CVE-2020-10939| Phoenix Contact PC WORX SRTȨÏÞÌáÉýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-22

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-10939

ʱ   ¼ä

2020-04-22

Àà    ÐÍ

EOP

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£

PHOENIX CONTACT PC WORX SRT <=1.14


0x01 Îó²îÏêÇé


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾



Phoenix Contact PC WORX SRTÊǵ¹ú·ÆÄá¿Ë˹µçÆø£¨Phoenix Contact£©¹«Ë¾µÄÒ»¿î¿É±à³ÌÂß¼­¿ØÖÆÆ÷¡£¡£¡£

Phoenix Contact PC WORX SRT 1.14¼°Ö®Ç°°æ±¾Öб£´æÈ¨ÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ²»Çå¾²µÄĬÈÏ·¾¶È¨ÏÞ¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáÉýȨÏÞ¡£¡£¡£CVSSÆÀ·Ö7.8¡£¡£¡£

PC WORX SRTÊÇPhoenix ContactÓ¦ÓÃÖеÄЧÀͳÌÐò¡£¡£¡£¸Ã³ÌÐòµÄ×°Ö÷¾¶ÉèÖñ£´æ²»Çå¾²µÄȨÏÞ£¬£¬£¬£¬£¬¸ÃȨÏÞÔÊÐíÈκÎδÊÚȨÓû§½«í§ÒâÎļþдÈë¸ÃЧÀ͵ÄËùÓÐÉèÖÃÎļþºÍ¶þ½øÖÆÎļþËùÔÚµÄ×°ÖÃĿ¼¡£¡£¡£

¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÓöñÒâ¶þ½øÖÆÎļþÁýÕÖÖ÷ÒªµÄ¡° PC WORX SRT¡±Ð§ÀÍ£¬£¬£¬£¬£¬µ¼ÖÂÒÔϵͳȨÏÞÔËÐжñÒâ´úÂë¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥£¬£¬£¬£¬£¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³ÒÔ»ñÈ¡½â¾ö²½·¥£º

https://www.phoenixcontact.com/


0x03 Ïà¹ØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-10939


0x04 ²Î¿¼Á´½Ó


https://cert.vde.com/en-us/advisories/vde-2020-012

https://nvd.nist.gov/vuln/detail/CVE-2020-10939

https://www.cnvd.org.cn/flaw/show/CNVD-2020-20687


0x05 ʱ¼äÏß


2020-03-27 CVEÐû²¼¸ÃÎó²î


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾