{"id":36640,"date":"2019-10-31T22:12:50","date_gmt":"2019-10-31T19:12:50","guid":{"rendered":"https:\/\/prohoster.info\/blog\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks\/"},"modified":"2019-10-31T22:12:50","modified_gmt":"2019-10-31T19:12:50","slug":"11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks","title":{"rendered":"11 vulnerabilit\u0103\u021bi exploatabile de la distan\u021b\u0103 \u00een stiva TCP\/IP VxWorks","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Cercet\u0103torii \u00een securitate de la Armis <noindex><a rel=\"nofollow\" href=\"https:\/\/armis.com\/armis-discovers-vulnerabilities-in-vxworks-in-critical-devices\/\">au dezv\u0103luit<\/a><\/noindex> informa\u021bii despre <noindex><a rel=\"nofollow\" href=\"https:\/\/armis.com\/urgent11\/\">11 vulnerabilit\u0103\u021bi<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/go.armis.com\/hubfs\/White-papers\/Urgent11%20Technical%20White%20Paper.pdf\">PDF<\/a><\/noindex>) \u00een stiva TCP\/IP IPnet, utilizat\u0103 \u00een sistemul de operare VxWorks. Problemele au primit numele de cod \u201eURGENT\/11\u201d. Vulnerabilit\u0103\u021bile pot fi exploatate de la distan\u021b\u0103 prin trimiterea de pachete de re\u021bea formate special, inclusiv pentru unele probleme este posibil s\u0103 se efectueze un atac prin intermediul firewall-urilor \u0219i NAT (de exemplu, dac\u0103 atacatorul controleaz\u0103 serverul DNS la care se conecteaz\u0103 dispozitivul vulnerabil aflat \u00eentr-o re\u021bea intern\u0103).<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/armis.com\/wp-content\/uploads\/2019\/07\/u11-cloud-printing-service-e1564371849694.png\"><img decoding=\"async\" alt=\"11 vulnerabilit\u0103\u021bi exploatabile de la distan\u021b\u0103 \u00een stiva TCP\/IP VxWorks\" src=\"\/wp-content\/uploads\/2019\/07\/bd4bb8430a2c575d93f6a74a174daedc.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>\u0218ase probleme pot duce la executarea codului de c\u0103tre un atacator \u00een timpul proces\u0103rii op\u021biunilor IP sau TCP incorect configurate \u00een pachet, precum \u0219i \u00een timpul analizei pachetelor DHCP. Cinci dintre probleme sunt mai pu\u021bin periculoase \u0219i pot duce la scurgeri de informa\u021bii sau la atacuri DoS. Divulgarea informa\u021biilor despre vulnerabilit\u0103\u021bi a fost coordonat\u0103 cu compania Wind River - \u00een ultima actualizare publicat\u0103 s\u0103pt\u0103m\u00e2na trecut\u0103, \u00een VxWorks 7 SR0620 problemele au fost deja remediate.<\/p>\n<p>Deoarece fiecare vulnerabilitate afecteaz\u0103 diferite p\u0103r\u021bi ale stivei de re\u021bea, problemele pot fi specifice anumitor versiuni, dar se sus\u021bine c\u0103 \u00een fiecare versiune VxWorks \u00eencep\u00e2nd cu 6.5 apare cel pu\u021bin o vulnerabilitate care permite executarea de cod la distan\u021b\u0103. Totu\u0219i, pentru fiecare variant\u0103 VxWorks este necesar\u0103 crearea unui exploit separaat. Conform estim\u0103rilor companiei Armis, problema afecteaz\u0103 aproximativ 200 de milioane de dispozitive, inclusiv echipamente industriale \u0219i medicale, routere, telefoane VOIP, firewall-uri, imprimante \u0219i diverse dispozitive IoT.  <\/p>\n<p>Compania Wind River <noindex><a rel=\"nofollow\" href=\"https:\/\/blogs.windriver.com\/wind_river_blog\/2019\/07\/urgent-11-further-boosts-vxworks-security.html\">consider\u0103<\/a><\/noindex>, consider\u0103 c\u0103 acest num\u0103r este exagerat \u0219i c\u0103 problema acoper\u0103 doar un num\u0103r relativ mic de dispozitive necritice, care, de obicei, sunt limitate la re\u021belele corporative interne. Stiva de re\u021bea IPnet a fost livrat\u0103 doar \u00een unele edi\u021bii VxWorks, inclusiv versiuni ale c\u0103ror suport a fost deja \u00eencheiat (p\u00e2n\u0103 la 6.5). \u00cen dispozitivele bazate pe platformele VxWorks 653 \u0219i VxWorks Cert Edition, utilizate \u00een domenii critice (robo\u021bi industriali, electronic\u0103 auto \u0219i aeronautic\u0103), problemele nu se manifest\u0103.<\/p>\n<p>Reprezentan\u021bii Armis consider\u0103 c\u0103, din cauza complexit\u0103\u021bii actualiz\u0103rii dispozitivelor vulnerabile, nu este exclus\u0103 apari\u021bia de viermi care afecteaz\u0103 re\u021belele locale \u0219i atac\u0103 \u00een mas\u0103 cele mai populare categorii de dispozitive vulnerabile. De exemplu, unele dispozitive, cum ar fi cele medicale \u0219i industriale, necesit\u0103 reacreditare \u0219i teste extinse atunci c\u00e2nd firmware-ul este actualizat, ceea ce \u00eengreuneaz\u0103 actualizarea acestora.<\/p>\n<p>Wind River <noindex><a rel=\"nofollow\" href=\"https:\/\/www.windriver.com\/security\/announcements\/tcp-ip-network-stack-ipnet-urgent11\/ipnet-faq\/\">consider\u0103<\/a><\/noindex>, astfel \u00eenc\u00e2t, \u00een astfel de cazuri, riscul de compromis poate fi redus prin activarea unor instrumente de securitate deja existente, cum ar fi stiva non-executabil\u0103, protec\u021bia \u00eempotriva suprascrierii stivei, limitarea apelurilor de sistem \u0219i izolarea proceselor. Securitatea poate fi, de asemenea, asigurat\u0103 prin ad\u0103ugarea de semn\u0103turi de blocare a atacurilor pe firewall-uri \u0219i sistemele de prevenire a intruziunilor, precum \u0219i prin limitarea accesului la re\u021bea al dispozitivelor doar la perimetrul de securitate intern.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51189\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Armis \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431 11 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (PDF) \u0432 TCP\/IP \u0441\u0442\u0435\u043a\u0435 IPnet, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c \u0432 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 VxWorks. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f &#171;URGENT\/11&#187;. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0434\u043b\u044f \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u0430\u0442\u0430\u043a\u0438 \u043f\u0440\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0435 \u0447\u0435\u0440\u0435\u0437 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0435 \u044d\u043a\u0440\u0430\u043d\u044b \u0438 NAT (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0435\u0441\u043b\u0438 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27438,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-36640","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Armis \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd4711 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 TCP\/IP \u0441\u0442\u0435\u043a\u0435 VxWorks | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Armis \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:12:50+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:12:50+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd4711 vulnerabilit\u0103\u021bi exploatabile de la distan\u021b\u0103 \u00een stiva TCP\/IP VxWorks | ProHoster","description":"Cercet\u0103torii \u00een securitate de la compania Armis au dezv\u0103luit informa\u021bii despre","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd4711 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 TCP\/IP \u0441\u0442\u0435\u043a\u0435 VxWorks | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Armis \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/11-udalyonno-ekspluatiruemyh-uyazvimostej-v-tcp-ip-steke-vxworks","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:12:50+00:00","article:modified_time":"2019-10-31T19:12:50+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36640","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 04:15:12","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 23:17:29","updated":"2026-01-22 04:15:12","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/36640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=36640"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/36640\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media\/27438"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=36640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=36640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=36640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}