ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื•ื•ืึธืก ืœืึธื–ืŸ ืงืึธื ื˜ืจืึธืœ ืคื•ืŸ Cisco, Zyxel ืื•ืŸ NETGEAR ืกื•ื•ื™ื˜ืฉืึทื– ืื•ื™ืฃ RTL83xx ื˜ืฉื™ืคึผืก ืฆื• ื–ื™ื™ืŸ ืื™ื‘ืขืจื’ืขื ื•ืžืขืŸ

ืื™ืŸ ืกื•ื•ื™ื˜ืฉืึทื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ RTL83xx ื˜ืฉื™ืคึผืก, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ Cisco Small Business 220, Zyxel GS1900-24, NETGEAR GS75x, ALLNET ALL-SG8208M ืื•ืŸ ืžืขืจ ื•ื•ื™ ืึท ื˜ื•ืฅ ื“ืขื•ื•ื™ืกืขืก ืคื•ืŸ ื•ื•ื™ื™ื ื™ืงืขืจ ื‘ืึทื•ื•ื•ืกื˜ ืžืึทื ื™ืึทืคืึทืงื˜ืฉืขืจืขืจื–, ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื•ื•ืึธืก ืœืึธื–ืŸ ืึทืŸ ืึทื ืึทื•ื˜ืขื ื˜ืึทืงื™ื™ื˜ื™ื“ ืึทื˜ืึทืงืขืจ ืฆื• ื‘ืึทืงื•ืžืขืŸ ืงืึธื ื˜ืจืึธืœ ืคื•ืŸ ื“ื™ ื‘ืึทืฉื˜ื™ืžืขืŸ. ื“ื™ ืคืจืื‘ืœืขืžืขืŸ ื–ืขื ืขืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืขืจืจืึธืจืก ืื™ืŸ ื“ื™ Realtek Managed Switch Controller SDK, ื“ื™ ืงืึธื“ ืคื•ืŸ ื•ื•ืึธืก ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ืฆื•ื’ืจื™ื™ื˜ืŸ ื“ื™ ืคื™ืจืžื•ื•ืึทืจืข.

ืขืจืฉื˜ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2019-1913) ืึทืคืขืงืฅ ื“ื™ ื•ื•ืขื‘ ืงืึธื ื˜ืจืึธืœ ืฆื•ื‘ื™ื ื“ ืื•ืŸ ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ื•ื™ืกืคื™ืจืŸ ื“ื™ื™ืŸ ืงืึธื“ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืจืขื›ื˜ ืฆื• ื ื™ื˜ ื’ืขื ื•ื’ื™ืง ื•ื•ืึทืœืึทื“ื™ื™ืฉืึทืŸ ืคื•ืŸ ื‘ืึทื ื™ืฆืขืจ-ืกืึทืคึผืœื™ื™ื“ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืื•ืŸ ื“ื•ืจื›ืคืึทืœ ืฆื• ืจืขื›ื˜ ืึธืคึผืฉืึทืฆืŸ ื‘ืึทืคืขืจ ื‘ืึทื•ื ื“ืจื™ื– ื•ื•ืขืŸ ืœื™ื™ืขื ืขืŸ ืึทืจื™ื™ึทื ืฉืจื™ื™ึทื‘ ื“ืึทื˜ืŸ. ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ืึท ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ืึธื ืžืึทื›ืŸ ืึท ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ื“ื•ืจืš ืฉื™ืงืŸ ืึท ืกืคึผืขืฆื™ืขืœ ืงืจืึทืคื˜ืขื“ ื‘ืขื˜ืŸ ืื•ืŸ ื’ื•ื•ื•ืจืข ื“ืขื ืคึผืจืึธื‘ืœืขื ืฆื• ื•ื™ืกืคื™ืจืŸ ื–ื™ื™ืขืจ ืงืึธื“.

ืฆื•ื•ื™ื™ื˜ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2019-1912) ืึทืœืึทื•ื– ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื˜ืขืงืขืก ืฆื• ื–ื™ื™ืŸ ืœืึธื•ื“ื™ื“ ืื•ื™ืฃ ื“ื™ ื‘ืึทืฉื˜ื™ืžืขืŸ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืึธื•ื•ื•ืขืจืจื™ื™ื˜ื™ื ื’ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืขืก ืื•ืŸ ืงืึทื˜ืขืจ ืึท ืคืึทืจืงืขืจื˜ ืฉืึธืœ ืคึฟืึทืจ ื•ื•ื™ื™ึทื˜ ืœืึธื’ื™ืŸ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ืขืจืขื ื“ื™ืงื˜ ืงืึธื ื˜ืจืึธืœ ืคื•ืŸ ืคึผืขืจืžื™ืฉืึทื ื– ืื™ืŸ ื“ื™ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“.

ืื™ืจ ืงืขื ืขืŸ ืื•ื™ืš ื˜ืึธืŸ ื“ื™ ื™ืœื™ืžืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ ื•ื•ื™ื™ื ื™ืงืขืจ ื’ืขืคืขืจืœืขืš ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2019-1914), ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ืงืึทืžืึทื ื“ื– ืฆื• ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื•ื™ื‘ ืขืก ืื™ื– ืึทืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉื“ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ืœืึธื’ื™ืŸ ืฆื• ื“ื™ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“. ื™ืฉื•ื– ื–ืขื ืขืŸ ืจื™ื–ืึทืœื•ื•ื“ ืื™ืŸ Cisco Small Business 220 (1.1.4.4), Zyxel ืื•ืŸ NETGEAR ืคื™ืจืžื•ื•ืึทืจืข ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ. ื ื“ื™ื˜ื™ื™ืœื“ ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’ ืคื•ืŸ ืึทืคึผืขืจื™ื™ื˜ื™ื ื’ ืžืขื˜ื”ืึธื“ืก ืื™ื– ืคึผืœืึทื ื ืขื“ ืึทืจื•ื™ืกื’ืขื‘ืŸ 20ื˜ืŸ ืื•ื™ื’ื•ืกื˜.

ืคึผืจืึธื‘ืœืขืžืก ืื•ื™ืš ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื™ืŸ ืื ื“ืขืจืข ื“ืขื•ื•ื™ืกืขืก ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ RTL83xx ื˜ืฉื™ืคึผืก, ืึธื‘ืขืจ ื–ื™ื™ ื–ืขื ืขืŸ ื ื™ืฉื˜ ื ืึธืš ื‘ืืฉื˜ืขื˜ื™ืงื˜ ื“ื•ืจืš ื“ื™ ืžืึทื ื™ืึทืคืึทืงื˜ืฉืขืจืขืจื– ืื•ืŸ ื–ืขื ืขืŸ ื ื™ืฉื˜ ืคืึทืจืคืขืกื˜ื™ืงื˜:

  • ืขื ื’ื ื™ื•ืก EGS2110P, EWS1200-28TFP, EWS1200-28TFP;
  • PLANET GS-4210-8P2S, GS-4210-24T2;
  • DrayTek VigorSwitch P1100;
  • CERIO CS-2424G-24P;
  • Xhome DownLoop-G24M;
  • Abaniact (INABA) AML2-PS16-17GP L2;
  • Araknis Networks (SnapAV) AN-310-SW-16-POE;
  • ืขื“ื™ืžืึทืงืก ื’ืก-5424ืคึผืœืง, ื’ืก-5424ืคึผืœืง;
  • ืขืคึฟืขื ืขืŸ ืžืขืฉ ืึธืžืก24;
  • ืคึผืึทืงื™ื“ื–ืฉื“ ื“ื™ื•ื•ื™ื™ืก SX-8P;
  • TG-NET P3026M-24POE.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’