Schneider IGSS Ô¶³Ì©¶´·ÖÎö

Ðû²¼Ê±¼ä 2022-04-15

Ò»¡¢Ç°ÑÔ


½üÆÚ £¬¶«É­Æ½Ì¨ADLabÔÚ¹¤Òµ¿ØÖÆϵͳ©¶´¼à²âÖз¢ÏÖSchneiderÐû²¼Á˽»»¥Ê½Í¼ÐÎSCADAϵͳ£¨Interactive Graphical SCADA System £¬¼ò³ÆIGSS£©µÄ¸ßΣ©¶´Í¨¸æºÍ²¹¶¡ £¬°üÂÞÓлº³åÇøÒç³öºÍĿ¼´©Ô½µÈ £¬NVDµÄÆÀ·Ö¸ß´ï9.8¡£ADLabÑо¿Ô±µÚһʱ¼ä¶ÔÆäÖеĸßΣ©¶´½øÐÐÁËÏêϸ·ÖÎöºÍʵ¼ÊÑéÖ¤ £¬Í¬Ê±»¹·¢ÏÖÁËÒ»¸öеĸßΣ©¶´²¢Ð­Öú³§É̽øÐÐÁËÐÞ¸´¡£


¶þ¡¢Â©¶´»ù±¾ÐÅÏ¢



ƾ¾ÝSchneiderµÄ©¶´Í¨¸æ £¬ÕâЩ©¶´µÄ»ù±¾ÐÅÏ¢ÈçÏ£º



ÊÜÓ°ÏìµÄ²úÎV15.0.0.22020 and prior

´æÔÚ©¶´

  • CVE-2022-24312 £¬Ä¿Â¼´©Ô½
  • CVE-2022-24311 £¬Ä¿Â¼´©Ô½
  • CVE-2022-24310 £¬»º³åÇøÒç³ö


ÊÜÓ°ÏìµÄ²úÎV15.0.0.22073 and prior

´æÔÚ©¶´


  • CVE-2022-24324 £¬»º³åÇøÒç³ö



´¥·¢·½Ê½£ºÍøÂç
CVSS v3ÆÀ·Ö:  9.8

Èý¡¢Â©¶´·ÖÎöÓëÑéÖ¤


3.1 CVE-2022-24311(24312)·ÖÎö


ÕâÁ½¸ö©¶´´æÔÚÓÚIGSS V15.0.0.22020 and prior°æ±¾ £¬Æ䩶´ÃèÊöΪ£º¡°´æÔÚ¶ÔÊÜÏÞÖÆĿ¼·¾¶ÃûµÄ²»Í×ÏÞÖÆ £¬¿Éµ¼ÖÂͨ¹ýÔÚÎļþĩβÌí¼Ó»òÔÚÊý¾Ý·þÎñÆ÷ÉÏÏÂÎÄÖд´½¨ÐÂÎļþÀ´ÐÞ¸ÄÏÖÓÐÎļþ £¬µ±¹¥»÷Õßͨ¹ýÍøÂç·¢ËÍÌض¨Êý¾Ýʱ £¬¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐС±¡£


ͨ¹ý·ÖÎö £¬ÎÒÃÇ·¢ÏÖÕâÁ½¸ö©¶´Î»ÓÚsub_49FF20º¯Êý £¬¸Ãº¯ÊýµÄα´úÂëÈçÏ£º


ͼƬ1.png


¸ú½øsub_4A0C50º¯Êý £¬Î±´úÂëÈçÏÂËùʾ£º


ͼƬ2.png



¿ÉÒÔ¿´³ö £¬¸Ãº¯ÊýÄÚ²¿½øÐÐÁËһϵÁÐÎļþ²Ù×÷ £¬µ«¶Ô´«Èë¸Ãº¯ÊýµÄ²ÎÊýûÓÐ×öÓÐЧµÄÄþ¾²¼ì²é £¬Òò´Ë¿ÉÒÔ±»²Ù¿ØÀ´ÏòSCADA·þÎñÆ÷дÈëÈÎÒâÎļþ¡£


ͬÀí £¬¸ú½øsub_4A0C50º¯Êý £¬Î±´úÂëÈçÏÂËùʾ£º


ͼƬ3.png



¿ÉÒÔ¿´³ö £¬¸Ãº¯ÊýµÄÄÚ²¿Í¬ÑùҲûÓжԴ«ÈëµÄ²ÎÊý½øÐÐÄþ¾²¼ì²é £¬Òò´ËÒ²¿ÉÒÔ±»²Ù¿ØÀ´ÏòSCADA·þÎñÆ÷дÈëÈÎÒâÎļþ¡£


ƾ¾ÝÉÏÊö·ÖÎöÎÒÃǽøÐÐÁËÑéÖ¤ £¬ÀÖ³ÉÏòSCADA·þÎñÆ÷дÈëÈÎÒâÄÚÈݵÄÎļþ¡£


ͼƬ4.png


¶ÔÓÚÉÏÊöÁ½¸ö©¶´ £¬Schneider¹Ù·½Ðû²¼Á˲¹¶¡ £¬ÆäÐÞ¸´·½Ê½ÈçÏ£º


ͼƬ5.png


¾ßÌåÀ´½² £¬¡°Prepend file¡±ºÍ¡°Append file¡±·ÖÖ§ÔÚ½øÈë¾ßÌ幦Чº¯ÊýÇ°µ÷ÓÃÁËÌرðµÄsub_4A16F0º¯Êý¡£¸Ãº¯Êý´«ÈëÁ˲ÎÊý v6+72 £¬´Ë²ÎÊý¶ÔÓ¦±»²Ù×÷ÎļþµÄÎļþ·¾¶Ãû¡£¸ú½ø¸Ãº¯Êý £¬Æäα´úÂëÈçÏ£º


ͼƬ6.png


¸Ãº¯Êý¶ÔÎļþ·¾¶Ãû½øÐÐÁËÏÞÖÆ£º(1)ÏÞÖÆ(v6+72)³¤¶È £¬¾ÞϸҪÂú×ã<=0x100£»(2)ÏÞÖÆ(v6+72)ÄÚÈÝ £¬²»ÄÜÓÐĿ¼´©Ô½µÄÌØÕ÷·û¡£Í¨¹ýÕâÖÖÏÞÖÆ £¬²¹¶¡·ÀÖ¹Á˶ñÒâÊý¾Ýµ¼ÖµÄÌøתĿ¼ £¬°ÑÎļþ²Ù×÷ÏÞÖÆÔÚµ±Ç°Ä¿Â¼Ï¡£


3.2 CVE-2022-24310·ÖÎö


¸Ã©¶´´æÔÚÓÚIGSS V15.0.0.22020 and prior°æ±¾ £¬Â©¶´µÄÃèÊöΪ£º¡°´æÔÚÕûÊýÒç³ö £¬µ±¹¥»÷Õß·¢ËͶàÌõ¾«ÐÄ×¼±¸µÄÏûϢʱ £¬¸Ã©¶´¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö £¬µ¼Ö¾ܾø·þÎñ²¢¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС±¡£

ͨ¹ý·ÖÎö £¬ÎÒÃÇ·¢ÏÖÕâ¸ö©¶´´æÔÚÓÚsub_49FA30º¯Êý £¬¸Ãº¯ÊýµÄα´úÂëÈçÏ£º


ͼƬ7.png


´ÓÉÏͼ¿ÉÒÔ¿´³ö £¬¸Ãº¯ÊýµÄÖ÷ÒªÂß¼­ÊÇ£ºÊ×ÏÈ £¬Í¨¹ýrealloc¸ø*(this+48)µÄ¶ÑÔö¼Ó*(a1+0xBA)ÊýÖµµÄ´óС£»È»ºó £¬Ê¹ÓÃmemcpyÏò(*(v5 +52)+*(v5 + 48))¸³Öµ*(a2+0xBA)³¤¶ÈµÄ(a2+190)»º³åÇøÄÚÈÝ £¬¼´Ìî³äreallocзÖÅä³öµÄÄÚ´æ¿Õ¼ä¡£


¾­¹ý·ÖÎö £¬ÎÒÃÇ·¢ÏÖ£ºÔÚ*(a2+ 0xBA)+*(this + 52)µÄ¼Ó·¨²Ù×÷ÖÐ £¬Á½¸ö²Ù×÷Êý¾ùΪÎÞ·ûºÅÀàÐÍ £¬ÇÒ*(a2+0xBA)¿É¿Ø¡£Òò´Ë £¬Í¨¹ý¿ØÖÆ*(a2+0xBA)µÄÖµ £¬¿ÉʹµÃ*(a2 + 0xBA)+*(this + 52)·¢ÉúÕûÊýÉÏÒç £¬´Ó¶øµ¼ÖÂreallocÐÂÉêÇëÄÚ´æµÄÈÝÁ¿Ð¡ÓÚºóÐømemcpyµÄ²ÎÊý*(a2+0xBA) £¬ºóÐøÖ´ÐÐmemcpyÄڴ濽±´²Ù×÷ʱ¾Í»á´¥·¢¶ÑÒç³ö¡£


ƾ¾ÝÉÏÊö·ÖÎöÎÒÃǽøÐÐÁËÑéÖ¤ £¬Àֳɴ¥·¢ÁËSCADA·þÎñÆ÷µÄ¶ÑÆÆ»µ¡£


ͼƬ8.png

¶ÔÓڸ鶴 £¬Schneider¹Ù·½Ðû²¼Á˲¹¶¡ £¬ÆäÐÞ¸´·½Ê½ÈçÏ£º


ͼƬ9.png


¾ßÌåÀ´½² £¬ÔÚ½øÐÐrealloc²Ù×÷Ö´ÐÐÇ° £¬ÏÈÅжÏ*(a2+0xBA)µÄÖµÊÇ·ñÔÚ[0,0xF42]µÄÇø¼ä·¶Î§ÄÚ £¬´Ó¶øÖÆÖ¹ÕûÊýÒç³ö¡£


3.3 CVE-2022-24324·ÖÎö


ÔÚ¶ÔIGSS V15.0.0.22073 and priorµÄ²¹¶¡·ÖÎöÖÐ £¬ADLabÑо¿Ô±»¹·¢ÏÖÁËÒ»¸öеĻº´æÇøÒç³ö©¶´¡£¸Ã©¶´¿ÉÒÔÔ¶³ÌÎÞÌõ¼þ´¥·¢ £¬ADLab¼°Ê±³ÂËßÁ˳§É̲¢Ð­Öú³§É̽øÐÐÁËÐÞ¸´ £¬³§É̶Ը鶴µÄCVSS3ÆÀ·ÖΪÑÏÖØ¡£


ͼƬ11.png


SchneiderÒѾ­Ðû²¼ÁËв¹¶¡À´ÐÞ¸´Õâ¸ö¸ßΣ©¶´¡£Ïà¹Ø²¹¶¡ºÍ¸ü¶àµÄÄÚÈÝ¿ÉÔÚ¹Ù·½ÌṩµÄͨ¸æÖвéѯ£º

https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-102-01_IGSS_Security_Notification.pdf&p_Doc_Ref=SEVD-2022-102-01


ËÄ¡¢ÐÞ¸´½¨Òé


¾­¹ýADLabÑо¿Ô±µÄ·ÖÎöºÍÑéÖ¤ £¬ÉÏÊö¸ßΣ©¶´¶¼¿ÉÒÔͨ¹ýÍøÂç½øÐÐÎÞÌõ¼þµÄÔ¶³Ì´¥·¢ £¬¾ßÓкܴóµÄΣº¦ÐÔ¡£Ä¿Ç°¹Ù·½ÒѾ­Ðû²¼Á˲¹¶¡ £¬Ç¿ÁÒ½¨ÒéʹÓÃIGGSµÄ¹¤ÒµÓû§Á¢¼´Éý¼¶µ½×îа汾£º15.0.0.22074¡£


Õë¶Ô¹¤Òµ¿ØÖÆϵͳ £¬CISAÌṩÁËÈçϵÄͨÓý¨Ò飺

  • ¾¡Á¿¼õÉÙÔÚ¹«Íø̻¶¹¤¿ØÉ豸»òÕßϵͳ£»
  • ½«¿ØÖÆϵͳÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó £¬²¢ºÍ°ì¹«ÍøÂç¸ôÀ룻
  • µ±ÐèÒªÔ¶³Ì·ÃÎÊʱ £¬½ÓÄÉÀàËÆVPNµÄÄþ¾²·ÃÎÊ·½Ê½¡£


²Î¿¼Á´½Ó£º

[1] SEVD-2022-102-01, IGSS Data Server (V15.0.0.22073 and prior)

https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-102-01 
[2] SEVD-2022-039-01, IGSS Data Server (V15.0.0.22020 and prior)
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-01