ืคื’ื™ืขื•ืช ื‘ื ืชื‘ื™ MikroTik ื”ืžื•ื‘ื™ืœื” ืœื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ IPv6 RA

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2023-32154) ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื” RouterOS ื”ืžืฉืžืฉืช ื‘ื ืชื‘ื™ MikroTik, ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืœื ืžืื•ืžืช ืœื”ืคืขื™ืœ ืžืจื—ื•ืง ืงื•ื“ ื‘ืžื›ืฉื™ืจ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื”ื•ื“ืขืช ื ืชื‘ IPv6 ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“ (RA, Router Advertisement).

ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžื”ื™ืขื“ืจ ืื™ืžื•ืช ื ื›ื•ืŸ ืฉืœ ื ืชื•ื ื™ื ื”ืžื’ื™ืขื™ื ืžื‘ื—ื•ืฅ ื‘ืชื”ืœื™ืš ื”ืื—ืจืื™ ืขืœ ืขื™ื‘ื•ื“ ื‘ืงืฉื•ืช IPv6 RA (ืคืจืกื•ื ื ืชื‘), ืฉืื™ืคืฉืจ ืœื›ืชื•ื‘ ื ืชื•ื ื™ื ืžืขื‘ืจ ืœื’ื‘ื•ืœื•ืช ื”ืžืื’ืจ ื”ืžื•ืงืฆื” ื•ืœืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš ืขื ื”ืจืฉืื•ืช ืฉื•ืจืฉ. ื”ืคื’ื™ืขื•ืช ืžืชื‘ื˜ืืช ื‘ืกื ื™ืคื™ MikroTik RouterOS v6.xx ื•-v7.xx, ื›ืืฉืจ ื”ื•ื“ืขื•ืช IPv6 RA ืžื•ืคืขืœื•ืช ื‘ื”ื’ื“ืจื•ืช ืœืงื‘ืœืช ื”ื•ื“ืขื•ืช ("ipv6/settings/ set accept-router-advertisements=yes" ืื• "ipv6/settings/ set forward=no accept-router -advertisements=yes-if-forwarding-disabled").

ื”ื™ื›ื•ืœืช ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ื‘ืคื•ืขืœ ื”ื•ื›ื—ื” ื‘ืชื—ืจื•ืช Pwn2Own ื‘ื˜ื•ืจื•ื ื˜ื•, ื‘ืžื”ืœื›ื” ืงื™ื‘ืœื• ื”ื—ื•ืงืจื™ื ืฉื–ื™ื”ื• ืืช ื”ื‘ืขื™ื” ืคืจืก ืฉืœ 100,000$ ืขื‘ื•ืจ ืคืจื™ืฆื” ืจื‘-ืฉืœื‘ื™ืช ืฉืœ ื”ืชืฉืชื™ืช ืขื ื”ืชืงืคื” ืขืœ ื”ื ืชื‘ Mikrotik ื•ืฉื™ืžื•ืฉ ื‘ื• ื›. ืงืจืฉ ืงืคื™ืฆื” ืœืชืงื•ืฃ ืจื›ื™ื‘ื™ื ืื—ืจื™ื ืฉืœ ื”ืจืฉืช ื”ืžืงื•ืžื™ืช (ืœื”ืœืŸ ื”ืชืงื™ืคื” ื”ืฉืชืœื˜ื” ืขืœ ืžื“ืคืกืช Canon, ืฉื ื’ื ื ื—ืฉืคื” ื”ืคื’ื™ืขื•ืช).

ืžื™ื“ืข ืขืœ ื”ืคื’ื™ืขื•ืช ืคื•ืจืกื ื‘ืžืงื•ืจ ืœืคื ื™ ื™ืฆื™ืจืช ื”ืชื™ืงื•ืŸ ืขืœ ื™ื“ื™ ื”ื™ืฆืจืŸ (0-day), ืืš ืขื“ื›ื•ื ื™ื ืœ-RouterOS 7.9.1, 6.49.8, 6.48.7, 7.10beta8 ื›ื‘ืจ ืคื•ืจืกืžื• ื›ืฉื”ืคื’ื™ืขื•ืช ืชื•ืงื ื”. ืขืœ ืคื™ ืžื™ื“ืข ืžืคืจื•ื™ืงื˜ ZDI (Zero Day Initiative), ื”ืžืงื™ื™ื ืืช ืชื—ืจื•ืช Pwn2Own, ื”ื™ืฆืจืŸ ืงื™ื‘ืœ ื”ื•ื“ืขื” ืขืœ ื”ืคื’ื™ืขื•ืช ื‘-29 ื‘ื“ืฆืžื‘ืจ 2022. ื ืฆื™ื’ื™ MikroTik ื˜ื•ืขื ื™ื ื›ื™ ืœื ืงื™ื‘ืœื• ื”ื•ื“ืขื” ื•ื ื•ื“ืข ืœื”ื ืขืœ ื”ื‘ืขื™ื” ืจืง โ€‹โ€‹ื‘-10 ื‘ืžืื™, ืœืื—ืจ ืฉืœื™ื—ืช ื”ืื–ื”ืจื” ื”ืกื•ืคื™ืช ืขืœ ื—ืฉื™ืคืช ืžื™ื“ืข. ื‘ื ื•ืกืฃ, ื“ื•"ื— ื”ืคื’ื™ืขื•ืช ืžื–ื›ื™ืจ ืฉืžื™ื“ืข ืขืœ ืžื”ื•ืช ื”ื‘ืขื™ื” ื”ื•ืขื‘ืจ ืœื ืฆื™ื’ ืฉืœ MikroTik ื‘ืื•ืคืŸ ืื™ืฉื™ ื‘ืžื”ืœืš ืชื—ืจื•ืช Pwn2Own ื‘ื˜ื•ืจื•ื ื˜ื•, ืืš ืœื“ื‘ืจื™ MikroTik, ืขื•ื‘ื“ื™ ื”ื—ื‘ืจื” ืœื ื”ืฉืชืชืคื• ื‘ืื™ืจื•ืข ื‘ืฉื•ื ืžืขืžื“.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”