CVE-2020-6994| ºÕ˹ÂüHiOSºÍHiSecOS²úÆ·Çå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-010x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-6994 |
ʱ ¼ä |
2020-04-01 |
|
Àà ÐÍ |
»º³åÇøÒç³ö |
µÈ ¼¶ |
ÑÏÖØ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
HiOS <= 07.0.02 Ó°Ïì²úÆ·£ºRSP£¬£¬£¬£¬£¬£¬RSPE£¬£¬£¬£¬£¬£¬RSPS£¬£¬£¬£¬£¬£¬RSPL£¬£¬£¬£¬£¬£¬MSP£¬£¬£¬£¬£¬£¬EES£¬£¬£¬£¬£¬£¬ EESX£¬£¬£¬£¬£¬£¬GRS£¬£¬£¬£¬£¬£¬OS£¬£¬£¬£¬£¬£¬RED½»Á÷»ú£»£»£»£»£»£» HiSecOS0 <= 3.2.00 Ó°Ïì²úÆ·£ºEAGLE 20/30·À»ðǽ |
x01 Îó²îÏêÇé
µÂ¹úºÕ˹Âü×Ô¶¯»¯ºÍ¿ØÖƹ«Ë¾½¨ÉèÓÚ1924Ä꣬£¬£¬£¬£¬£¬ÓªÒµÂþÑÜÔÚ×Ô¶¯»¯Í¨Ñ¶ÁìÓò£¬£¬£¬£¬£¬£¬²úÆ·¹æÄ£°üÀ¨½ÓÄÉÄ£ÄâºÍÊý×ֹ㲥µçÊÓ´«ÊäÊÖÒÕµÄÒÆ¶¯·¢ÉäºÍÎüÊÕϵͳ£¬£¬£¬£¬£¬£¬ÆóÒµºÍ¹¤ÒµÍøÂç½â¾ö¼Æ»®ÒÔ¼°ÏÖ³¡×ÜÏßϵͳ¡£¡£ºÕ˹ÂüÔÚ2007Äê±»ÃÀ¹ú°Ùͨ£¨Belden£©¹«Ë¾ÊÕ¹º¡£¡£ºÕ˹ÂüHiOSºÍHiSecOS¶¼ÊǰÙÍ¨ÍÆ³öµÄÇå¾²²Ù×÷ϵͳ¡£¡£
HiOSºÍHiSecOSµÄHTTP(S)web serverÖб£´æÒ»¸ö»º³åÇøÒç³öÎó²î¡£¡£¸ÃÎó²îÔ´ÓÚ¶ÔURL²ÎÊýµÄÆÊÎö²»µ±ÒýÆðµÄ¡£¡£¹¥»÷Õß¿ÉÒÔ½èÖúÌØÖÆµÄHTTPÇëÇóÈëÇÖÄ¿µÄ×°±¸£¬£¬£¬£¬£¬£¬Ôì³ÉÄÚ²¿»º³åÇøÒç³ö¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬½¨ÒéHiOSÓû§¾¡¿ì¸üÐÂÖÁ07.0.03»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬HiSecOSÓû§¸üÐÂÖÁ03.3.00»ò¸ü¸ß°æ±¾¡£¡£
ÔÝʱ²½·¥¿ÉʹÓá°IP»á¼ûÏÞÖÆ¡±¹¦Ð§£¬£¬£¬£¬£¬£¬ÏÞÖÆHTTPºÍHTTPS¶Ô¿ÉÐÅIPµØµãµÄ»á¼û£¬£¬£¬£¬£¬£¬»òÕß½ûÓÃHTTPºÍHTTPSЧÀÍÆ÷¡£¡£
https://www.belden.com/hubfs/support/security/bulletins/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf?hsLang=en
0x04 ²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-091-01
0x05 ʱ¼äÏß
2020-02-14 Ðû²¼Îó²î
2020-02-26 ÍÆ³ö½â¾ö¼Æ»®
2020-03-24 »ñµÃCVE±àºÅ


¾©¹«Íø°²±¸11010802024551ºÅ