Î÷ÃÅ×Ó²úÆ·¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-08-15

Îó²î±àºÅºÍ¼¶±ð


CVE-2018-11453£¬ £¬£¬¸ßΣ£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ7.8£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨

CVE-2018-11454£¬ £¬£¬¸ßΣ£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.6£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


SIMATIC STEP 7 and WinCC  (TIA Portal)  V10, V11,V12, V13 all versions
SIMATIC STEP 7 and WinCC (TIA Portal) V14 versions < V14 SP1 Update6

SIMATIC STEP 7 and WinCC (TIA Portal) V15 versions < V15 Update 2


Îó²î¸ÅÊö


Î÷ÃÅ×ÓÐû²¼¹Ù·½Í¨¸æ³ÆÆäSIMATIC STEP7ºÍWinCC²úÆ·ÖÐʹÓõÄTIA Portal(Totally Integrated Automation Portal)Èí¼þ±£´æÁ½¸ö¸ßΣÎó²î£¨CVE-2018-11453£¬ £¬£¬CVE-2018-11454£©£¬ £¬£¬Ó°Ïì¸Ã2¿î²úÆ·µÄ¶à¸ö°æ±¾¡£¡£


CVE-2018-11453£¬ £¬£¬ÔÚTIA PortalµÄĬÈÏ×°ÖÃÖУ¬ £¬£¬²»×¼È·µÄÎļþȨÏÞ¿ÉÄÜÔÊÐí¾ßÓÐÍâµØÎļþϵͳ»á¼ûȨÏ޵Ĺ¥»÷Õß×¢Èë¶ñÒâµÄÎļþ£¬ £¬£¬ÒÔ´Ë×èÖ¹TIA PortalÆô¶¯£¨¾Ü¾øÐ§ÀÍ£©»òµ¼ÖÂÍâµØ´úÂëÖ´ÐС£¡£ ¸ÃÎó²î²»ÐèÒªÌØÊâȨÏÞ£¬ £¬£¬µ«Êܺ¦ÕßÐèÒªÔÚ²Ù×÷ºóʵÑéÆô¶¯TIA Portal¡£¡£


CVE-2018-11453£¬ £¬£¬ÔÚTIA PortalµÄĬÈÏ×°ÖÃÖУ¬ £¬£¬²»×¼È·µÄÎļþȨÏÞ¿ÉÄÜÔÊÐí¾ßÓÐÍâµØÎļþϵͳ»á¼ûȨÏ޵Ĺ¥»÷ÕßʹÓñ¾¸ÃÊÇÓÉÆäËûÓû§ÔÚ×°±¸ÉÏÖ´ÐеÄ×ÊÔ´¡£¡£¸ÃÎó²î²»ÐèÒªÌØÊâȨÏÞ£¬ £¬£¬µ«Êܺ¦ÕßÐèÒª½«Ê¹ÓõÄÎļþ´«Êäµ½×°±¸£¬ £¬£¬×îÖÕÖ´ÐÐÊÇÔÚÄ¿µÄ×°±¸É϶ø²»ÊÇÔÚPG×°±¸ÉÏ¡£¡£


ÐÞ¸´½¨Òé


SIMATIC STEP 7 and WinCC (TIA Portal) V10¡¢11¡¢12¡¢13£¬ £¬£¬Çë½ÓÄÉÒÔϹæ±Ü²½·¥£º


1.È·±£½öÓÐÊÚȨµÄÖ°Ô±¿ÉÒÔ½Ó´¥µ½²Ù×÷ϵͳ


2.ÑéÖ¤GCDÎļþµÄÕýµ±ÐÔ²¢ÇÒ½ö´¦Öóͷ£ÊÜÐÅÈÎȪԴµÄGSDÎļþ


SIMATIC STEP 7 and WinCC (TIA Portal) V14Óû§ÇëÉý¼¶ÖÁV14 SP1 Update 6¾ÙÐзÀ»¤£¬ £¬£¬ÏÂÔØµØµã£º

https://support.industry.siemens.com/cs/ww/en/view/109747387


SIMATIC STEP 7 and WinCC (TIA Portal) V15Óû§ÇëÉý¼¶ÖÁV15 Update 2»ò¸ü¸ß°æ±¾¾ÙÐзÀ»¤£¬ £¬£¬ÏÂÔØµØµã£º

https://support.industry.siemens.com/cs/ww/en/view/109755826


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-226-01