ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ Cisco Catalyst PON ืกื•ื•ื™ื˜ืฉื™ื– ืึทื– ืึทืœืึทื•ื– ืœืึธื’ื™ืŸ ื“ื•ืจืš ื˜ืขืœื ืขื˜ ืึธืŸ ื•ื•ื™ืกืŸ ื“ื™ ืคึผืึทืจืึธืœ

ื ืงืจื™ื˜ื™ืฉ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืึทืจื•ื™ืกื’ืขื‘ืŸ (CVE-2021-34795) ืื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ Cisco Catalyst PON CGP-ONT-* (ืคึผืึทืกื™ื•ื• ืึธืคึผื˜ื™ืฉ ื ืขื˜ื•ื•ืึธืจืง) ืกืขืจื™ืข ืกื•ื•ื™ื˜ืฉื™ื–, ื•ื•ืึธืก ืึทืœืึทื•ื–, ื•ื•ืขืŸ ื“ื™ ื˜ืขืœื ืขื˜ ืคึผืจืึธื˜ืึธืงืึธืœ ืื™ื– ืขื ื™ื™ื‘ืึทืœื“, ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ ื‘ืึทืฉื˜ื™ืžืขืŸ ืžื™ื˜ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืจืขื›ื˜. ืึท ืคืึทืจ-ื‘ืืงืื ื˜ ื“ื™ื‘ืึทื’ ื—ืฉื‘ื•ืŸ ืœื™ื ืงืก ื“ื•ืจืš ื“ืขืจ ืคืึทื‘ืจื™ืงืึทื ื˜ ืื™ืŸ ื“ื™ ืคื™ืจืžื•ื•ืึทืจืข. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื‘ืœื•ื™ื– ื•ื•ืขืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืึทืงืกืขืก ื“ื•ืจืš ื˜ืขืœื ืขื˜ ืื™ื– ืึทืงื˜ื™ื•ื•ื™ื™ื˜ื™ื“ ืื™ืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก, ื•ื•ืึธืก ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ื“ืขื ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืึท ื—ืฉื‘ื•ืŸ ืžื™ื˜ ืึท ื‘ื™ื– ืึทื”ืขืจ ื‘ืึทื•ื•ื•ืกื˜ ืคึผืึทืจืึธืœ, ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2021-40112, CVE-2021-40113) ืื™ืŸ ื“ื™ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“ ื–ืขื ืขืŸ ืื•ื™ืš ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ ื“ื™ ื‘ืึทืฉื˜ื™ืžืขืŸ ืžืึธื“ืขืœืก ืื™ืŸ ืงืฉื™ื, ืึทืœืึทื•ื™ื ื’ ืึทืŸ ืึทื ืึธื˜ืขื ื˜ื™ืงื™ื™ื˜ื™ื“ ืึทื˜ืึทืงืขืจ ื•ื•ืึธืก ืงืขืŸ ื ื™ืฉื˜. ื•ื•ื™ืกืŸ ื“ื™ ืœืึธื’ื™ืŸ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืฆื• ื•ื™ืกืคื™ืจืŸ ืงืึทืžืึทื ื“ื– ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืื•ืŸ ืžืึทื›ืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก. ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ืึทืงืกืขืก ืฆื• ื“ื™ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“ ืื™ื– ืขืจืœื•ื™ื‘ื˜ ื‘ืœื•ื™ื– ืคึฟื•ืŸ ื“ื™ ื”ื™ื’ืข ื ืขืฅ, ืกื™ื™ึทื“ืŸ ื“ืขื ื ืึทื˜ื•ืจ ืื™ื– ืึธื•ื•ื•ืขืจืจื™ื“ืึทืŸ ืื™ืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก.

ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ืึท ืขื ืœืขืš ืคึผืจืึธื‘ืœืขื (CVE-2021-40119) ืžื™ื˜ ืึท ืคึผืจืขื“ืขืคื™ื ืขื“ ื™ื ื–ืฉืขื ื™ืขืจื™ืข ืœืึธื’ื™ืŸ ืื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ ื“ื™ Cisco Policy Suite ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืคึผืจืึธื“ื•ืงื˜, ืื™ืŸ ื•ื•ืึธืก ืึท SSH ืฉืœื™ืกืœ ืฆื•ื’ืขื’ืจื™ื™ื˜ ืื™ืŸ ืฉื˜ื™ื™ึทื’ืŸ ื“ื•ืจืš ื“ืขืจ ืคืึทื‘ืจื™ืงืึทื ื˜ ืื™ื– ื’ืขื•ื•ืขืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ, ืึทืœืึทื•ื™ื ื’ ืึท ื•ื•ื™ื™ึทื˜ ืึทื˜ืึทืงืขืจ ืฆื• ื’ืขื•ื•ื™ื ืขืŸ. ืฆื•ื˜ืจื™ื˜ ืฆื• ื“ื™ ืกื™ืกื˜ืขื ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’