{"id":36640,"date":"2019-10-31T22:12:50","date_gmt":"2019-10-31T19:12:50","guid":{"rendered":"https:\/\/prohoster.info\/blog\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks\/"},"modified":"2019-10-31T22:12:50","modified_gmt":"2019-10-31T19:12:50","slug":"11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks","title":{"rendered":"11 vulnerabilidades explotables remotamente en la pila TCP\/IP VxWorks","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Investigadores de seguridad de la empresa Armis <noindex><a rel=\"nofollow\" href=\"https:\/\/armis.com\/armis-discovers-vulnerabilities-in-vxworks-in-critical-devices\/\">revelaron<\/a><\/noindex> informaci\u00f3n sobre <noindex><a rel=\"nofollow\" href=\"https:\/\/armis.com\/urgent11\/\">11 vulnerabilidades<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/go.armis.com\/hubfs\/White-papers\/Urgent11%20Technical%20White%20Paper.pdf\">PDF<\/a><\/noindex>) en el stack TCP\/IP IPnet, utilizado en el sistema operativo VxWorks. Los problemas han sido asignados con el nombre en clave \u2018URGENT\/11\u2019. Las vulnerabilidades pueden ser explotadas de forma remota mediante el env\u00edo de paquetes de red espec\u00edficamente dise\u00f1ados, incluida la posibilidad de realizar ataques a trav\u00e9s de firewalls y NAT (por ejemplo, si el atacante controla un servidor DNS al que se dirige un dispositivo vulnerable en la red interna).<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/armis.com\/wp-content\/uploads\/2019\/07\/u11-cloud-printing-service-e1564371849694.png\"><img decoding=\"async\" alt=\"11 vulnerabilidades explotables remotamente en la pila TCP\/IP VxWorks\" src=\"\/wp-content\/uploads\/2019\/07\/bd4bb8430a2c575d93f6a74a174daedc.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Seis problemas pueden llevar a la ejecuci\u00f3n de c\u00f3digo malicioso al procesar opciones incorrectas de IP o TCP en el paquete, as\u00ed como al analizar paquetes DHCP. Cinco de estos problemas son menos peligrosos y pueden resultar en filtraciones de informaci\u00f3n o ataques DoS. La divulgaci\u00f3n de informaci\u00f3n sobre las vulnerabilidades fue coordinada con Wind River; en la \u00faltima versi\u00f3n de VxWorks 7 SR0620 publicada la semana pasada, los problemas ya han sido corregidos.<\/p>\n<p>Dado que cada vulnerabilidad afecta diferentes partes de la pila de red, los problemas pueden ser espec\u00edficos de ciertas versiones, pero se afirma que en cada versi\u00f3n de VxWorks a partir de 6.5 aparece al menos una vulnerabilidad que permite la ejecuci\u00f3n remota de c\u00f3digo. Adem\u00e1s, para cada variante de VxWorks es necesario crear un exploit separado. Seg\u00fan la empresa Armis, el problema afecta a alrededor de 200 millones de dispositivos, incluidos equipos industriales y m\u00e9dicos, enrutadores, tel\u00e9fonos VoIP, cortafuegos, impresoras y varios dispositivos de IoT.  <\/p>\n<p>La empresa Wind River <noindex><a rel=\"nofollow\" href=\"https:\/\/blogs.windriver.com\/wind_river_blog\/2019\/07\/urgent-11-further-boosts-vxworks-security.html\">considera<\/a><\/noindex>, que esta cifra es exagerada y que el problema afecta solo a un n\u00famero relativamente peque\u00f1o de dispositivos no cr\u00edticos, que generalmente est\u00e1n limitados a la red corporativa interna. La pila de red IPnet solo se suministr\u00f3 en algunas ediciones de VxWorks, incluyendo versiones cuyo soporte ya ha finalizado (hasta 6.5). En dispositivos basados en las plataformas VxWorks 653 y VxWorks Cert Edition, utilizadas en \u00e1reas cr\u00edticas (robots industriales, electr\u00f3nica automotriz y aeron\u00e1utica), los problemas no se manifiestan.<\/p>\n<p>Los representantes de Armis consideran que, debido a la complejidad de la actualizaci\u00f3n de dispositivos vulnerables, no se puede excluir la aparici\u00f3n de gusanos que afecten a las redes locales y ataquen masivamente las categor\u00edas de dispositivos m\u00e1s populares. Por ejemplo, algunos dispositivos, como el equipo m\u00e9dico e industrial, requieren una recertificaci\u00f3n y una larga serie de pruebas cuando se actualiza el firmware, lo que dificulta el proceso de actualizaci\u00f3n.<\/p>\n<p>Wind River <noindex><a rel=\"nofollow\" href=\"https:\/\/www.windriver.com\/security\/announcements\/tcp-ip-network-stack-ipnet-urgent11\/ipnet-faq\/\">opinan<\/a><\/noindex>, por lo que en tales casos el riesgo de compromiso se puede reducir mediante la inclusi\u00f3n de las herramientas de seguridad ya existentes, como la pila no ejecutable, la protecci\u00f3n contra desbordamientos de pila, la limitaci\u00f3n de llamadas al sistema y la aislamiento de procesos. La protecci\u00f3n tambi\u00e9n se puede lograr mediante la adici\u00f3n de firmas que bloquean ataques en cortafuegos y sistemas de prevenci\u00f3n de intrusiones, as\u00ed como limitando el acceso a la red del dispositivo \u00fanicamente al per\u00edmetro de seguridad interno.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51189\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Armis \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431 11 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (PDF) \u0432 TCP\/IP \u0441\u0442\u0435\u043a\u0435 IPnet, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c \u0432 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 VxWorks. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f &#171;URGENT\/11&#187;. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0434\u043b\u044f \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u0430\u0442\u0430\u043a\u0438 \u043f\u0440\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0435 \u0447\u0435\u0440\u0435\u0437 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0435 \u044d\u043a\u0440\u0430\u043d\u044b \u0438 NAT (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0435\u0441\u043b\u0438 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27438,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-36640","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Armis \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd4711 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 TCP\/IP \u0441\u0442\u0435\u043a\u0435 VxWorks | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Armis \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:12:50+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:12:50+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd4711 vulnerabilidades explotables de manera remota en la pila TCP\/IP de VxWorks | ProHoster","description":"Investigadores de seguridad de Armis revelaron informaci\u00f3n sobre","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd4711 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 TCP\/IP \u0441\u0442\u0435\u043a\u0435 VxWorks | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Armis \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:12:50+00:00","article:modified_time":"2019-10-31T19:12:50+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36640","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 04:15:12","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 23:17:29","updated":"2026-01-22 04:15:12","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/36640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=36640"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/36640\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media\/27438"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=36640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=36640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=36640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}