Schneider IGSS Ô¶³Ì©¶´·ÖÎö
Ðû²¼Ê±¼ä 2022-04-15Ò»¡¢Ç°ÑÔ
½üÆÚ£¬¶«Éƽ̨ADLabÔÚ¹¤Òµ¿ØÖÆϵͳ©¶´¼à²âÖз¢ÏÖSchneiderÐû²¼Á˽»»¥Ê½Í¼ÐÎSCADAϵͳ£¨Interactive Graphical SCADA System£¬¼ò³ÆIGSS£©µÄ¸ßΣ©¶´Í¨¸æºÍ²¹¶¡£¬°üÂÞÓлº³åÇøÒç³öºÍĿ¼´©Ô½µÈ£¬NVDµÄÆÀ·Ö¸ß´ï9.8¡£ADLabÑо¿Ô±µÚһʱ¼ä¶ÔÆäÖеĸßΣ©¶´½øÐÐÁËÏêϸ·ÖÎöºÍʵ¼ÊÑéÖ¤£¬Í¬Ê±»¹·¢ÏÖÁËÒ»¸öеĸßΣ©¶´²¢ÐÖú³§É̽øÐÐÁËÐÞ¸´¡£
¶þ¡¢Â©¶´»ù±¾ÐÅÏ¢
ƾ¾ÝSchneiderµÄ©¶´Í¨¸æ£¬ÕâЩ©¶´µÄ»ù±¾ÐÅÏ¢ÈçÏ£º
´æÔÚ©¶´
CVE-2022-24312£¬Ä¿Â¼´©Ô½ CVE-2022-24311£¬Ä¿Â¼´©Ô½ CVE-2022-24310£¬»º³åÇøÒç³ö
´æÔÚ©¶´
CVE-2022-24324£¬»º³åÇøÒç³ö
Èý¡¢Â©¶´·ÖÎöÓëÑéÖ¤
3.1 CVE-2022-24311(24312)·ÖÎö
ÕâÁ½¸ö©¶´´æÔÚÓÚIGSS V15.0.0.22020 and prior°æ±¾£¬Æ䩶´ÃèÊöΪ£º¡°´æÔÚ¶ÔÊÜÏÞÖÆĿ¼·¾¶ÃûµÄ²»Í×ÏÞÖÆ£¬¿Éµ¼ÖÂͨ¹ýÔÚÎļþĩβÌí¼Ó»òÔÚÊý¾Ý·þÎñÆ÷ÉÏÏÂÎÄÖд´½¨ÐÂÎļþÀ´ÐÞ¸ÄÏÖÓÐÎļþ£¬µ±¹¥»÷Õßͨ¹ýÍøÂç·¢ËÍÌض¨Êý¾Ýʱ£¬¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐС±¡£
ͨ¹ý·ÖÎö£¬ÎÒÃÇ·¢ÏÖÕâÁ½¸ö©¶´Î»ÓÚsub_49FF20º¯Êý£¬¸Ãº¯ÊýµÄα´úÂëÈçÏ£º
¸ú½øsub_4A0C50º¯Êý£¬Î±´úÂëÈçÏÂËùʾ£º
¿ÉÒÔ¿´³ö£¬¸Ãº¯ÊýÄÚ²¿½øÐÐÁËһϵÁÐÎļþ²Ù×÷£¬µ«¶Ô´«Èë¸Ãº¯ÊýµÄ²ÎÊýûÓÐ×öÓÐЧµÄÄþ¾²¼ì²é£¬Òò´Ë¿ÉÒÔ±»²Ù¿ØÀ´ÏòSCADA·þÎñÆ÷дÈëÈÎÒâÎļþ¡£
ͬÀí£¬¸ú½øsub_4A0C50º¯Êý£¬Î±´úÂëÈçÏÂËùʾ£º
¿ÉÒÔ¿´³ö£¬¸Ãº¯ÊýµÄÄÚ²¿Í¬ÑùҲûÓжԴ«ÈëµÄ²ÎÊý½øÐÐÄþ¾²¼ì²é£¬Òò´ËÒ²¿ÉÒÔ±»²Ù¿ØÀ´ÏòSCADA·þÎñÆ÷дÈëÈÎÒâÎļþ¡£
ƾ¾ÝÉÏÊö·ÖÎöÎÒÃǽøÐÐÁËÑéÖ¤£¬ÀÖ³ÉÏòSCADA·þÎñÆ÷дÈëÈÎÒâÄÚÈݵÄÎļþ¡£
¶ÔÓÚÉÏÊöÁ½¸ö©¶´£¬Schneider¹Ù·½Ðû²¼Á˲¹¶¡£¬ÆäÐÞ¸´·½Ê½ÈçÏ£º
¾ßÌåÀ´½²£¬¡°Prepend file¡±ºÍ¡°Append file¡±·ÖÖ§ÔÚ½øÈë¾ßÌ幦Чº¯ÊýÇ°µ÷ÓÃÁËÌرðµÄsub_4A16F0º¯Êý¡£¸Ãº¯Êý´«ÈëÁ˲ÎÊý v6+72£¬´Ë²ÎÊý¶ÔÓ¦±»²Ù×÷ÎļþµÄÎļþ·¾¶Ãû¡£¸ú½ø¸Ãº¯Êý£¬Æäα´úÂëÈçÏ£º
¸Ãº¯Êý¶ÔÎļþ·¾¶Ãû½øÐÐÁËÏÞÖÆ£º(1)ÏÞÖÆ(v6+72)³¤¶È£¬¾ÞϸҪÂú×ã<=0x100£»(2)ÏÞÖÆ(v6+72)ÄÚÈÝ£¬²»ÄÜÓÐĿ¼´©Ô½µÄÌØÕ÷·û¡£Í¨¹ýÕâÖÖÏÞÖÆ£¬²¹¶¡·ÀÖ¹Á˶ñÒâÊý¾Ýµ¼ÖµÄÌøתĿ¼£¬°ÑÎļþ²Ù×÷ÏÞÖÆÔÚµ±Ç°Ä¿Â¼Ï¡£
3.2 CVE-2022-24310·ÖÎö
¸Ã©¶´´æÔÚÓÚIGSS V15.0.0.22020 and prior°æ±¾£¬Â©¶´µÄÃèÊöΪ£º¡°´æÔÚÕûÊýÒç³ö£¬µ±¹¥»÷Õß·¢ËͶàÌõ¾«ÐÄ×¼±¸µÄÏûϢʱ£¬¸Ã©¶´¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö£¬µ¼Ö¾ܾø·þÎñ²¢¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС±¡£
ͨ¹ý·ÖÎö£¬ÎÒÃÇ·¢ÏÖÕâ¸ö©¶´´æÔÚÓÚsub_49FA30º¯Êý£¬¸Ãº¯ÊýµÄα´úÂëÈçÏ£º
´ÓÉÏͼ¿ÉÒÔ¿´³ö£¬¸Ãº¯ÊýµÄÖ÷ÒªÂß¼ÊÇ£ºÊ×ÏÈ£¬Í¨¹ýrealloc¸ø*(this+48)µÄ¶ÑÔö¼Ó*(a1+0xBA)ÊýÖµµÄ´óС£»È»ºó£¬Ê¹ÓÃmemcpyÏò(*(v5 +52)+*(v5 + 48))¸³Öµ*(a2+0xBA)³¤¶ÈµÄ(a2+190)»º³åÇøÄÚÈÝ£¬¼´Ìî³äreallocзÖÅä³öµÄÄÚ´æ¿Õ¼ä¡£
¾¹ý·ÖÎö£¬ÎÒÃÇ·¢ÏÖ£ºÔÚ*(a2+ 0xBA)+*(this + 52)µÄ¼Ó·¨²Ù×÷ÖУ¬Á½¸ö²Ù×÷Êý¾ùΪÎÞ·ûºÅÀàÐÍ£¬ÇÒ*(a2+0xBA)¿É¿Ø¡£Òò´Ë£¬Í¨¹ý¿ØÖÆ*(a2+0xBA)µÄÖµ£¬¿ÉʹµÃ*(a2 + 0xBA)+*(this + 52)·¢ÉúÕûÊýÉÏÒ磬´Ó¶øµ¼ÖÂreallocÐÂÉêÇëÄÚ´æµÄÈÝÁ¿Ð¡ÓÚºóÐømemcpyµÄ²ÎÊý*(a2+0xBA)£¬ºóÐøÖ´ÐÐmemcpyÄڴ濽±´²Ù×÷ʱ¾Í»á´¥·¢¶ÑÒç³ö¡£
ƾ¾ÝÉÏÊö·ÖÎöÎÒÃǽøÐÐÁËÑéÖ¤£¬Àֳɴ¥·¢ÁËSCADA·þÎñÆ÷µÄ¶ÑÆÆ»µ¡£
¶ÔÓڸ鶴£¬Schneider¹Ù·½Ðû²¼Á˲¹¶¡£¬ÆäÐÞ¸´·½Ê½ÈçÏ£º
¾ßÌåÀ´½²£¬ÔÚ½øÐÐrealloc²Ù×÷Ö´ÐÐÇ°£¬ÏÈÅжÏ*(a2+0xBA)µÄÖµÊÇ·ñÔÚ[0,0xF42]µÄÇø¼ä·¶Î§ÄÚ£¬´Ó¶øÖÆÖ¹ÕûÊýÒç³ö¡£
3.3 CVE-2022-24324·ÖÎö
ÔÚ¶ÔIGSS V15.0.0.22073 and priorµÄ²¹¶¡·ÖÎöÖУ¬ADLabÑо¿Ô±»¹·¢ÏÖÁËÒ»¸öеĻº´æÇøÒç³ö©¶´¡£¸Ã©¶´¿ÉÒÔÔ¶³ÌÎÞÌõ¼þ´¥·¢£¬ADLab¼°Ê±³ÂËßÁ˳§É̲¢ÐÖú³§É̽øÐÐÁËÐÞ¸´£¬³§É̶Ը鶴µÄCVSS3ÆÀ·ÖΪÑÏÖØ¡£
SchneiderÒѾÐû²¼ÁËв¹¶¡À´ÐÞ¸´Õâ¸ö¸ßΣ©¶´¡£Ïà¹Ø²¹¶¡ºÍ¸ü¶àµÄÄÚÈÝ¿ÉÔÚ¹Ù·½ÌṩµÄͨ¸æÖвéѯ£º
https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-102-01_IGSS_Security_Notification.pdf&p_Doc_Ref=SEVD-2022-102-01
ËÄ¡¢ÐÞ¸´½¨Òé
¾¹ýADLabÑо¿Ô±µÄ·ÖÎöºÍÑéÖ¤£¬ÉÏÊö¸ßΣ©¶´¶¼¿ÉÒÔͨ¹ýÍøÂç½øÐÐÎÞÌõ¼þµÄÔ¶³Ì´¥·¢£¬¾ßÓкܴóµÄΣº¦ÐÔ¡£Ä¿Ç°¹Ù·½ÒѾÐû²¼Á˲¹¶¡£¬Ç¿ÁÒ½¨ÒéʹÓÃIGGSµÄ¹¤ÒµÓû§Á¢¼´Éý¼¶µ½×îа汾£º15.0.0.22074¡£
Õë¶Ô¹¤Òµ¿ØÖÆϵͳ£¬CISAÌṩÁËÈçϵÄͨÓý¨Ò飺
¾¡Á¿¼õÉÙÔÚ¹«Íø̻¶¹¤¿ØÉ豸»òÕßϵͳ£» ½«¿ØÖÆϵͳÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬²¢ºÍ°ì¹«ÍøÂç¸ôÀ룻 µ±ÐèÒªÔ¶³Ì·ÃÎÊʱ£¬½ÓÄÉÀàËÆVPNµÄÄþ¾²·ÃÎÊ·½Ê½¡£
²Î¿¼Á´½Ó£º