¡¾Â©¶´Í¨¸æ¡¿ICEFALL £ºOTÉ豸¶à¸ö©¶´

Ðû²¼Ê±¼ä 2022-06-22


0x00 ©¶´¸ÅÊö

2022Äê6ÔÂ20ÈÕ £¬Ñо¿ÈËÔ±¹ûÈ»Åû¶Á˲Ù×÷¼¼Êõ (OT) É豸ÖÐÓÉÓÚ²»Äþ¾²Éè¼Æµ¼ÖµÄ56¸ö©¶´ £¬ÕâЩ©¶´Í³³ÆÎªOT:ICEFALL £¬Ó°ÏìÁËÀ´×Ô10¼ÒOT¹©Ó¦É̵ÄÉ豸¡£

 

0x01 ©¶´ÏêÇé

OT:ICEFALL©¶´Ö÷ÒªÊÇÓÉÓÚOTµÄÉè¼Æ²»Äþ¾²¡¢Äþ¾²¿ØÖƲ»×ãµ¼ÖµÄ £¬ÆäÖÐÐí¶àÊÜÓ°ÏìÉ豸ʹÓÃÃ÷ÎÄÆ¾¾Ý¡¢ÈõÃÜÂë»òËð»µÃÜÂë¡¢Ó²±àÂëÃÜÔ¿ºÍ¿Í»§¶ËÉí·ÝÑéÖ¤¡£ÖµµÃ×¢ÒâµÄÊÇ £¬ÆäÖÐ74%µÄÒ×Êܹ¥»÷²úÎïϵÁÐÒÑͨ¹ýÄþ¾²ÈÏÖ¤¡£

ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÄܵ¼Ö£ºÆ¾¾Ýй¶¡¢Éí·ÝÑéÖ¤ÈÆ¹ý¡¢Îļþ/¹Ì¼þ/ÅäÖõĸ͝¡¢¾Ü¾ø·þÎñ(DoS)»òÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£

image.png

Icefall©¶´µÄÀàÐÍ£¨À´Ô´£ºForescout£©

OT:ICEFALL©¶´Ó°ÏìµÄ¹©Ó¦Ḛ́üÂÞHoneywell¡¢Motorola¡¢Omron¡¢Siemens¡¢Emerson¡¢JTEKT¡¢Bentley Nevada¡¢Phoenix Contract¡¢ProConOS ºÍ Yokogawa¡££¨»ôÄáΤ¶û¡¢Ä¦ÍÐÂÞÀ­¡¢Å·Ä·Áú¡¢Î÷ÃÅ×Ó¡¢°¬Ä¬É­¡¢JTEKT¡¢±¾ÌØÀûÄÚ»ª´ï¡¢·ÆÄá¿Ë˹µçÆø¹«Ë¾¡¢ProConOSºÍºáºÓ£©¡£ÆäÖÐÓ°ÏìHoneywellÉ豸µÄ©¶´°üÂÞ£ºCVE-2022-30312µ½CVE-2022-30320µÈ9¸ö©¶´ £¬Ó°ÏìBently NevadaÉ豸µÄ©¶´°üÂÞ£ºCVE-2022-29952ºÍCVE-2022-29953 £¬Ó°ÏìJTEKTÉ豸µÄ©¶´°üÂÞCVE-2022-29951ºÍCVE-2022-29958 £¬Ó°ÏìSiemensÉ豸µÄ©¶´°üÂÞCVE-2022-33139 £¬Ó°ÏìEmersonÉ豸µÄ©¶´°üÂÞCVE-2022-29957ºÍCVE-2022-29962µÈ15¸ö©¶´¡£

ÊÜOT:ICEFALL©¶´Ó°ÏìµÄ²úÎï¹ã·ºÓ¦ÓÃÓÚʯÓͺÍÌìÈ»Æø¡¢»¯¹¤¡¢ºËÄÜ¡¢·¢µçºÍÅäµç¡¢ÖÆÔ졢ˮ´¦ÖúͷÖÅä¡¢²É¿óºÍ½¨Öþ×Ô¶¯»¯µÈÒªº¦»ù´¡ÉèÊ©ÐÐÒµ £¬ÀÄÓÃÕâЩ©¶´¿ÉÄÜÔì³ÉÔÖÄÑÐÔºó¹û¡£

ºÃ±È £¬½üÆÚÕë¶ÔÒªº¦»ù´¡ÉèÊ©£¨ÈçIndustroyer2¡¢TritonºÍINCONTROLLERµÈ£©µÄ¶ñÒâÈí¼þµÄÉú³¤±íÃ÷ £¬ÍþвÕßÒѾ­Òâʶµ½OTÉ豸µÄ²»Äþ¾²Éè¼ÆÈ±ÏÝ £¬²¢ÊÔͼͨ¹ýÀûÓÃÕâЩÎÊÌâÀ´Ôì³ÉÑÏÖØÆÆ»µ¡£

 

Ó°Ï췶Χ

ÊÜÓ°ÏìÖÆÔìÉÌ

Ä£ÐÍ

É豸ÀàÐÍ

Bently Nevada

3700, TDI equipment

״̬¼àÊÓÆ÷

Emerson

DeltaV

ÂþÑÜʽ¿ØÖÆÏµÍ³

Emerson

Ovation

ÂþÑÜʽ¿ØÖÆÏµÍ³

Emerson

OpenBSI

¹¤³ÌÊÂÇéÕ¾

Emerson

ControlWave, BB 33xx, ROC

Ô¶³ÌÖն˵¥Ôª

Emerson

Fanuc, PACsystems

¿É±à³ÌÂß¼­¿ØÖÆÆ÷

Honeywell

Trend IQ*

Â¥Óî¿ØÖÆÆ÷

Honeywell

Safety Manager FSC

Äþ¾²ÒDZíϵͳ

Honeywell

Experion LX

ÂþÑÜʽ¿ØÖÆÏµÍ³

Honeywell

ControlEdge

Ô¶³ÌÖն˵¥Ôª

Honeywell

Saia Burgess PCD

¿É±à³ÌÂß¼­¿ØÖÆÆ÷

JTEKT

Toyopuc

¿É±à³ÌÂß¼­¿ØÖÆÆ÷

Motorola

MOSCAD, ACE IP gateway

Ô¶³ÌÖն˵¥Ôª

Motorola

MDLC

ЭÒé

Motorola

ACE1000

Ô¶³ÌÖն˵¥Ôª

Motorola

MOSCAD Toolbox STS

¹¤³ÌÊÂÇéÕ¾

Omron

SYSMAC Cx series, Nx series

¿É±à³ÌÂß¼­¿ØÖÆÆ÷

Phoenix Contact

ProConOS

ÔËÐÐÂß¼­

Siemens

WinCC OA

¼à¿ØºÍÊý¾ÝÊÕÂÞ (SCADA)

Yokogawa

STARDOM

¿É±à³ÌÂß¼­¿ØÖÆÆ÷

 

0x02 ´¦Öý¨Òé

Ŀǰ²¿ÃʩӦÉÌÒѾ­Ðû²¼ÁËÊÜÓ°ÏìÉ豸µÄ¹Ì¼þ¸üР£¬ÊÜÓ°ÏìÓû§¿ÉÔڹ̼þ¸üпÉÓÃʱ¼°Ê±Ó¦Óà £¬¹©Ó¦ÉÌÉÐδÐû²¼¹Ì¼þ¸üеÄÓû§¿ÉÑ¡ÔñÓ¦ÓÃÒÔÏ»º½â´ëÊ©£º

l  ·¢ÏÖºÍÇåµãÍøÂçÖÐÒ×Êܹ¥»÷µÄÉ豸 £»

l  ÊµÊ©ÍøÂç·Ö¶Î¿ØÖÆ £¬ÒÔ¼õÇáÒ×Êܹ¥»÷É豸µÄ·çÏÕ £»

l  Ó¦ÓÃÉ豸¹©Ó¦ÉÌÐû²¼µÄ²¹¶¡;

l  ¼à¿ØÍøÂçÁ÷Á¿ÖÐÊÇ·ñ´æÔÚÊÔͼÀûÓé¶´µÄ¶ñÒâÊý¾Ý°ü¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.forescout.com/blog/ot-icefall-56-vulnerabilities-caused-by-insecure-by-design-practices-in-ot/

https://www.forescout.com/resources/ot-icefall-report/

https://www.bleepingcomputer.com/news/security/icefall-56-flaws-impact-thousands-of-exposed-industrial-devices/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-06-22

Ê×´ÎÐû²¼


0x05 ¸½Â¼

¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏà £¬¹«Ë¾Ô±¹¤½ü4000ÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png