ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ื‘-150 ื“ื’ืžื™ ืžื“ืคืกื•ืช HP LaserJet ื•-PageWide

ื—ื•ืงืจื™ ืื‘ื˜ื—ื” ืž-F-Secure ื–ื™ื”ื• ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2021-39238) ื”ืžืฉืคื™ืขื” ืขืœ ื™ื•ืชืจ ืž-150 ืžื“ืคืกื•ืช ื•-MFP ืฉืœ HP LaserJet, LaserJet Managed, PageWide ื•-PageWide. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืš ืœื’ืจื•ื ืœื”ืฆืคืช ืžืื’ืจ ื‘ืžืขื‘ื“ ื”ืคื•ื ื˜ื™ื ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžืกืžืš PDF ืฉืชื•ื›ื ืŸ ื‘ืžื™ื•ื—ื“ ืœื”ื“ืคืกื” ื•ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืฉืœ ื”ืงื•ื“ ืฉืœืš ื‘ืจืžืช ื”ืงื•ืฉื—ื”. ื”ื‘ืขื™ื” ืงื™ื™ืžืช ืžืื– 2013 ื•ืชื•ืงื ื” ื‘ืขื“ื›ื•ื ื™ ืงื•ืฉื—ื” ืฉืคื•ืจืกืžื• ื‘-1 ื‘ื ื•ื‘ืžื‘ืจ (ื”ื™ืฆืจืŸ ืงื™ื‘ืœ ื”ื•ื“ืขื” ืขืœ ื”ื‘ืขื™ื” ื‘ืืคืจื™ืœ).

ื”ื”ืชืงืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ื”ืŸ ื‘ืžื“ืคืกื•ืช ื”ืžื—ื•ื‘ืจื•ืช ืžืงื•ืžื™ื•ืช ื•ื”ืŸ ื‘ืžืขืจื›ื•ืช ื”ื“ืคืกื” ื‘ืจืฉืช. ืœื“ื•ื’ืžื”, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื˜ื›ื ื™ืงื•ืช ื”ื ื“ืกื” ื—ื‘ืจืชื™ืช ื›ื“ื™ ืœืืœืฅ ืžืฉืชืžืฉ ืœื”ื“ืคื™ืก ืงื•ื‘ืฅ ื–ื“ื•ื ื™, ืœืชืงื•ืฃ ืžื“ืคืกืช ื“ืจืš ืžืขืจื›ืช ืžืฉืชืžืฉ ืฉื›ื‘ืจ ื ืคื’ืขืช, ืื• ืœื”ืฉืชืžืฉ ื‘ื˜ื›ื ื™ืงื” ื“ื•ืžื” ืœ-"DNS rebinding", ื”ืžืืคืฉืจืช, ื›ืืฉืจ ืžืฉืชืžืฉ ืคื•ืชื— ืงื•ื‘ืฅ ืžืกื•ื™ื. ืขืžื•ื“ ื‘ื“ืคื“ืคืŸ, ื›ื“ื™ ืœืฉืœื•ื— ื‘ืงืฉืช HTTP ืœื™ืฆื™ืืช ื”ืจืฉืช ืฉืœ ื”ืžื“ืคืกืช (9100/TCP, JetDirect), ืœื ื–ืžื™ื ื” ืœื’ื™ืฉื” ื™ืฉื™ืจื” ื“ืจืš ื”ืื™ื ื˜ืจื ื˜.

ืœืื—ืจ ื ื™ืฆื•ืœ ืžื•ืฆืœื— ืฉืœ ื”ืคื’ื™ืขื•ืช, ืžื“ืคืกืช ืฉื ืคืจืฆื” ื™ื›ื•ืœื” ืœืฉืžืฉ ื›ืžืงืคืฆื” ืœื”ืคืขืœืช ื”ืชืงืคื” ืขืœ ืจืฉืช ืžืงื•ืžื™ืช, ืœืจื—ืจื— ืชืขื‘ื•ืจื” ืื• ืœื”ืฉืื™ืจ ื ืงื•ื“ืช ื ื•ื›ื—ื•ืช ื ืกืชืจืช ืœืชื•ืงืคื™ื ื‘ืจืฉืช ื”ืžืงื•ืžื™ืช. ื”ืคื’ื™ืขื•ืช ืžืชืื™ืžื” ื’ื ืœื‘ื ื™ื™ืช ื‘ื•ื˜ื ื˜ื™ื ืื• ื™ืฆื™ืจืช ืชื•ืœืขื™ ืจืฉืช ืฉืกื•ืจืงื•ืช ืžืขืจื›ื•ืช ืคื’ื™ืขื•ืช ืื—ืจื•ืช ื•ืžื ืกื•ืช ืœื”ื“ื‘ื™ืง ืื•ืชืŸ. ื›ื“ื™ ืœื”ืคื—ื™ืช ืืช ื”ื ื–ืง ืžื”ืชืคืฉืจื•ืช ืขืœ ื”ืžื“ืคืกืช, ืžื•ืžืœืฅ ืœืžืงื ืžื“ืคืกื•ืช ืจืฉืช ื‘-VLAN ื ืคืจื“, ืœื”ื’ื‘ื™ืœ ืืช ื—ื•ืžืช ื”ืืฉ ืžื™ืฆื™ืจืช ื—ื™ื‘ื•ืจื™ ืจืฉืช ื™ื•ืฆืื™ื ืžืžื“ืคืกื•ืช ื•ืœื”ืฉืชืžืฉ ื‘ืฉืจืช ื”ื“ืคืกื” ื‘ื™ื ื™ื™ื ื ืคืจื“ ื‘ืžืงื•ื ืœื’ืฉืช ื™ืฉื™ืจื•ืช ืœืžื“ืคืกืช ืžืชื—ื ื•ืช ืขื‘ื•ื“ื”.

ื—ื•ืงืจื™ื ื–ื™ื”ื• ื’ื ืคื’ื™ืขื•ืช ื ื•ืกืคืช (CVE-2021-39237) ื‘ืžื“ืคืกื•ืช HP, ื”ืžืืคืฉืจืช ืœืงื‘ืœ ื’ื™ืฉื” ืžืœืื” ืœืžื›ืฉื™ืจ. ื‘ื ื™ื’ื•ื“ ืœืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื”, ืœื‘ืขื™ื” ืžื•ืงืฆื™ืช ืจืžืช ืกื›ื ื” ื‘ื™ื ื•ื ื™ืช, ืฉื›ืŸ ื”ื”ืชืงืคื” ื“ื•ืจืฉืช ื’ื™ืฉื” ืคื™ื–ื™ืช ืœืžื“ืคืกืช (ืฆืจื™ืš ืœื”ืชื—ื‘ืจ ืœื™ืฆื™ืืช UART ืœืžืฉืš ื›-5 ื“ืงื•ืช).



ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”