CVE-2020-10607| Advantech WebAccess»º³åÇøÒç³öÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-22

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-10607

ʱ   ¼ä

2020-04-22

Àà    ÐÍ

BO

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Advantech WebAccess <=8.4.2




0x01 Îó²îÏêÇé


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø




Advantech WebAccessÊÇÖйų́ÍåÑлª£¨Advantech£©¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¡£¡£¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý¿ØÖÆ£¬ £¬£¬²¢ÌṩԶ³Ì¿ØÖƺÍÖÎÀí×Ô¶¯»¯×°±¸µÄ¹¦Ð§¡£¡£¡£¡£

Advantech WebAccess 8.4.2¼°Ö®Ç°°æ±¾Öб£´æ»º³åÇøÒç³öÎó²î£¬ £¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷУÑéÓû§Ìá½»Êý¾ÝµÄ³¤¶È¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐдúÂë¡£¡£¡£¡£CVSSÆÀ·Ö8.8¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬ £¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.advantech.com.cn/

±ðµÄ£¬ £¬£¬½¨ÒéÏà¹ØÓû§Ó¦½ÓÄɵįäËûÇå¾²·À»¤²½·¥ÈçÏ£º

£¨1£© ×î´óÏ޶ȵØïÔÌ­ËùÓпØÖÆÏµÍ³×°±¸ºÍ/»òϵͳµÄÍøÂç̻¶£¬ £¬£¬²¢È·±£ÎÞ·¨´ÓInternet»á¼û£»£»£»£»

£¨2£© ¶¨Î»·À»ðǽ·À»¤µÄ¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸£¬ £¬£¬²¢½«ÆäÓëÓªÒµÍøÂç¸ôÀ룻£»£»£»

£¨3£© µ±ÐèÒªÔ¶³Ì»á¼ûʱ£¬ £¬£¬ÇëʹÓÃÇå¾²ÒªÁ죬 £¬£¬ÀýÈçÐéÄâרÓÃÍøÂ磨VPN£©£¬ £¬£¬²¢È·ÈÏVPN¿ÉÄܱ£´æµÄÎó²î£¬ £¬£¬Ð轫VPN¸üе½×îа汾¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://www.auscert.org.au/bulletins/ESB-2020.1084/


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-086-01

https://nvd.nist.gov/vuln/detail/CVE-2020-10607

https://www.cnvd.org.cn/flaw/show/CNVD-2020-19926


0x05 ʱ¼äÏß


2020-03-26 CVEÐû²¼¸ÃÎó²î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø