Schneider IGSS Ô¶³ÌÎó²îÆÊÎö

Ðû²¼Ê±¼ä 2022-04-15

Ò»¡¢Ç°ÑÔ


½üÆÚ£¬£¬ £¬Z6×ðÁú¿­Ê±ADLabÔÚ¹¤Òµ¿ØÖÆÏµÍ³Îó²î¼à²âÖз¢Ã÷SchneiderÐû²¼Á˽»»¥Ê½Í¼ÐÎSCADAϵͳ£¨Interactive Graphical SCADA System£¬£¬ £¬¼ò³ÆIGSS£©µÄ¸ßΣÎó²îͨ¸æºÍ²¹¶¡£¬£¬ £¬°üÀ¨Óлº³åÇøÒç³öºÍĿ¼´©Ô½µÈ£¬£¬ £¬NVDµÄÆÀ·Ö¸ß´ï9.8¡£¡£¡£¡£¡£¡£ADLabÑо¿Ô±µÚһʱ¼ä¶ÔÆäÖеĸßΣÎó²î¾ÙÐÐÁËÏêϸÆÊÎöºÍÏÖʵÑéÖ¤£¬£¬ £¬Í¬Ê±»¹·¢Ã÷ÁËÒ»¸öеĸßΣÎó²î²¢Ð­Öú³§É̾ÙÐÐÁËÐÞ¸´¡£¡£¡£¡£¡£¡£


¶þ¡¢Îó²î»ù±¾ÐÅÏ¢



ƾ֤SchneiderµÄÎó²îͨ¸æ£¬£¬ £¬ÕâЩÎó²îµÄ»ù±¾ÐÅÏ¢ÈçÏ£º



ÊÜÓ°ÏìµÄ²úÆ·£ºV15.0.0.22020 and prior

±£´æÎó²î

  • CVE-2022-24312£¬£¬ £¬Ä¿Â¼´©Ô½
  • CVE-2022-24311£¬£¬ £¬Ä¿Â¼´©Ô½
  • CVE-2022-24310£¬£¬ £¬»º³åÇøÒç³ö


ÊÜÓ°ÏìµÄ²úÆ·£ºV15.0.0.22073 and prior

±£´æÎó²î


  • CVE-2022-24324£¬£¬ £¬»º³åÇøÒç³ö



´¥·¢·½·¨£ºÍøÂç
CVSS v3ÆÀ·Ö:  9.8

Èý¡¢Îó²îÆÊÎöÓëÑéÖ¤


3.1 CVE-2022-24311(24312)ÆÊÎö


ÕâÁ½¸öÎó²î±£´æÓÚIGSS V15.0.0.22020 and prior°æ±¾£¬£¬ £¬ÆäÎó²îÐÎòΪ£º¡°±£´æ¶ÔÊÜÏÞÖÆÄ¿Â¼Â·¾¶ÃûµÄ²»µ±ÏÞÖÆ£¬£¬ £¬¿Éµ¼ÖÂͨ¹ýÔÚÎļþĩβÌí¼Ó»òÔÚÊý¾ÝЧÀÍÆ÷ÉÏÏÂÎÄÖн¨ÉèÐÂÎļþÀ´ÐÞ¸ÄÏÖÓÐÎļþ£¬£¬ £¬µ±¹¥»÷Õßͨ¹ýÍøÂç·¢ËÍÌØ¶¨Ãü¾Ýʱ£¬£¬ £¬¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐС±¡£¡£¡£¡£¡£¡£


̫ͨ¹ýÎö£¬£¬ £¬ÎÒÃÇ·¢Ã÷ÕâÁ½¸öÎó²îλÓÚsub_49FF20º¯Êý£¬£¬ £¬¸Ãº¯ÊýµÄα´úÂëÈçÏ£º


ͼƬ1.png


¸ú½øsub_4A0C50º¯Êý£¬£¬ £¬Î±´úÂëÈçÏÂËùʾ£º


ͼƬ2.png



¿ÉÒÔ¿´³ö£¬£¬ £¬¸Ãº¯ÊýÄÚ²¿¾ÙÐÐÁËһϵÁÐÎļþ²Ù×÷£¬£¬ £¬µ«¶Ô´«Èë¸Ãº¯ÊýµÄ²ÎÊýûÓÐ×öÓÐÓõÄÇå¾²¼ì²é£¬£¬ £¬Òò´Ë¿ÉÒÔ±»²Ù¿ØÀ´ÏòSCADAЧÀÍÆ÷дÈëí§ÒâÎļþ¡£¡£¡£¡£¡£¡£


ͬÀí£¬£¬ £¬¸ú½øsub_4A0C50º¯Êý£¬£¬ £¬Î±´úÂëÈçÏÂËùʾ£º


ͼƬ3.png



¿ÉÒÔ¿´³ö£¬£¬ £¬¸Ãº¯ÊýµÄÄÚ²¿Í¬ÑùҲûÓжԴ«ÈëµÄ²ÎÊý¾ÙÐÐÇå¾²¼ì²é£¬£¬ £¬Òò´ËÒ²¿ÉÒÔ±»²Ù¿ØÀ´ÏòSCADAЧÀÍÆ÷дÈëí§ÒâÎļþ¡£¡£¡£¡£¡£¡£


ƾ֤ÉÏÊöÆÊÎöÎÒÃǾÙÐÐÁËÑéÖ¤£¬£¬ £¬ÀÖ³ÉÏòSCADAЧÀÍÆ÷дÈëí§ÒâÄÚÈݵÄÎļþ¡£¡£¡£¡£¡£¡£


ͼƬ4.png


¹ØÓÚÉÏÊöÁ½¸öÎó²î£¬£¬ £¬Schneider¹Ù·½Ðû²¼Á˲¹¶¡£¬£¬ £¬ÆäÐÞ¸´·½·¨ÈçÏ£º


ͼƬ5.png


ÏêϸÀ´½²£¬£¬ £¬¡°Prepend file¡±ºÍ¡°Append file¡±·ÖÖ§ÔÚ½øÈëÏêϸ¹¦Ð§º¯ÊýǰŲÓÃÁËÌØÁíÍâsub_4A16F0º¯Êý¡£¡£¡£¡£¡£¡£¸Ãº¯Êý´«ÈëÁ˲ÎÊý v6+72£¬£¬ £¬´Ë²ÎÊý¶ÔÓ¦±»²Ù×÷ÎļþµÄÎļþ·¾¶Ãû¡£¡£¡£¡£¡£¡£¸ú½ø¸Ãº¯Êý£¬£¬ £¬Æäα´úÂëÈçÏ£º


ͼƬ6.png


¸Ãº¯Êý¶ÔÎļþ·¾¶Ãû¾ÙÐÐÁËÏÞÖÆ£º(1)ÏÞÖÆ(v6+72)³¤¶È£¬£¬ £¬¾ÞϸҪ֪×ã<=0x100£»£»£»£»£»£»(2)ÏÞÖÆ(v6+72)ÄÚÈÝ£¬£¬ £¬²»¿ÉÓÐĿ¼´©Ô½µÄÌØÕ÷·û¡£¡£¡£¡£¡£¡£Í¨¹ýÕâÖÖÏÞÖÆ£¬£¬ £¬²¹¶¡±ÜÃâÁ˶ñÒâÊý¾Ýµ¼ÖµÄÌø×ªÄ¿Â¼£¬£¬ £¬°ÑÎļþ²Ù×÷ÏÞÖÆÔÚÄ¿½ñĿ¼Ï¡£¡£¡£¡£¡£¡£


3.2 CVE-2022-24310ÆÊÎö


¸ÃÎó²î±£´æÓÚIGSS V15.0.0.22020 and prior°æ±¾£¬£¬ £¬Îó²îµÄÐÎòΪ£º¡°±£´æÕûÊýÒç³ö£¬£¬ £¬µ±¹¥»÷Õß·¢ËͶàÌõÈ«ÐÄ×¼±¸µÄÐÂÎÅʱ£¬£¬ £¬¸ÃÎó²î¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö£¬£¬ £¬µ¼Ö¾ܾøÐ§ÀͲ¢¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС±¡£¡£¡£¡£¡£¡£

̫ͨ¹ýÎö£¬£¬ £¬ÎÒÃÇ·¢Ã÷Õâ¸öÎó²î±£´æÓÚsub_49FA30º¯Êý£¬£¬ £¬¸Ãº¯ÊýµÄα´úÂëÈçÏ£º


ͼƬ7.png


´ÓÉÏͼ¿ÉÒÔ¿´³ö£¬£¬ £¬¸Ãº¯ÊýµÄÖ÷ÒªÂß¼­ÊÇ£ºÊ×ÏÈ£¬£¬ £¬Í¨¹ýrealloc¸ø*(this+48)µÄ¶ÑÔöÌí*(a1+0xBA)ÊýÖµµÄ´óС£¡£¡£¡£¡£¡£»£»£»£»£»£»È»ºó£¬£¬ £¬Ê¹ÓÃmemcpyÏò(*(v5 +52)+*(v5 + 48))¸³Öµ*(a2+0xBA)³¤¶ÈµÄ(a2+190)»º³åÇøÄÚÈÝ£¬£¬ £¬¼´Ìî³äreallocзÖÅɳöµÄÄÚ´æ¿Õ¼ä¡£¡£¡£¡£¡£¡£


¾­Ì«¹ýÎö£¬£¬ £¬ÎÒÃÇ·¢Ã÷£ºÔÚ*(a2+ 0xBA)+*(this + 52)µÄ¼Ó·¨²Ù×÷ÖУ¬£¬ £¬Á½¸ö²Ù×÷Êý¾ùΪÎÞ·ûºÅÀàÐÍ£¬£¬ £¬ÇÒ*(a2+0xBA)¿É¿Ø¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬ £¬Í¨¹ý¿ØÖÆ*(a2+0xBA)µÄÖµ£¬£¬ £¬¿ÉʹµÃ*(a2 + 0xBA)+*(this + 52)±¬·¢ÕûÊýÉÏÒ磬£¬ £¬´Ó¶øµ¼ÖÂreallocÐÂÉêÇëÄÚ´æµÄÈÝÁ¿Ð¡ÓÚºóÐømemcpyµÄ²ÎÊý*(a2+0xBA)£¬£¬ £¬ºóÐøÖ´ÐÐmemcpyÄڴ濽±´²Ù×÷ʱ¾Í»á´¥·¢¶ÑÒç³ö¡£¡£¡£¡£¡£¡£


ƾ֤ÉÏÊöÆÊÎöÎÒÃǾÙÐÐÁËÑéÖ¤£¬£¬ £¬Àֳɴ¥·¢ÁËSCADAЧÀÍÆ÷µÄ¶ÑÆÆË𡣡£¡£¡£¡£¡£


ͼƬ8.png

¹ØÓÚ¸ÃÎó²î£¬£¬ £¬Schneider¹Ù·½Ðû²¼Á˲¹¶¡£¬£¬ £¬ÆäÐÞ¸´·½·¨ÈçÏ£º


ͼƬ9.png


ÏêϸÀ´½²£¬£¬ £¬ÔÚ¾ÙÐÐrealloc²Ù×÷Ö´ÐÐǰ£¬£¬ £¬ÏÈÅжÏ*(a2+0xBA)µÄÖµÊÇ·ñÔÚ[0,0xF42]µÄÇø¼ä¹æÄ£ÄÚ£¬£¬ £¬´Ó¶ø×èÖ¹ÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£


3.3 CVE-2022-24324ÆÊÎö


ÔÚ¶ÔIGSS V15.0.0.22073 and priorµÄ²¹¶¡ÆÊÎöÖУ¬£¬ £¬ADLabÑо¿Ô±»¹·¢Ã÷ÁËÒ»¸öÐµĻº´æÇøÒç³öÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÒÔÔ¶³ÌÎÞÌõ¼þ´¥·¢£¬£¬ £¬ADLabʵʱ±¨¸æÁ˳§É̲¢Ð­Öú³§É̾ÙÐÐÁËÐÞ¸´£¬£¬ £¬³§É̶ԸÃÎó²îµÄCVSS3ÆÀ·ÖΪÑÏÖØ¡£¡£¡£¡£¡£¡£


ͼƬ11.png


SchneiderÒѾ­Ðû²¼ÁËв¹¶¡À´ÐÞ¸´Õâ¸ö¸ßΣÎó²î¡£¡£¡£¡£¡£¡£Ïà¹Ø²¹¶¡ºÍ¸ü¶àµÄÄÚÈÝ¿ÉÔÚ¹Ù·½ÌṩµÄͨ¸æÖÐÅÌÎÊ£º

https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-102-01_IGSS_Security_Notification.pdf&p_Doc_Ref=SEVD-2022-102-01


ËÄ¡¢ÐÞ¸´½¨Òé


¾­ÓÉADLabÑо¿Ô±µÄÆÊÎöºÍÑéÖ¤£¬£¬ £¬ÉÏÊö¸ßΣÎó²î¶¼¿ÉÒÔͨ¹ýÍøÂç¾ÙÐÐÎÞÌõ¼þµÄÔ¶³Ì´¥·¢£¬£¬ £¬¾ßÓкܴóµÄΣº¦ÐÔ¡£¡£¡£¡£¡£¡£ÏÖÔÚ¹Ù·½ÒѾ­Ðû²¼Á˲¹¶¡£¬£¬ £¬Ç¿ÁÒ½¨ÒéʹÓÃIGGSµÄ¹¤ÒµÓû§Á¬Ã¦Éý¼¶µ½×îа汾£º15.0.0.22074¡£¡£¡£¡£¡£¡£


Õë¶Ô¹¤Òµ¿ØÖÆÏµÍ³£¬£¬ £¬CISAÌṩÁËÈçϵÄͨÓý¨Ò飺

  • Ö»¹ÜïÔÌ­ÔÚ¹«ÍøÌ»Â¶¹¤¿Ø×°±¸»òÕßϵͳ£»£»£»£»£»£»
  • ½«¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸ÖÃÓÚ·À»ðǽ֮ºó£¬£¬ £¬²¢ºÍ°ì¹«ÍøÂç¸ôÀ룻£»£»£»£»£»
  • µ±ÐèÒªÔ¶³Ì»á¼ûʱ£¬£¬ £¬½ÓÄÉÀàËÆVPNµÄÇå¾²»á¼û·½·¨¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó£º

[1] SEVD-2022-102-01, IGSS Data Server (V15.0.0.22073 and prior)

https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-102-01 
[2] SEVD-2022-039-01, IGSS Data Server (V15.0.0.22020 and prior)
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-01