Phoenix Contact²úÆ·¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-16

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-9435£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.1£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-9436£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.2£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2017-16544£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬ £¬¹Ù·½£º8.8


Ó°Ïì°æ±¾


Article name

Article number

Affected versions

TC ROUTER

TC ROUTER 3002T-4G

2702528

<= 2.05.3

TC ROUTER 3002T-4G

2702530

<= 2.05.3

TC ROUTER 2002T-3G

2702529

<= 2.05.3

TC ROUTER 2002T-3G

2702531

<= 2.05.3

TC ROUTER 3002T-4G VZW

2702532

<= 2.05.3

TC ROUTER 3002T-4G ATT

2702533

<= 2.05.3

TC CLOUD CLIENT

TC CLOUD CLIENT 1002-4G

2702886

<= 2.03.17

TC CLOUD CLIENT 1002-4G VZW

2702887

<= 2.03.17

TC CLOUD CLIENT 1002-4G ATT

2702888

<= 2.03.17

TC CLOUD CLIENT 1002-TXTX

2702885

<= 1.03.17


Îó²î¸ÅÊö


Phoenix ContactΪ×ܲ¿Î»Óڵ¹úµÄ¹¤Òµ×Ô¶¯»¯¡¢ÅþÁ¬ºÍ½Ó¿Ú½â¾ö¼Æ»®ÌṩÉÌ¡£¡£¡£¡£¡£¡£¡£ÔÚPhoenix ContactÉú²úµÄPhoenix Contact TC·ÓÉÆ÷ºÍTCÔÆ¿Í»§¶Ë×°±¸Öз¢Ã÷ÁËÈý¸öÎó²î£¬£¬£¬ £¬¸ÅÊöÈçÏÂ:


CVE-2020-9435£¬£¬£¬ £¬ÓëÓÃÓÚHTTPSµÄÓ²±àÂëÖ¤ÊéµÄ±£´æÏà¹Ø¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÖ¤Êé¾ÙÐÐÖÐÐÄÈË(MitM)¹¥»÷¡¢×°±¸Ä£ÄâºÍ±»¶¯½âÃÜ£¬£¬£¬ £¬´Ó¶ø»ñµÃÖÎÀíԱƾ֤ºÍÆäËûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


CVE-2020-9436£¬£¬£¬ £¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÀ´¾ÙÐÐÏÂÁî×¢È룬£¬£¬ £¬´Ó¶øÈëÇÖ×°±¸µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£


CVE-2017-16544£¬£¬£¬ £¬ÔÚBusyBox 1.27.2¼°Ö®Ç°µÄ°æ±¾ÖУ¬£¬£¬ £¬shellµÄtab auto completeÌØÕ÷ÓÃÓÚ»ñȡĿ¼ÖеÄÎļþÃûÁбí£¬£¬£¬ £¬Ëü²»»áÕûÀíÎļþÃû£¬£¬£¬ £¬²¢µ¼ÖÂÔÚÖÕ¶ËÖÐÖ´ÐÐÈκÎתÒåÐòÁС£¡£¡£¡£¡£¡£¡£´ËÎó²î¿ÉÄܵ¼Ö´úÂëÖ´ÐС¢í§ÒâÎļþдÈë»òÆäËû¹¥»÷¡£¡£¡£¡£¡£¡£¡£´ËÎó²î¶Ô×°±¸µÄÓ°ÏìÓÐÏÞ£¬£¬£¬ £¬ÓÉÓÚÖ»ÓоßÓÐÖÎÀíԱȨÏ޲Żª»á¼ûshell³ÌÐò¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½ÒÑÐû²¼×îа汾ÐÞ¸´¸ÃÎó²î£¬£¬£¬ £¬Á´½Ó£ºhttps://cert.vde.com/en-us/advisories/vde-2020-003¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://cert.vde.com/en-us/advisories/vde-2020-003