ÈýÁâHMI¹¤¾ßE-DesignerÔ¶³ÌÖ´ÐдúÂë ÊÖÒÕÆÊÎöÓë·À»¤¼Æ»®
2017-09-01
×ÛÊö
ÃÀ¹ú¹¤Òµ¿ØÖÆÏµÍ³ÍøÂçÓ¦¼±ÏìӦС×飨ICS-CERT£©Ð¯ÊÖÇ÷ÊÆ¿Æ¼¼£¨Trend Micro¹«Ë¾£©µÄÁãÈÕÍýÏ루¼ò³ÆZDI£©Åû¶Á˶àÏî¶ÔÈýÁâµç»úE-DesignerÒýÇæ£¨E-Designer ÊÇÓÃÓÚ¸ø E1000 ÈË»ú½çÃæ£¨HMI£©±à³ÌµÄ¹¤¾ß£©±¬·¢Ó°ÏìµÄ¶àÏî¸ßΣÇå¾²Îó²î¡£
Èí¼þ¼ò½é
E-DesignerÊÇBeijer¹«Ë¾ÎªÈýÁ⿪·¢£¬ÓÃÀ´±àдE1000ϵÁÐÈË»ú½çÃæµÄÈí¼þ¡£E-Designer×é̬Èí¼þµÄ¹¤³ÌÎļþÒÔºó׺ÃûΪ.mpaµÄÎı¾Îļþ´æ´¢£¬¸ÃÎı¾Îļþ´æ´¢Á˹¤³ÌµÄÏêϸ²ÎÊýÐÅÏ¢£¬ÈçPLCÐͺš¢Çý¶¯ÐÅÏ¢µÈ£¨Í¼2.1£©¡£
ͼ2.1 E-Designer×é̬½çÃæÒÔ¼°¹¤³ÌÎļþ
ÊÜÓ°Ïì°æ±¾
l ÈýÁâµçÆøE-Designer 7.52µÄËùÓа汾¡£
Îó²îÆÊÎö
E-Designer×é̬Èí¼þµÄ¹¤³ÌÎļþ´æ´¢Á˹¤³ÌÏîÄ¿µÄÉèÖÃÒÔ¼°ÏêϸÐÅÏ¢¡£¹¤³ÌÎļþµÄÆðʼ´¦Îª[Project]£¬°üÀ¨Á˹¤³ÌÎļþ½¨ÉèµÄʱ¼ä¡¢×î½üÐ޸ĵÄʱ¼ä¡¢PLC×°±¸ÐÅÏ¢¡¢Í¨Ñ¶ÐÒéÐÅÏ¢µÈ¡£[Project]ºóΪһЩ[FontMapTable]¡¢[Drivers]¡¢[Setup]µÈ×ÓÏî²ÎÊý¡£Ã¿Ò»¸ö×ÓÏî²ÎÊýÓÖ°üÀ¨Á˸ü¶àµÄ×ÓÏî²ÎÊý¡£ÀýÈç[Setup]×ÓÏî°üÀ¨ÁË[SetupIndex]¡¢[SetupSystemSignals]¡¢[SetupClock]µÈ£¬Èçͼ4.1Ëùʾ£º
ͼ4.1 E-Designer¹¤³ÌÎļþ
Ed.exe×é̬³ÌÐò·¿ª¹¤³Ìʱ£¬ÐèÒª¼ÓÔØ.mpa¹¤³ÌÎļþ¡£¸Ã×é̬³ÌÐòÔÚ¼ÓÔØÌØ¶¨µÄÒì³£.mpa¹¤³ÌÎļþʱ£¬±£´æ¶ÑÒç³öÎó²î¡£
.mpa¹¤³ÌÎļþÖÐ[Setup]Ñ¡ÏîµÄ[SetupAlarm]×ÓÑ¡ÏîÖÐÓÐÒ»²ÎÊýÏîΪFont£¬ÔÚed.exeÖÐʹÓÃCº¯Êý¿âµÄsscanf()º¯Êý¾ÙÐмÓÔØ£¬Æä²ÎÊýÃûÌÃÈçÏ£º
"%[A-Za-z]%ux%u%u%u%u%u"
%uÌåÏÖÎÞ·ûºÅÕûÐÎÊý£¬%[A-Za-z]Ϊ³¤¶ÈΪ100¸ö×Ö½ÚµÄ×Ö·û´®¡£
ÈôÊÇ.mpa¹¤³ÌÎļþ±£´æ[SetupAlarm]×ÓÑ¡Ï²¢ÇÒFontÖµµÄ×Ö·û´®Áè¼Ý100×Ö½Ú£¨Í¼4.2Ëùʾ£©£¬»á´¥·¢¶ÑÒç³öÎó²î¡£
ͼ4.2 Òì³£¹¤³ÌÎļþ
ʹÓõ÷ÊÔÈí¼þ¾ÙÐÐÆÊÎö£¬µ±ed.exe³ÌÐò¼ÓÔØÒì³£¹¤³Ì×é̬Îļþʱ£¬»á½«.mpaÎļþÖÐFontµÄÖµÔØÈ룬×îÖÕÔì³É¶ÑÒç³ö£¬Èçͼ4.3Ëùʾ
ͼ4.3 ¼ÓÔØÒì³£¹¤³ÌÎļþÔì³É¶ÑÒç³ö
Îó²îʹÓÃ
A. ʹÓÃÌõ¼þ
±»¹¥»÷Õß×°ÖÃÓÐE-Designer 7.52°æ±¾Èí¼þ¡£
¹¥»÷ÕßÐèÒª½«Òì³£µÄ×é̬ÎļþÖ²Èëµ½±»¹¥»÷ÕßµÄÅÌËã»úÖС£
B. Ö²ÈëÒªÁì
¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄÖ÷»ú·¢ËÍÖ²ÈëÒì³£×é̬ÎļþµÄÊý¾Ý°üʵÏÖ¡£Êý¾Ý°üÈçͼ5.1Ëùʾ
C. Îó²îʹÓÃÓ°Ïì
l ÀÖ³ÉʹÓøÃÎó²î£¬¿ÉʵÏÖÌáȨִÐдúÂë¡£
l δÀÖ³ÉʹÓøÃÎó²î£¬¿ÉʵÏÖ¸ÃÈí¼þµÄ¾Ü¾ø·þÎñ¡£
¼ì²âÓë·À»¤¼Æ»®
A. ¼ì²âÓë·À»¤
l ͨ¹ýÍøÂç¼à¿ØÈí¼þ£¬¼ì²âÍøÂçÖÐÊÇ·ñ±£´æ°üÀ¨Òì³£×é̬ÎļþµÄ¹¥»÷Êý¾Ý°ü--ƾ֤Òì³£×é̬ÎļþÌØÕ÷£¬¼ì²âÍøÂçÖÐÊÇ·ñÓÐÏòÖ÷»ú·¢ËÍ.mpaÎļþ¡£²¢ÇÒ¼ì²âÎļþÄÚÈÝÖеÄ[SetupAlarm]×ÓÏîÖеÄFont²ÎÊýÖµÊÇ·ñÁè¼Ý100×Ö½Ú£¨Í¼5.1£©¡£
l ʹÓÃÎó²îɨÃ蹤¾ß¼ì²âÅÌËã»úÖÐE-DesignerÈí¼þ
1) ¼ì²âÈí¼þ°æ±¾ÊÇ·ñΪ7.52£¨Í¼6.1£©
ͼ6.1 E-Designer×é̬Èí¼þ°æ±¾¼ì²é
2) ƾ֤Òì³£×é̬ÎļþÌØÕ÷£¬¼ì²âÅÌËã»úÖÐE-DesignerµÄ.mpa¹¤³Ì×é̬ÎļþÊÇ·ñ±£´æÒì³£Ïî¡£
B. ¹æ±Ü¼Æ»®
l ·¿ª×é̬¹¤³ÌʱÐè¼ì²é¸Ã×é̬¹¤³ÌÎļþÊÇ·ñ±£´æÒì³£¡£
l Éý¼¶Èí¼þµ½¸ü¸ß°æ±¾ÒÔ¹æ±Ü¸ÃÎó²î¡£
C. ²úÆ·¼Æ»®
l ʹÓÃAG¹«Ë¾¿Æ¼¼¹¤¿ØÎó²îɨÃèϵͳ£¨ICSScan£©¾ÙÐÐÔ¶³ÌÇå¾²ÆÀ¹À¡£
l ʹÓÃAG¹«Ë¾¿Æ¼¼·À»¤Àà×°±¸£¨IPS/NF£©¾ÙÐÐÇå¾²·À»¤¡£
l ʹÓÃAG¹«Ë¾¿Æ¼¼Çå¾²Éó¼ÆÏµÍ³¾ÙÐÐʵʱÇå¾²¼à¿Ø¡£
²Î¿¼Á´½Ó
https://ics-cert.us-cert.gov/advisories/ICSA-17-213-01
TSL20170802-09 Vulnerability Report (Mitsubishi Electric E-Designer SetupAlarm Font Stack Buffer Overflow).pdf
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ





