¶»ñSNMPÉçÇø×Ö·û´®¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7848

´ËÎó²îΪÐÅϢй¶Îó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸·µ»Ø±à³ÌÕ½ÂԵĿé £¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁд £¬Ð´ÈëºÍÏÝÚåSNMPÉçÇø×Ö·û´®µÄй¶¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7842

´ËÎó²îΪ²»×¼È·ÈÏÖ¤Îó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÒÔÔÊÐí¹¥»÷Õßαװ³É¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§ £¬´Ó¶ø¿ÉÒÔÈÆ¹ýÉè±¹ØÁ¬ÄÃÜÂë±£»¤¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7847

´ËÎó²îΪδ¾­Éí·ÝÑéÖ¤µÄÎļþдÈëÎó²î¡£ÌØÖƵÄUMASÏÂÁîÐòÁпÉÄܻᵼÖÂ×°±¸ÁýÕÖÆä±à³ÌÕ½ÂÔ £¬´Ó¶ø±¬·¢ÖÖÖÖÓ°Ïì £¬°üÀ¨ÉèÖÃÐÞ¸Ä £¬ÔËÐÐÀú³ÌÖÐÖ¹ºÍDZÔڵĴúÂëÖ´ÐС£ ¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7850

Schneider Electric UnityProL±à³ÌÈí¼þµÄÕ½ÂÔ´«Ê书ЧÖб£´æ¿ÉʹÓõĶԲ»¿ÉÐÅÊäÈëÎó²îµÄÒÀÀµ¡£½«ÌØÖÆÕ½ÂÔ±à³Ìµ½Modicon M580¿É±à³Ì×Ô¶¯»¯¿ØÖÆÆ÷ £¬²¢Ê¹ÓÃUnityProL¶ÁÈ¡¸ÃÕ½ÂÔʱ £¬»áÏòÓû§ÏÔʾÓë×°±¸²î±ðµÄÉèÖá£Õâµ¼ÖÂUnityProLÓû§ÎÞ·¨Ñé֤װ±¸ÊÇ·ñ°´Ô¤ÆÚÔËÐС£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7845

´ËÎó²îΪÐÅϢй¶Îó²î¡£ÌØÖƵÄUMASÇëÇó¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡ £¬´Ó¶øµ¼ÖÂÃô¸ÐÐÅÏ¢µÄй¶¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7852

´ËÎó²îΪ¾Ü¾ø·þÎñÎó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬ £¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢ÕâЩÎó²î¡£


CVE-2018-7853

´ËÎó²îΪ¾Ü¾ø·þÎñÎó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬ £¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7854

´ËÎó²îΪ¾Ü¾ø·þÎñÎó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬ £¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7855

´ËÎó²îΪ¾Ü¾ø·þÎñÎó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬ £¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7856

´ËÎó²îΪ¾Ü¾ø·þÎñÎó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬ £¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-7857

´ËÎó²îΪ¾Ü¾ø·þÎñÎó²î¡£ÌØÖƵÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬ £¬µ¼ÖÂÓë×°±¸µÄÔ¶³ÌͨѶÍêÈ«×èÖ¹¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-6806

´ËÎó²îΪÐÅϢй¶Îó²î¡£ ÌØÖÆµÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸·µ»ØÄÚ´æ¿é £¬´Ó¶øµ¼ÖÂÃ÷ÎĶÁÈ¡ £¬Ð´ÈëºÍ²¶»ñSNMPÉçÇø×Ö·û´®¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-6807

¿É±à³ÌµÄ¾Ü¾ø·þÎñÎó²î±£´æÓÚSchneider Electric Modicon M580¿É±à³Ì×Ô¶¯»¯¿ØÖÆÆ÷µÄ¹Ì¼þ°æ±¾SV2.70µÄUMASдÈëϵͳλºÍ¿é¹¦Ð§ÖС£Ò»×éÌØÖÆµÄUMASÏÂÁî¿ÉÄܵ¼ÖÂ×°±¸½øÈë²»¿É»Ö¸´µÄ¹ÊÕÏ״̬ £¬´Ó¶øµ¼ÖÂ×°±¸Ô¶³ÌͨѶÍêÈ«×èÖ¹¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£


CVE-2018-6808

Schneider Electric Unity Pro±à³ÌÈí¼þPLCÄ£ÄâÆ÷µÄUMASÕ½ÂÔ±à³Ì¹¦Ð§Öб£´æ¿ÉʹÓõÄÔ¶³ÌÖ´ÐдúÂëÎó²î¡£·¢Ë͵½Èí¼þPLC·ÂÕæÆ÷µÄÌØÖÆUMASÏÂÁîÐòÁпÉÒÔµ¼ÖÂÐÞ¸ÄÕ½ÂÔ±à³Ì £¬´Ó¶øÔÚ·ÂÕæÆ÷Çл»µ½Æô¶¯Ä£Ê½Ê±Ö´ÐдúÂë¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÀ´´¥·¢´ËÎó²î¡£



Îó²îÑéÖ¤



ÔÝÎÞPOC/EXP¡£



ÐÞ¸´½¨Òé



¹Ù·½ÒÑÍÆ³ö¸üв¹¶¡ £¬Çëʵʱ¸üУºhttps://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-11+-+Modicon+Controller.pdf&p_Doc_Ref=SEVD-2019-134-11¡£



²Î¿¼Á´½Ó



https://blog.talosintelligence.com/2019/06/vulnerability-spotlight-multiple.html