AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

Siemens ¶à¸ö²úÆ·Îó²î ÍþвԤ¾¯Í¨¸æ

2018-09-14

Ðû²¼ÕߣºAG¹«Ë¾¿Æ¼¼

×ÛÊö

   ÍâµØÊ±¼ä9ÔÂ11ÈÕ£¬Î÷ÃÅ×Ó¹Ù·½Ðû²¼Í¨¸æÐÞ¸´ÁËÆä¶à¿î²úÆ·Öвî±ðˮƽµÄÇå¾²Îó²î£¬ÊÜÓ°Ïì²úÆ·°üÀ¨SIMATIC WinCC OA¡¢SCALANCE X½»Á÷»úµÈ ¡£

¹Ù·½Í¨¸æ£º

https://www.siemens.com/global/en/home/products/services/cert.html#SecurityPublications


Îó²î¸ÅÊö

SIMATIC WinCC OA

Ó°ÏìSIMATIC WinCC OAµÄÎó²îCVE-2018-13799ÊÇÓÉÓÚ5678/TCP¶Ë¿ÚµÄ»á¼û¿ØÖƲ»µ±¶ø±¬·¢£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚSIMATIC WinCC OAÇéÐÎÖÐÌáÉýÆäȨÏÞ ¡£

CVSS v3.0 Base Score 9.1

CVSS:3.0/AV£ºN/AC£ºL/PR£ºN/UI£ºN/S£ºU/C£ºN/I£ºH/A£ºH

l  ÊÜÓ°Ïì°æ±¾: SIMATIC WinCC OA Version <= 3.14

l  ²»ÊÜÓ°Ïì°æ±¾: SIMATIC WinCC OA Version 3.14-P021


½â¾ö¼Æ»®

Î÷ÃÅ×Ó¹Ù·½ÒѾ­Ðû²¼ÁËÏà¹Ø²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬¿É´ÓÒÔÏÂÁ´½Ó»ñµÃ£º

https://portal.etm.at/index.php?option=com_content&view=category&id=67&layout=blog&Itemid=80£¨ÒªÇóµÇ¼£©

Î÷ÃÅ×Ó»¹½¨Òé½ÓÄÉÒÔÏÂÊÖ¶¯»º½â²½·¥À´½µµÍΣº¦£º

l  ƾ֤ÒÔÏÂÁ´½ÓÖеİ취ÊÖ¶¯ÐÞ¸´Îó²î£º

https://portal.etm.at/patchdownload.php?fp=version_3.14/win64vc12/ReadmeP021.txt£¨ÒªÇóµÇ¼£©

l  ×ñÕÕSIMATIC WinCC OAÇå¾²Ö¸ÄÏÒÔά»¤Çå¾²µÄSIMATIC WinCC OAÇéÐΣº

https://portal.etm.at/index.php?option=com_phocadownload&view=category&id=52:security&Itemid=81£¨ÒªÇóµÇ¼£©

l  Ó¦ÓÃÉî¶È·ÀÓù£º 

https://www.siemens.com/cert/operational-guidelines-industrial-security

¸ü¶àÐÅÏ¢£¬Çë²ÎÔÄÒÔÏÂÎ÷ÃÅ×ÓÇå¾²×ÉѯSSA-346256£º

http://www.siemens.com/cert/advisories


SCALANCE X½»Á÷»ú

Ó°Ïì¶à¸ö°æ±¾SCALANCE X½»Á÷»úµÄÎó²îCVE-2018-13807¿ÉÄÜÔÊÐí¹¥»÷Õßͨ¹ýÏòWeb·þÎñÆ÷·¢ËÍÌØÖÆÊý¾Ý°üÀ´µ¼Ö¾ܾø·þÎñ ¡£Ê¹×°±¸×Ô¶¯ÖØÆô£¬Ó°ÏìÆäËû×°±¸µÄÍøÂç¿ÉÓÃÐÔ ¡£²»¹ý¹¥»÷Õß±ØÐè¾ßÓжÔ443/TCP¶Ë¿ÚµÄÍøÂç»á¼ûÄÜÁ¦²Å»ªÊ¹ÓôËÎó²î£¬Ê¹ÓôËÎó²î¼È²»ÐèÒªÓÐÓÃÆ¾Ö¤Ò²²»ÐèÒªÕýµ±Óû§µÄ½»»¥ ¡£

CVSS v3.0 Base Score 8.6

CVSS:3.0/AV£ºN/AC£ºL/PR£ºN/UI£ºN/S£ºC/C£ºN/I£ºN/A£ºH

l  ÊÜÓ°Ïì°æ±¾:

SCALANCE X300 Version < 4.0.0

SCALANCE X408 Version < 4.0.0

SCALANCE X414ËùÓа汾

l  ²»ÊÜÓ°Ïì°æ±¾:

SCALANCE X300 Version 4.1.2

SCALANCE X408 Version 4.1.2

SCALANCE X414Çë²ÎÔĽâ¾ö¼Æ»®

½â¾ö¼Æ»®

Î÷ÃÅ×ÓΪSCALANCE X300ºÍSCALANCE X408Ìṩ¸üУ¬²¢ÎªSCALANCE X414Ìṩ»º½â²½·¥ ¡£

SCALANCE X300£º¸üÐÂÖÁ4.1.2°æ

https://support.industry.siemens.com/cs/us/en/view/109753720

SCALANCE X408£º¸üÐÂÖÁ4.1.2°æ

https://support.industry.siemens.com/cs/us/en/view/109753720

SCALANCE X414£º

Î÷ÃÅ×ÓÒÑÈ·¶¨Óû§¿ÉÒÔÓ¦ÓÃÒÔϽâ¾ö¼Æ»®»ººÍ½â²½·¥½µµÍΣº¦£º

l  ʹÓÃÊʵ±µÄ»úÖÆ±£»¤¶Ô443/TCP¶Ë¿ÚÉϼ¯³ÉµÄWeb·þÎñÆ÷µÄÍøÂç»á¼û ¡£

l  ½«443/TCP¶Ë¿ÚµÄÍøÂç»á¼ûÏÞÖÆÔÚ¿ÉÐÅIPµØµãÄÚ£¬²¢×èÖ¹ÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÔËÐÐÀ´×Ô¿ÉÐÅIPµØµãµÄÎó²îɨÃ蹤¾ß ¡£

²Î¿¼Á´½Ó£º

https://ics-cert.us-cert.gov/advisories/ICSA-18-254-05


Éù Ã÷

±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí ¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈÎ ¡£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ ¡£Î´¾­AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ ¡£


¹ØÓÚAG¹«Ë¾¿Æ¼¼

±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾© ¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐÐ ¡£

»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ ¡£

±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊÐÉúÒ⣬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369 ¡£



?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼