19 ืคื’ื™ืขื•ื™ื•ืช ื”ื ื™ืชื ื•ืช ืœื ื™ืฆื•ืœ ืžืจื—ื•ืง ื‘ืขืจื™ืžืช TCP/IP ืฉืœ Treck

ื‘ืขืจื™ืžืช TCP/IP ืงื ื™ื™ื ื™ืช ื˜ืจืง ื’ื™ืœื” 19 ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ืžื ื•ืฆืœ ื‘ืืžืฆืขื•ืช ืฉืœื™ื—ืช ื—ื‘ื™ืœื•ืช ืžืขื•ืฆื‘ื•ืช ื‘ืžื™ื•ื—ื“. ืœืคืจืฆื•ืช ื”ื•ืงืฆื” ืฉื ืงื•ื“ ืื“ื•ื•ื” 20. ื›ืžื” ืคื’ื™ืขื•ื™ื•ืช ืžื•ืคื™ืขื•ืช ื’ื ื‘ืขืจื™ืžืช KASAGO TCP/IP ืžื‘ื™ืช Zuken Elmic (Elmic Systems), ืฉื™ืฉ ืœื” ืฉื•ืจืฉื™ื ืžืฉื•ืชืคื™ื ืขื Treck. ืขืจื™ืžืช ื”-Track ืžืฉืžืฉืช ื‘ืžื›ืฉื™ืจื™ื ืชืขืฉื™ื™ืชื™ื™ื, ืจืคื•ืื™ื™ื, ืชืงืฉื•ืจืชื™ื™ื, ืžืฉื•ื‘ืฆื™ื ื•ืฆืจื›ื ื™ื™ื ืจื‘ื™ื (ืžื ื•ืจื•ืช ื—ื›ืžื•ืช ืœืžื“ืคืกื•ืช ื•ืกืคืงื™ ื›ื•ื— ืืœ-ืคืกืง), ื›ืžื• ื’ื ื‘ืฆื™ื•ื“ ืื ืจื’ื™ื”, ืชื—ื‘ื•ืจื”, ืชืขื•ืคื”, ืžืกื—ืจื™ ื•ื”ืคืงืช ื ืคื˜.

19 ืคื’ื™ืขื•ื™ื•ืช ื”ื ื™ืชื ื•ืช ืœื ื™ืฆื•ืœ ืžืจื—ื•ืง ื‘ืขืจื™ืžืช TCP/IP ืฉืœ Treck

ื™ืขื“ื™ ืชืงื™ืคื” ื‘ื•ืœื˜ื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืขืจื™ืžืช TCP/IP ืฉืœ Treck ื›ื•ืœืœื™ื ืžื“ืคืกื•ืช ืจืฉืช ืฉืœ HP ื•ืฉื‘ื‘ื™ ืื™ื ื˜ืœ. ื‘ื™ืŸ ื”ื™ืชืจ, ื‘ืขื™ื•ืช ื‘ืขืจื™ืžืช TCP/IP ืฉืœ Treck ื”ืชื‘ืจืจื• ื›ื’ื•ืจื ืœืื—ืจื•ื ื” ืคื’ื™ืขื•ืช ืžืจื—ื•ืง ื‘ืชืชื™ ืžืขืจื›ื•ืช Intel AMT ื•-ISM, ื”ืžื•ืคืขืœื•ืช ื‘ืืžืฆืขื•ืช ืฉืœื™ื—ืช ื—ื‘ื™ืœืช ืจืฉืช. ื ื•ื›ื—ื•ืชืŸ ืฉืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืื•ืฉืจื” ืขืœ ื™ื“ื™ ื”ื™ืฆืจื ื™ื•ืช ืื™ื ื˜ืœ, HP, Hewlett Packard Enterprise, Baxter, Caterpillar, Digi, Rockwell Automation ื•ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง. ื™ื•ืชืจ
66 ื™ืฆืจื ื™ื, ืฉืžื•ืฆืจื™ื• ืžืฉืชืžืฉื™ื ื‘ืขืจื™ืžืช TCP/IP ืฉืœ Treck, ื˜ืจื ื”ื’ื™ื‘ื• ืœื‘ืขื™ื•ืช. 5 ื™ืฆืจื ื™ื, ื›ื•ืœืœ AMD, ืฆื™ื™ื ื• ืฉื”ืžื•ืฆืจื™ื ืฉืœื”ื ืื™ื ื ืจื’ื™ืฉื™ื ืœื‘ืขื™ื•ืช.

19 ืคื’ื™ืขื•ื™ื•ืช ื”ื ื™ืชื ื•ืช ืœื ื™ืฆื•ืœ ืžืจื—ื•ืง ื‘ืขืจื™ืžืช TCP/IP ืฉืœ Treck

ื ืžืฆืื• ื‘ืขื™ื•ืช ื‘ื™ื™ืฉื•ื ืคืจื•ื˜ื•ืงื•ืœื™ IPv4, IPv6, UDP, DNS, DHCP, TCP, ICMPv4 ื•-ARP, ื•ื ื’ืจืžื• ืžืขื™ื‘ื•ื“ ืฉื’ื•ื™ ืฉืœ ืคืจืžื˜ืจื™ ื’ื•ื“ืœ ื ืชื•ื ื™ื (ืฉื™ืžื•ืฉ ื‘ืฉื“ื” ื’ื•ื“ืœ ืœืœื ื‘ื“ื™ืงืช ื’ื•ื“ืœ ื”ื ืชื•ื ื™ื ื‘ืคื•ืขืœ), ืฉื’ื™ืื•ืช ื‘ ื‘ื“ื™ืงืช ืžื™ื“ืข ืงืœื˜, ืฉื—ืจื•ืจ ื›ืคื•ืœ ืฉืœ ื–ื™ื›ืจื•ืŸ, ืงืจื™ืื•ืช ืžื—ื•ืฅ ืœืžืื’ืจ, ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื, ื‘ืงืจืช ื’ื™ืฉื” ืฉื’ื•ื™ื” ื•ื‘ืขื™ื•ืช ื‘ื˜ื™ืคื•ืœ ื‘ืžื—ืจื•ื–ื•ืช ืžื•ืคืจื“ื•ืช ืืคืก.

ืฉืชื™ ื”ื‘ืขื™ื•ืช ื”ืžืกื•ื›ื ื•ืช ื‘ื™ื•ืชืจ (CVE-2020-11896, CVE-2020-11897), ืœื”ืŸ ืžื•ืงืฆื•ืช CVSS ืจืžื” 10, ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืžื›ืฉื™ืจ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžื ื•ืช IPv4/UDP ืื• IPv6 ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“. ื”ื‘ืขื™ื” ื”ืงืจื™ื˜ื™ืช ื”ืจืืฉื•ื ื” ืžื•ืคื™ืขื” ื‘ืžื›ืฉื™ืจื™ื ืขื ืชืžื™ื›ื” ื‘ืžื ื”ืจื•ืช IPv4, ื•ื”ืฉื ื™ื™ื” ื‘ื’ืจืกืื•ืช ืฉืคื•ืจืกืžื• ืœืคื ื™ 04.06.2009/6/9 ืขื ืชืžื™ื›ื” ื‘-IPv2020. ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ื ื•ืกืคืช (CVSS 11901) ืงื™ื™ืžืช ื‘ืคื•ืชืจ ื”-DNS (CVE-XNUMX-XNUMX) ื•ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉืช DNS ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“ (ื”ื‘ืขื™ื” ืฉื™ืžืฉื” ืœื”ื“ื’ืžืช ื”ืคืจื™ืฆื” ืฉืœ Schneider Electric APC UPS ื•ืžื•ืคื™ืขื” ื‘ืžื›ืฉื™ืจื™ื ืขื ืชืžื™ื›ื” ื‘-DNS).

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืื—ืจื•ืช CVE-2020-11898, CVE-2020-11899, CVE-2020-11902, CVE-2020-11903, CVE-2020-11905 ืžืืคืฉืจื•ืช ืœื—ืฉื•ืฃ ืืช ื”ืชื•ื›ืŸ ืฉืœ IPv4/ICDHMPv4, IPv6OverIPv4, IPv6OverIPv6, ืื• IPvXNUMXOverIPvXNUMX, ืฉืœื™ื—ืช ืžื ื•ืช ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“ ืื–ื•ืจื™ ื–ื™ื›ืจื•ืŸ ืžืขืจื›ืช. ื‘ืขื™ื•ืช ืื—ืจื•ืช ืขืœื•ืœื•ืช ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช ืื• ืœื“ืœื™ืคื” ืฉืœ ื ืชื•ื ื™ื ืฉื™ื•ืจื™ื™ื ืžืžืื’ืจื™ ื”ืžืขืจื›ืช.

ืจื•ื‘ ื”ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช ื‘-Track 6.0.1.67 (CVE-2020-11897 ืชื•ืงืŸ ื‘-5.0.1.35, CVE-2020-11900 ื‘-6.0.1.41, CVE-2020-11903 ื‘-6.0.1.28 ื‘-CVE-2020, ื‘-CVE-11908 4.7.1.27. 20). ืžื›ื™ื•ื•ืŸ ืฉื”ื›ื ืช ืขื“ื›ื•ื ื™ ืงื•ืฉื—ื” ืœืžื›ืฉื™ืจื™ื ืกืคืฆื™ืคื™ื™ื ืขืœื•ืœื” ืœื”ืชืขื›ื‘ ืื• ื‘ืœืชื™ ืืคืฉืจื™ืช (ืžื—ืกื ื™ืช ื”-Track ื–ืžื™ื ื” ื›ื‘ืจ ื™ื•ืชืจ ืž-6 ืฉื ื”, ืžื›ืฉื™ืจื™ื ืจื‘ื™ื ื ื•ืชืจื• ืœื ืžืชื•ื—ื–ืงื™ื ืื• ืฉืงืฉื” ืœืขื“ื›ืŸ), ืžื•ืžืœืฅ ืœืžื ื”ืœื™ ืžืขืจื›ืช ืœื‘ื•ื“ื“ ืžื›ืฉื™ืจื™ื ื‘ืขื™ื™ืชื™ื™ื ื•ืœื”ื’ื“ื™ืจ ืžืขืจื›ื•ืช ื‘ื“ื™ืงืช ืžื ื•ืช, ื—ื•ืžื•ืช ืืฉ. ืื• ื ืชื‘ื™ื ื›ื“ื™ ืœื ืจืžืœ ืื• ืœื—ืกื•ื ืžื ื•ืช ืžืงื•ื˜ืขื•ืช, ืœื—ืกื•ื ืžื ื”ืจื•ืช IP (IPv4-in-IPv6 ื•-IP-in-IP), ืœื—ืกื•ื "ื ื™ืชื•ื‘ ืžืงื•ืจ", ืœืืคืฉืจ ื‘ื“ื™ืงื” ืฉืœ ืืคืฉืจื•ื™ื•ืช ืฉื’ื•ื™ื•ืช ื‘ื—ื‘ื™ืœื•ืช TCP, ืœื—ืกื•ื ื”ื•ื“ืขื•ืช ื‘ืงืจืช ICMP ืฉืื™ื ืŸ ื‘ืฉื™ืžื•ืฉ (ืขื“ื›ื•ืŸ MTU ื•- ืžืกื™ื›ืช ื›ืชื•ื‘ืช), ื‘ื˜ืœ ืฉื™ื“ื•ืจ IPvXNUMX ื•ื”ืคื ื™ื” ืžื—ื“ืฉ ืฉืœ ืฉืื™ืœืชื•ืช DNS ืœืฉืจืช DNS ืจืงื•ืจืกื™ื‘ื™ ืžืื•ื‘ื˜ื—.


ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”