ºáºÓµç»úSTARDOM¿ØÖÆÆ÷ÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-06-05

Îó²î±àºÅ

 

CVE-2018-10592


Îó²î¼¶±ð


ÑÏÖØ  ICS-CERTÆÀ·Ö£º9.8   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


¸ÃÎó²îÓ°ÏìÈÕ±¾ºáºÓµç»úµÄSTARDOM¶à¿î¿ØÖÆÆ÷ £¬£¬£¬£¬£¬£¬¹Ù·½Ðû²¼µÄÊÜÓ°Ïì¿ØÖÆÆ÷ÓÐFCJ (R4.02 and prior)¡¢FCN-100 (R4.02 and prior)¡¢FCN-RTU (R4.02 and prior)¡¢FCN-500 (R4.02 and prior)¡£¡£ ¡£¡£¡£ÓÉÓÚSTARDOM¿ØÖÆÆ÷Ó¦ÓÃÊ®·ÖÆÕ±é £¬£¬£¬£¬£¬£¬Éæ¼°ÄÜÔ´¡¢Òªº¦ÖÆÔ졢ʳÎïºÍũҵµÈÐÐÒµ £¬£¬£¬£¬£¬£¬¿ÉÔì³ÉÑÏÖØÎ£º¦ £¬£¬£¬£¬£¬£¬Ïà¹ØÓû§¼°³§ÉÌÓ¦ÒýÆð¸ß¶ÈÖØÊÓ¡£¡£ ¡£¡£¡£


Îó²îÐÎò


2018Äê5ÔÂ21ÈÕ £¬£¬£¬£¬£¬£¬ÈÕ±¾ºáºÓµç»úÐû²¼5Ô·ÝÇ徲ͨ¸æ £¬£¬£¬£¬£¬£¬Í¨¸æÖÐÐÞ¸´ÁËÒ»¸ö¸ßΣÎó²î¡£¡£ ¡£¡£¡£¹¥»÷ÕßʹÓøÃÎó²î¿ÉÒÔ¶ÔSTARDOM¿ØÖÆÆ÷ÌᳫԶ³Ì¹¥»÷ £¬£¬£¬£¬£¬£¬²¢Ö´ÐÐí§Òâ´úÂë £¬£¬£¬£¬£¬£¬»ñÈ¡¿ØÖÆÆ÷ËùÓÐȨÏÞ¡£¡£ ¡£¡£¡£


2018Äê5ÔÂ31ÈÕ £¬£¬£¬£¬£¬£¬ICS-CERTÕýʽÐû²¼¸ÃÎó²îÇ徲ͨ¸æ £¬£¬£¬£¬£¬£¬²¢ÎªÆäÊÚÓè±àºÅCVE-2018-10592 £¬£¬£¬£¬£¬£¬È϶¨Îó²îÆ·¼¶ÎªÑÏÖØ £¬£¬£¬£¬£¬£¬CVSS V3ÆÀ·Ö9.8¡£¡£ ¡£¡£¡£

 

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


 

CVE-2018-10592Îó²îÊǶ«·½µçÆø-918²©ÌìÌù¤¿ØÐÅÏ¢Çå¾²ÁªºÏʵÑéÊÒ£¨VDLab£©ÔÚ2017Äê8Ô·¢Ã÷²¢Éϱ¨¹ú¼ÒÏà¹ØÖ÷¹Ü»ú¹¹¡¢CVEºÍÏà¹ØÆóÒµ¡£¡£ ¡£¡£¡£ÈÕ±¾ºáºÓµç»úÈ·ÈϸÃÎó²îºó £¬£¬£¬£¬£¬£¬Ñ¸ËÙ¿ªÕ¹ÐÞ¸´ÊÂÇé £¬£¬£¬£¬£¬£¬²¢ÊµÊ±ÏòVDLabÌṩÁËÐÞ²¹²½·¥¡£¡£ ¡£¡£¡£VDLabÔÚ»ñµÃ²¹¶¡ºóµÄµÚһʱ¼ä £¬£¬£¬£¬£¬£¬Ð­Í¬Ïà¹ØÆóÒµ¾ÙÐÐÁËÄÚ²¿²âÊÔ £¬£¬£¬£¬£¬£¬²¢¶ÔÏà¹Ø¿ØÖÆÏµÍ³¾ÙÐÐÁËÏÖ³¡Éý¼¶ £¬£¬£¬£¬£¬£¬ÒÔ°ü¹ÜµçÁ¦»ù´¡ÉèÊ©ÍøÂçÇå¾²¡£¡£ ¡£¡£¡£
ʱ¸ô°ëÄê¶à £¬£¬£¬£¬£¬£¬³§É̽«¸ÃÎó²î¾ÙÐйûÕæ £¬£¬£¬£¬£¬£¬ÔÚ´ËÌáÐÑʹÓøÃϵÁпØÖÆÆ÷µÄÓû§ £¬£¬£¬£¬£¬£¬ÉÐδÍê³ÉÐÞ²¹ÊÂÇéµÄ £¬£¬£¬£¬£¬£¬Ð辡¿ì¶Ôϵͳ¾ÙÐÐÉý¼¶¡£¡£ ¡£¡£¡£


½â¾ö²½·¥


ºáºÓµç»ú¹Ù·½ÒÑÓÚ5ÔÂ21ÈÕ¶ÔÍâÕýʽÐû²¼Õë¶Ô¸ÃÎó²îµÄ²¹¶¡ £¬£¬£¬£¬£¬£¬¿É¸üйٷ½×îеIJ¹¶¡¡£¡£ ¡£¡£¡£Óû§Ò²¿É×·ÇóºáºÓµç»úµÄÊÖÒÕÖ§³ÖÖ°Ô±¶Ô×°±¸¾ÙÐÐÉý¼¶¸üС£¡£ ¡£¡£¡£


²Î¿¼×ÊÁÏ


https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03


https://mp.weixin.qq.com/s/Wxr8Mk6WxTVBe6iHMgjN5w