安全研究
安全漏洞
Johnson Controls Metasys XML外部实体引用漏洞(CVE-2020-9044)
发布日期:2020-03-10
更新日期:2020-03-11
受影响系统:Johnson Controls Metasys System Configuration Tool (SCT
Johnson Controls Metasys Smoke Control Network Automati
Johnson Controls Metasys Open Data Server (ODS): <=Rele
Johnson Controls Metasys Open Application Server (OAS):
Johnson Controls Metasys Network Integration Engine (NI
Johnson Controls Metasys Network Automation Engine (NAE
Johnson Controls Metasys NAE85 and NIE85: <=Release 10.
Johnson Controls Metasys LonWorks Control Server (LCS):
Johnson Controls Metasys Extended Application and Data
Johnson Controls Metasys Application and Data Server (A
描述:
CVE(CAN) ID:
CVE-2020-9044
Johnson Controls Metasys是楼宇自控系统。
Metasys某些版本在实现中存在XML外部实体引用漏洞,攻击者利用此漏洞可获取服务器中的ASCII文件。
<*来源:Lukasz Rupala
*>
建议:
厂商补丁:
Johnson Controls
----------------
目前厂商已经发布了升级补丁以修复这个安全问题,细节请参考产品安全公告:
https://www.johnsoncontrols.com/cyber-solutions/security-advisories
email:
productsecurity@jci.com浏览次数:1298
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载 绿盟科技给您安全的保障 |