CVE-2020-10939| Phoenix Contact PC WORX SRTȨÏÞÌáÉýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-22

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-10939

ʱ   ¼ä

2020-04-22

Àà    ÐÍ

EOP

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£

PHOENIX CONTACT PC WORX SRT <=1.14


0x01 Îó²îÏêÇé


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



Phoenix Contact PC WORX SRTÊǵ¹ú·ÆÄá¿Ë˹µçÆø£¨Phoenix Contact£©¹«Ë¾µÄÒ»¿î¿É±à³ÌÂß¼­¿ØÖÆÆ÷¡£¡£

Phoenix Contact PC WORX SRT 1.14¼°Ö®Ç°°æ±¾Öб£´æÈ¨ÏÞÌáÉýÎó²î £¬£¬£¬¸ÃÎó²îÔ´ÓÚ²»Çå¾²µÄĬÈÏ·¾¶È¨ÏÞ¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáÉýȨÏÞ¡£¡£CVSSÆÀ·Ö7.8¡£¡£

PC WORX SRTÊÇPhoenix ContactÓ¦ÓÃÖеÄЧÀͳÌÐò¡£¡£¸Ã³ÌÐòµÄ×°Ö÷¾¶ÉèÖñ£´æ²»Çå¾²µÄȨÏÞ £¬£¬£¬¸ÃȨÏÞÔÊÐíÈκÎδÊÚȨÓû§½«í§ÒâÎļþдÈë¸ÃЧÀ͵ÄËùÓÐÉèÖÃÎļþºÍ¶þ½øÖÆÎļþËùÔÚµÄ×°ÖÃĿ¼¡£¡£

¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÓöñÒâ¶þ½øÖÆÎļþÁýÕÖÖ÷ÒªµÄ¡° PC WORX SRT¡±Ð§ÀÍ £¬£¬£¬µ¼ÖÂÒÔϵͳȨÏÞÔËÐжñÒâ´úÂë¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥ £¬£¬£¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³ÒÔ»ñÈ¡½â¾ö²½·¥£º

https://www.phoenixcontact.com/


0x03 Ïà¹ØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-10939


0x04 ²Î¿¼Á´½Ó


https://cert.vde.com/en-us/advisories/vde-2020-012

https://nvd.nist.gov/vuln/detail/CVE-2020-10939

https://www.cnvd.org.cn/flaw/show/CNVD-2020-20687


0x05 ʱ¼äÏß


2020-03-27 CVEÐû²¼¸ÃÎó²î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø