Î÷ÃÅ×Ó PLCÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2020-15782£©

Ðû²¼Ê±¼ä 2021-05-31

0x00 ©¶´¸ÅÊö

CVE  ID

CVE-2020-15782

ʱ   ¼ä

2021-05-31

Àà   ÐÍ

RCE

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

PLC£¨¿É±à³ÌÂß¼­¿ØÖÆÆ÷£©ÊÇÒ»ÖÖרÃÅΪ¹¤Òµ»·¾³Ó¦ÓöøÉè¼ÆµÄÊý×ÖÔËËã²Ù×÷µç×Óϵͳ¡£Ëü½ÓÄÉÒ»Öֿɱà³ÌµÄ´æ´¢Æ÷£¬ÔÚÆäÄÚ²¿´æ´¢Ö´ÐÐÂß¼­ÔËË㡢˳Ðò¿ØÖÆ¡¢¶¨Ê±¡¢¼ÆÊýºÍËãÊõÔËËãµÈ²Ù×÷µÄÖ¸Áͨ¹ýÊý×Öʽ»òÄ£ÄâʽµÄÊäÈëÊä³öÀ´¿ØÖÆÖÖÖÖÀàÐ͵ĻúеÉ豸»òÉú²ú¹ý³Ì¡£

2021Äê05ÔÂ28ÈÕ£¬ClarotyµÄÑо¿ÈËÔ±¹ûÈ»Åû¶ÁËSiemens£¨Î÷ÃÅ×Ó£©PLCÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2020-15782£©£¬ÆäCVSSÆÀ·ÖΪ8.1¡£Äܹ»ÍøÂç·ÃÎÊ TCP ¶Ë¿Ú 102 µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´ÈƹýPLC CPUÖеÄPLCɳÏ䣬ÔÚÊܱ£»¤µÄÄÚ´æÇøÓòÖÐдÈë»ò¶ÁÈ¡Êý¾Ý£¬×îÖÕÔ¶³ÌÖ´ÐжñÒâ´úÂ룬ÇҸé¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓá£

¹¥»÷Õß¿ÉÒÔÔÚ½ûÓ÷ÃÎʱ£»¤µÄ PLC ÉÏÀÄÓôË©¶´£¬ÒÔ»ñµÃ PLC ÉÏÈκÎλÖõĶÁд·ÃÎÊȨÏÞ²¢Ô¶³ÌÖ´ÐжñÒâ´úÂ룬¶øÇÒÀûÓôË©¶´µÄ¹¥»÷½«ºÜÄѱ»¼ì²â¡£

 

Ó°Ï췶Χ

image.png

 

 

0x02 ´¦Öý¨Òé

ĿǰSiemensÒѾ­ÐÞ¸´ÁË´Ë©¶´£¬½¨Òé²Î¿¼¹Ù·½Ðû²¼µÄÄþ¾²×Éѯ¼°Ê±Éý¼¶¸üÐÂ:

ÏÂÔØÁ´½Ó£º

https://cert-portal.siemens.com/productcert/pdf/ssa-434534.pdf

 

0x03 ²Î¿¼Á´½Ó

https://cert-portal.siemens.com/productcert/pdf/ssa-434534.pdf

https://claroty.com/2021/05/28/blog-research-race-to-native-code-execution-in-plcs/

https://securityaffairs.co/wordpress/118367/ics-scada/cve-2020-15782-siemens-plcs-flaw.html?

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15782


0x04 ʱ¼äÏß

2021-05-28  Claroty¹ûÈ»Åû¶©¶´

2021-05-28  SiemensÐû²¼Äþ¾²Í¨¸æ

2021-05-31  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png