VxWorks¶à¸ö°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-30

¡ô ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12256 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12257 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12255 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12260 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12261 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12263 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12258 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12259 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.3 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12262 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-12264 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-12265 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.4 £¬¹Ù·½Î´ÆÀ¶¨


¡ô Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

 

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¡ô ·ì϶¸ÅÊö


VxWorksÊÇÊÀ½çÉÏʹÓÃ×î¿í·ºµÄÒ»ÖÖÔÚǶÈëʽϵͳÖв¿ÊðµÄʵʱ²Ù×÷ϵͳ £¬ÊÇÓÉÃÀ¹úWindRiver¹«Ë¾£¨¼ò³Æ·çºÓ¹«Ë¾ £¬¼´WRS ¹«Ë¾£©ÓÚ1983ÄêÉè¼Æ¿ª·¢µÄ £¬VxWorks±»³¬¹ý20ÒŲ́É豸ʹÓà £¬Ô̺¬¹Ø¼ü»ù´¡ÉèÊ© £¬ÍøÂçÉ豸 £¬Ò½ÁÆÉ豸 £¬¹¤ÒµÏµÍ³ÉõÖÁº½ÌìÆ÷¡ £Äܹ»Ëµ´ÓPLCµ½MRI»úе £¬µ½·À»ðǽºÍ´òÓ¡»ú £¬ÔÙµ½·É»ú £¬»ð³µµÈµÈ¶¼ÓÐ¿í·ºÀûÓá£


½üÈÕ £¬VxWorks¹Ù·½°ä²¼Á˰²È«·ì϶²¼¸æ³Æ½¨¸´ÁËÓÉArmis×êÑÐÍŶӷ¢ÏÖ²¢»ã±¨µÄ11¸ö°²È«·ì϶ £¬ÆäÖÐÓÐ6¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶ £¬CVE-2019-12256¡¢CVE-2019-12255¡¢CVE-2019-12260 CVSSÆÀ·ÖΪ9.8·Ö¡£ÆäÓà5¸ö·ì϶¿ÉÄܵ¼Ö»ؾø·þÎñ £¬ÐÅϢй©»ò¹éÀàΪÂß¼­È±µã¡£ÕâЩ·ì϶´æÔÚÓÚVxWorksµÄTCP/IP²Ö¿â£¨IPnet£©ÖÐ £¬Ó°ÏìVxWorks 7 (SR540 and SR610)¡¢VxWorks 6.5-6.9¼°Ê¹ÓÃInterpeak¶ÀÁ¢ÍøÂç²Ö¿âµÄVxWorks°æ±¾¡£¹¥»÷ÕßÄܹ»ÀûÓÃÆäÖзì϶ʵÏÖÎÞÐèÓû§½»»¥¼°ÈÏ֤ʵÏÖÔ¶³Ì¹¥»÷ £¬×îÖÕÔÚÆëÈ«½ÚÔìÓйØÉ豸¡£


ÔÚÈ«Çò £¬Ê¹ÓÃVxWorksµÄÊýÁ¿ÓÐ126460¸ö £¬ÆäÖÐÖйúÓÐ25046¸ö £¬É¢²¼ÈçÏ£º

 

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¡ô ·ì϶ÑéÖ¤


ĿǰArmis×êÑÐÍŶӰ䲼Á˳ɹ¦ÀûÓ÷ì϶½ÚÔìÁËSonicWall·À»ðǽ¡¢Xerox´òÓ¡»ú¡¢²¡È˼໤ÒǵÄÑÝʾÊÓÆµ £¬µ«ÊÇûÓа䲼·ì϶ÓйØÏ¸½Ú»ò·ì϶ÑéÖ¤·¨Ê½¡£


¡ô ½¨¸´½¨Òé


SonicWall¼°Xerox¹Ù·½¾ùÒѾ­°ä²¼Óйطì϶¸üС£
SonicWall£ºhttps://blog.sonicwall.com/en-us/2019/07/wind-river-vxworks-and-urgent-11-patch-now/
Xerox£ºhttps://security.business.xerox.com/en-us/


¡ô ²Î¿¼Á´½Ó


https://armis.com/urgent11/ 
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/