GE Communicator¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-05-08

Îó²î±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-6564£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-6546£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-6548£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-6544£¬Î£ÏÕ¼¶±ð£ºÖм¶£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.6£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-6566£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.3£¬¹Ù·½Î´ÆÀ¶¨



Ó°Ïì°æ±¾¼°²úÆ·



ËùÓеÍÓÚ4.0.517°æ±¾µÄÈçÏÂCommunicator×é¼þ£º


Communicator Installer
Communicator Application
Communicator PostGreSQL
Communicator MeterManager

Communicator WISE Uninstaller



Îó²î¸ÅÊö



GE CommunicatorÊÇÃÀ¹úͨÓÃµçÆø£¨GE£©¹«Ë¾µÄÒ»¿îÓÃÓÚ¼ÆÁ¿×°±¸µÄ±à³ÌºÍ¼à²âµÄÓ¦ÓóÌÐò ¡£¸Ã¹¤¾ß±»Ììϸ÷µØµÄµçÁ¦¹«Ë¾£¬´óÐÍÖÆÔìÉÌºÍÆäËûÀàÐ͵Ä×é֯ʹÓà ¡£ICS-CERT͸¶£¬GE Communicator±£´æÒÔÏÂÎó²î£º


CVE-2019-6564

¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·µÄ´úÂ뿪·¢Àú³ÌÖб£´æÉè¼Æ»òʵÏÖ²»µ±µÄÎÊÌâ ¡£·Ç¹ÜÀíÓû§¿ÉÄܻὫ¶ñÒâÎļþ·ÅÔÚ×°ÖóÌÐòÎļþĿ¼ÖУ¬Õâ¿ÉÄÜÔÊÐí¹¥»÷ÕßÔÚ×°ÖûòÉý¼¶Ê±´ú»ñµÃϵͳµÄ¹ÜÀíȨÏÞ ¡£


CVE-2019-6546

¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·µÄ´úÂ뿪·¢Àú³ÌÖб£´æÉè¼Æ»òʵÏÖ²»µ±µÄÎÊÌâ ¡£¹¥»÷Õß¿ÉÄܽ«¶ñÒâÎļþ·ÅÔÚ³ÌÐòµÄÊÂÇéĿ¼ÖУ¬Õâ¿ÉÄÜÔÊÐí¹¥»÷ÕßʹÓÃС²¿¼þºÍUIÔªËØ ¡£


CVE-2019-6548

¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·ÖÐȱ·¦ÓÐÓõÄÐÅÈιÜÀí»úÖÆ ¡£±£´æ¾ßÓÐÓ²±àÂëÆ¾Ö¤µÄÁ½¸öºóÃÅÕÊ»§£¬Õâ¿ÉÒÔÔÊÐí¿ØÖÆÊý¾Ý¿â ¡£ÈôÊÇ×îÖÕÓû§Ê¹ÓÃWindowsĬÈÏ·À»ðǽÉèÖã¬Ôò¹¥»÷ÕßÎÞ·¨»á¼û´Ë·þÎñ ¡£


CVE-2019-6544

¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úƷδ׼ȷÏÞÖÆÀ´×ÔδÊÚȨ½ÇÉ«µÄ×ÊÔ´»á¼û ¡£Ê¹ÓÃÏµÍ³ÌØÈ¨ÔËÐеķþÎñ¿ÉÄÜÔÊÐí·ÇÌØÈ¨Óû§Ö´ÐÐijЩ¹ÜÀí²Ù×÷£¬Õâ¿ÉÄÜÔÊÐíÖ´ÐоßÓÐϵͳ¹ÜÀíԱȨÏ޵ĵ÷Àí¾ç±¾ ¡£ÈôÊÇ×îÖÕÓû§Ê¹ÓÃWindowsĬÈÏ·À»ðǽÉèÖã¬Ôò¹¥»÷ÕßÎÞ·¨»á¼û´Ë·þÎñ ¡£


CVE-2019-6566

¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úƷδ׼ȷÏÞÖÆÀ´×ÔδÊÚȨ½ÇÉ«µÄ×ÊÔ´»á¼û ¡£·Ç¹ÜÀíÓû§¿ÉÄÜ»áʹÓöñÒâ°æ±¾Ìæ»»Ð¶ÔØ³ÌÐò£¬Õâ¿ÉÄÜÔÊÐí¹¥»÷Õß»ñµÃϵͳµÄ¹ÜÀíԱȨÏÞ ¡£



Îó²îÑéÖ¤



ÔÝÎÞPOC/EXP ¡£



ÐÞ¸´½¨Òé



ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£ºhttps://www.gegridsolutions.com/app/ViewFiles.aspx?prod=EPM9700&type=7 ¡£



²Î¿¼Á´½Ó



https://ics-cert.us-cert.gov/advisories/ICSA-19-122-02