19 ืจื™ืžืึธื•ื˜ืœื™ ืขืงืกืคึผืœืึธื™ื˜ืึทื‘ืœืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื˜ืจืขืง ืก TCP / IP ืกื˜ืึทืง

ืื™ืŸ ืึท ืคึผืจืึทืคึผืจื™ื™ืึทื˜ืขืจื™ TCP / IP ืึธื ืœื™ื™ื’ืŸ ื˜ืจืขืง ืื ื˜ืคืœืขืงื˜ 19 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ื“ื•ืจืš ื“ื™ ืฉื™ืงื˜ ืคื•ืŸ ืกืคึผืขืฉืœื™ ื“ื™ื–ื™ื™ื ื“ ืคึผืึทืงืึทื“ื–ืฉืึทื–. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืึทืกื™ื™ื ื“ ืึท ืงืึธื“ ื ืึธืžืขืŸ ืจื™ืคึผืึทืœ20. ืขื˜ืœืขื›ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื•ื™ืš ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื™ืŸ ื“ื™ KASAGO TCP / IP ืึธื ืœื™ื™ื’ืŸ ืคึฟื•ืŸ Zuken Elmic (Elmic Systems), ื•ื•ืึธืก ื”ืื˜ ืคึผืจืึธืกื˜ ืจื•ืฅ ืžื™ื˜ ื˜ืจืขืง. ื“ื™ ื˜ืจืขืง ืกื˜ืึทืง ืื™ื– ื’ืขื ื™ืฆื˜ ืื™ืŸ ืคื™ืœืข ื™ื ื“ืึทืกื˜ืจื™ืึทืœ, ืžืขื“ื™ืฆื™ื ื™ืฉ, ืงืึธืžื•ื ื™ืงืึทืฆื™ืข, ืขืžื‘ืขื“ื™ื“ ืื•ืŸ ืงืึทื ืกื•ืžืขืจ ื“ืขื•ื•ื™ืกืขืก (ืคื•ืŸ ืกืžืึทืจื˜ ืœืืžืคืŸ ืฆื• ืคึผืจื™ื ื˜ืขืจืก ืื•ืŸ ืึทื ื™ื ื˜ืขืจืึทืคึผื˜ืึทื‘ืึทืœ ืžืึทื›ื˜ ืกื•ืคึผืคึผืœื™ืขืก), ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืื™ืŸ ืขื ืขืจื’ื™ืข, ื˜ืจืึทื ืกืคึผืขืจื˜ื™ื™ืฉืึทืŸ, ื™ื™ื•ื•ื™ื™ื™ืฉืึทืŸ, ื’ืขืฉืขืคื˜ ืื•ืŸ ื™ื™ืœ ืคึผืจืึธื“ื•ืงืฆื™ืข ื•ื™ืกืจื™ื›ื˜.

19 ืจื™ืžืึธื•ื˜ืœื™ ืขืงืกืคึผืœืึธื™ื˜ืึทื‘ืœืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื˜ืจืขืง ืก TCP / IP ืกื˜ืึทืง

ื ืึธื•ื˜ืึทื‘ืึทืœ ื‘ืึทืคืึทืœืŸ ื˜ืึทืจื’ืึทืฅ ื ื™ืฆืŸ ื˜ืจืขืง ืก TCP / IP ืึธื ืœื™ื™ื’ืŸ ืึทืจื™ื™ึทื ื ืขืžืขืŸ ื”ืคึผ ื ืขืฅ ืคึผืจื™ื ื˜ืขืจืก ืื•ืŸ ื™ื ื˜ืขืœ ื˜ืฉื™ืคึผืก. ืฆื•ื•ื™ืฉืŸ ืื ื“ืขืจืข ื–ืื›ืŸ, ืคึผืจืึธื‘ืœืขืžืก ืื™ืŸ ื“ื™ ื˜ืจืขืง TCP / IP ืึธื ืœื™ื™ื’ืŸ ืื™ื– ื’ืขื•ื•ืขืŸ ื“ื™ ื’ืจื•ื ื˜ ืคื•ืŸ ื“ื™ ืœืขืฆื˜ืข ื•ื•ื™ื™ึทื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ Intel AMT ืื•ืŸ ISM ืกืึทื‘ืกื™ืกื˜ืึทืžื–, ืึทืคึผืขืจื™ื™ื˜ืึทื“ ื“ื•ืจืš ืฉื™ืงืŸ ืึท ื ืขืฅ ืคึผืึทืงืึทื˜. ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ื– ื‘ืืฉื˜ืขื˜ื™ืงื˜ ื“ื•ืจืš ืžืึทื ื™ืึทืคืึทืงื˜ืฉืขืจืขืจื– Intel, HP, Hewlett Packard Enterprise, Baxter, Caterpillar, Digi, Rockwell Automation ืื•ืŸ Schneider Electric. ืžืขืจ
66 ืžืึทื ื™ืึทืคืึทืงื˜ืฉืขืจืขืจื–, ื•ื•ืขืžืขื ืก ืคึผืจืึธื“ื•ืงื˜ืŸ ื ื•ืฆืŸ ื˜ืจืขืง ืก TCP / IP ืึธื ืœื™ื™ื’ืŸ, ื”ืึธื‘ืŸ ื ื™ืฉื˜ ื ืึธืš ืจื™ืกืคึผืึทื ื“ ืฆื• ื“ื™ ืคืจืื‘ืœืขืžืขืŸ. 5 ืžืึทื ื™ืึทืคืึทืงื˜ืฉืขืจืขืจื–, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืึทืžื“, ืกื˜ื™ื™ื˜ื™ื“ ืึทื– ื–ื™ื™ืขืจ ืคึผืจืึธื“ื•ืงื˜ืŸ ื–ืขื ืขืŸ ื ื™ืฉื˜ ืกืึทืกืขืคึผื˜ืึทื‘ืึทืœ ืฆื• ืคึผืจืึธื‘ืœืขืžืก.

19 ืจื™ืžืึธื•ื˜ืœื™ ืขืงืกืคึผืœืึธื™ื˜ืึทื‘ืœืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื˜ืจืขืง ืก TCP / IP ืกื˜ืึทืง

ืคึผืจืึธื‘ืœืขืžืก ื–ืขื ืขืŸ ื’ืขืคึฟื•ื ืขืŸ ืื™ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ IPv4, IPv6, UDP, DNS, DHCP, TCP, ICMPv4 ืื•ืŸ ARP ืคึผืจืึธื˜ืึธืงืึธืœืก, ืื•ืŸ ื–ืขื ืขืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืคืึทืœืฉ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ ื“ืึทื˜ืŸ ื’ืจื™ื™ืก ืคึผืึทืจืึทืžืขื˜ืขืจืก (ื ื™ืฆืŸ ืึท ื’ืจื™ื™ืก ืคืขืœื“ ืึธืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืคืึทืงื˜ื™ืฉ ื“ืึทื˜ืŸ ื’ืจื™ื™ืก), ืขืจืจืึธืจืก ืื™ืŸ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ืึทืจื™ื™ึทื ืฉืจื™ื™ึทื‘ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข, ื˜ืึธืคึผืœ ืคืจื™ื™ ืคื•ืŸ ื–ื›ึผืจื•ืŸ, ืื•ื™ืก-ืคื•ืŸ-ื‘ืึทืคืขืจ ืœื™ื™ืขื ื˜, ื™ื ื˜ืึทื“ื–ืฉืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื•ื–, ืคืึทืœืฉ ืึทืงืกืขืก ืงืึธื ื˜ืจืึธืœ, ืื•ืŸ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ื ืึทืœ-ื“ืขืœื™ืžื™ื˜ืขื“ ืกื˜ืจื™ื ื’ืก.

ื“ื™ ืฆื•ื•ื™ื™ ืžืขืจืกื˜ ื’ืขืคืขืจืœืขืš ืคึผืจืึธื‘ืœืขืžืก (CVE-2020-11896, CVE-2020-11897), ื•ื•ืึธืก ื–ืขื ืขืŸ ืึทืกื™ื™ื ื“ CVSS ืžื“ืจื’ื” 10, ืœืึธื–ืŸ ืงืึธื“ ืฆื• ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืื•ื™ืฃ ืึท ืžื™ื˜ืœ ื“ื•ืจืš ืฉื™ืงื˜ ืกืคึผืขืฉืœื™ ืคืึธืจืžืึทื˜ื˜ืขื“ IPv4/UDP ืึธื“ืขืจ IPv6 ืคึผืึทืงื™ืฅ. ื“ืขืจ ืขืจืฉื˜ืขืจ ืงืจื™ื˜ื™ืฉ ืคึผืจืึธื‘ืœืขื ืื™ื– ืืจื•ื™ืก ืื•ื™ืฃ ื“ืขื•ื•ื™ืกืขืก ืžื™ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ IPv4 ื˜ืึทื ืึทืœื–, ืื•ืŸ ื“ื™ ืจื’ืข ืื™ืŸ ื•ื•ืขืจืกื™ืขืก ืคืจื™ื™ ืื™ื™ื“ืขืจ 04.06.2009/6/9 ืžื™ื˜ IPv2020 ืฉื˜ื™ืฆืŸ. ืืŸ ืื ื“ืขืจ ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVSS 11901) ืื™ื– ืคืึธืจืฉื˜ืขืœืŸ ืื™ืŸ ื“ื™ ื“ื ืก ืจืขืกืึธืœื•ื•ืขืจ (CVE-XNUMX-XNUMX) ืื•ืŸ ืึทืœืึทื•ื– ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ื“ื•ืจืš ืฉื™ืงืŸ ืึท ืกืคึผืขืฆื™ืขืœ ืงืจืึทืคื˜ืขื“ ื“ื ืก ื‘ืขื˜ืŸ (ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื“ื™ ื›ืึทืงื™ื ื’ ืคื•ืŸ Schneider Electric APC UPS ืื•ืŸ ืื™ื– ืืจื•ื™ืก ืื•ื™ืฃ ื“ืขื•ื•ื™ืกืขืก ืžื™ื˜ ื“ื ืก ืฉื˜ื™ืฆืŸ).

ืื ื“ืขืจืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– CVE-2020-11898, CVE-2020-11899, CVE-2020-11902, CVE-2020-11903, CVE-2020-11905 ืœืึธื–ืŸ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ IPv4/ICDHMPv4, IPv6OverIPv4, IPv6OverIPv6, ืฉื™ืงื˜ ืกืคึผืขืฉืœื™ ื“ื™ื–ื™ื™ื ื“ ืคึผืึทืงื™ืฅ ืกื™ืกื˜ืขื ื–ื›ึผืจื•ืŸ ื’ืขื‘ื™ื˜ืŸ. ืื ื“ืขืจืข ืคึผืจืึธื‘ืœืขืžืก ืงืขืŸ ืจืขื–ื•ืœื˜ืึทื˜ ืื™ืŸ ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ืึธื“ืขืจ ืœื™ืงืึทื“ื–ืฉ ืคื•ืŸ ืจื™ื–ื™ื“ื–ืฉื•ืึทืœ ื“ืึทื˜ืŸ ืคื•ืŸ ืกื™ืกื˜ืขื ื‘ืึทืคืขืจื–.

ืจื•ื‘ึฟ ืคื•ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื˜ืจืขืง 6.0.1.67 (CVE-2020-11897 ืื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ 5.0.1.35, CVE-2020-11900 ืื™ืŸ 6.0.1.41, CVE-2020-11903 ืื™ืŸ 6.0.1.28 ืื™ืŸ CVE-2020, CVE-11908 4.7.1.27. 20). ื–ื™ื ื˜ ืคึผืจื™ืคึผืขืจื™ื ื’ ืคื™ืจืžื•ื•ืึทืจืข ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืคึฟืึทืจ ืกืคึผืขืฆื™ืคื™ืฉ ื“ืขื•ื•ื™ืกืขืก ืงืขืŸ ื–ื™ื™ืŸ ื“ื™ืœื™ื™ื“ ืึธื“ืขืจ ืื•ืžืžืขื’ืœืขืš (ื“ืขืจ ื˜ืจืขืง ืกื˜ืึทืง ืื™ื– ื‘ื ื™ืžืฆื ืคึฟืึทืจ ืžืขืจ ื•ื•ื™ 6 ื™ืึธืจ, ืคื™ืœืข ื“ืขื•ื•ื™ืกืขืก ื‘ืœื™ื™ื‘ืŸ ืึทื ืžื™ื™ื ื˜ื™ื™ื ื“ ืึธื“ืขืจ ื–ืขื ืขืŸ ืฉื•ื•ืขืจ ืฆื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ), ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก ื–ืขื ืขืŸ ืึทื“ื•ื•ื™ื™ื–ื“ ืฆื• ื™ื–ืึธืœื™ืจืŸ ืคึผืจืึธื‘ืœืขืžืึทื˜ื™ืง ื“ืขื•ื•ื™ืกืขืก ืื•ืŸ ืงืึทื ืคื™ื’ื™ืขืจ ืคึผืึทืงืึทื˜ ื“ื•ืจื›ืงื•ืง ืกื™ืกื˜ืขืžืขืŸ, ืคื™ืจืขื•ื•ืึทืœืœืก. ืึธื“ืขืจ ืจืึธื•ื˜ืขืจืก ืฆื• ื ืึธืจืžืึทืœื™ื™ื– ืึธื“ืขืจ ืคืึทืจืฉืคึผืึทืจืŸ ืคืจืึทื’ืžืึทื ื˜ื™ื“ ืคึผืึทืงื™ืฅ, ืคืึทืจืฉืคึผืึทืจืŸ IP ื˜ืึทื ืึทืœื– (IPv4-in-IPv6 ืื•ืŸ IP-in-IP), ืคืึทืจืฉืคึผืึทืจืŸ "ืžืงื•ืจ ืจื•ื˜ื™ื ื’", ื’ืขื‘ืŸ ื“ื•ืจื›ืงื•ืง ืคื•ืŸ ืคืึทืœืฉ ืึธืคึผืฆื™ืขืก ืื™ืŸ ื˜ืงืคึผ ืคึผืึทืงื™ืฅ, ืคืึทืจืฉืคึผืึทืจืŸ ืึทื ื™ื•ื–ื“ ICMP ืงืึธื ื˜ืจืึธืœ ืึทืจื˜ื™ืงืœืขืŸ (MTU ืึทืคึผื“ื™ื™ื˜ ืื•ืŸ ืึทื“ืจืขืก ืžืึทืกืงืข), ื“ื™ืกื™ื™ื‘ืึทืœ IPvXNUMX ืžื•ืœื˜ื™ืงืึทืกื˜ ืื•ืŸ ืจื™ื“ืขืจืขืงื˜ ื“ื ืก ืคึฟืจืื’ืŸ ืฆื• ืึท ื–ื™ื›ืขืจ ืจืขืงื•ืจืกื™ื•ื•ืข ื“ื ืก ืกืขืจื•ื•ืขืจ.


ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’