MikroTik ·ÓÉÆ÷¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-31

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-3976£¬£¬£¬ £¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3977£¬£¬£¬ £¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3978£¬£¬£¬ £¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3979£¬£¬£¬ £¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


RouterOS Stable 6.45.6 and below

RouterOS Long-term 6.44.5 and below


·ì϶¸ÅÊö


MikroTik RouterOSÊÇÀ­ÍÑάÑÇMikroTik¹«Ë¾µÄÒ»Ì×»ùÓÚLinux¿ª·¢µÄ·ÓÉÆ÷²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£¡£¸Ãϵͳ¿É²¿ÊðÔÚPCÖУ¬£¬£¬ £¬ £¬Ê¹ÆäÌṩ·ÓÉÆ÷Ö°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£


MikroTik ·ÓÉÆ÷Öб»ÆØ¶à¸ö·ì϶£¬£¬£¬ £¬ £¬¿Éµ¼Ö¹¥»÷Õß»ñµÃºóÃÅ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÀûÓÃÁ´Ê¼ÓÚ DNS Ͷ¶¾£¬£¬£¬ £¬ £¬¶øºó½µ¼¶Ëù×°ÖÃµÄ MikroTik RouterOS Èí¼þµÄ°æ±¾£¬£¬£¬ £¬ £¬×îÖÕÆôÓúóÃÅ¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶¼òÊöÈçÏ£º


CVE-2019-3976 õè¾¶±éÀú·ì϶£¬£¬£¬ £¬ £¬¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úƷδÄÜÕýÈ·µØ¹ýÂË×ÊÔ´»òÎļþõè¾¶ÖеÄÌØÊâÔªËØ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼ûÊÜÏÞĿ¼֮±íµÄµØÎ»¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-3977 ¸Ã·ì϶ԴÓÚ·¨Ê½Ã»Óгä·ÖÑéÖ¤¸üаüÏÂÔØµÄÆðÔ´¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñȡϵͳȫÊýµÄÓû§Ãû³ÆºÍÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-3978 ¹¥»÷Õ߿ɽèÖú8291¶Ë¿ÚÀûÓø÷ì϶½øÐÐDNS²éÎÊ£¬£¬£¬ £¬ £¬¿ÉÄÜÔì³É»º´æÖж¾¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-3979 Ô¶³Ì¹¥»÷Õ߿ɽèÖú¶ñÒâµÄÏìÓ¦ÀûÓø÷ì϶´«È¾Â·ÓÉÆ÷µÄDNS»º´æ¡£¡£¡£¡£¡£¡£¡£¡£


×êÑÐÈËÔ±½¨Òé½ûÓÃWinbox£¬£¬£¬ £¬ £¬¶ø¸ÄÓÃSSH£¬£¬£¬ £¬ £¬µ«ÒѾ­·¢ÏÖ³¬¹ý50Íò¸öWinboxÊ·ýÃæÏò»¥ÁªÍø¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ͨ¹ýÀûÓÃÒÔÉÏ·ì϶£¬£¬£¬ £¬ £¬Î´¾­ÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÄܽӼû·ÓÉÆ÷ÉϵĶ˿Ú8291£¬£¬£¬ £¬ £¬Ö´ÐÐ RouterOS ½µ¼¶£¬£¬£¬ £¬ £¬³ÁÐÂÉèÖÃϵͳÃÜÂë²¢¿ÉÄÜ»ñµÃ root shell¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÀûÓùý³ÌÈçÏ£º


1. DNS»º´æÖж¾


DNS·þÎñÆ÷ÔÚĬÈϽûÓõÄÇé¿öÏÂÈÔÓÐÆä×ÔÉíµÄDNS»º´æ£¬£¬£¬ £¬ £¬DNS²éÕÒÓÉ¡°½âÎöÆ÷¡±¶þ½øÔìÎļþ´¦Ö㬣¬£¬ £¬ £¬¸Ã¶þ½øÔìÎļþÊǹҽÓÔÚRouterOSµÄWinboxºÍ̸ÖУ»£»£»£»£»£»


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

½ûÓõÄDNS·þÎñÆ÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

DNS»º´æ


·¢Ë͵½Winbox¶Ë¿ÚµÄÐÂÎÅÄܹ»·¢Ë͵½·ÖÆçµÄ¶þ½øÔìÎļþ¼°½âÎöÆ÷£»£»£»£»£»£»


¶øºóŲÓÃÈçÏÂͼƬÖеÄÈýÌõºÅÁ3£¬£¬£¬ £¬ £¬4£¬£¬£¬ £¬ £¬6£©¾ÍÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÓû§Í¨¹ý·ÓÉÆ÷Ïò×Ô¼ºÑ¡ÔñµÄDNS·þÎñÆ÷·¢ËÍDNSÒªÇ󣻣»£»£»£»£»


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ºÅÁî3¡¢4¡¢6


ʹÓÃ×Ô½ç˵µÄ¶ñÒâDNS·þÎñÆ÷£¬£¬£¬ £¬ £¬¹¥»÷ÕßÄܹ»½«Ò»ÏµÁжñÒâIPµØÖ·£¨Ô̺¬ÏÂÔØµØÖ·£©Ð´È뵽·ÓÉÆ÷µÄ»º´æÖУ¬£¬£¬ £¬ £¬µ±Â·ÓÉÆ÷Éý¼¶Ê±£¬£¬£¬ £¬ £¬½«×ªµ½¹¥»÷ÕߵĶñÒâÕ¾µã£¬£¬£¬ £¬ £¬ÆäÌṩRouterOSµÄÔçÆÚ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£


2. ÖÎÀíÔ±Éí·ÝµÇ¼


´Ó6.43°æÆðÍ·£¬£¬£¬ £¬ £¬MikroTikÃÜÂë´¦ÖûúÔì×öÁ˸ü¸Ä£¬£¬£¬ £¬ £¬ÔÚMikroTikµÄÓйص÷»»ÈÕÖ¾ÖУº¡°½µ¼¶µ½6.43֮ǰµÄÈκΰ汾£¬£¬£¬ £¬ £¬½«¶Ï¸ùËùÓÐЧ»§ÃÜÂë²¢ÔÊÐíÎÞÃÜÂëÉí·ÝÑéÖ¤¡±¡£¡£¡£¡£¡£¡£¡£¡£


×êÑÐÈËԱ˵£º¡°µ±Óû§×°Öá®Ð¸üС¯Ê±£¬£¬£¬ £¬ £¬Èƹý²»ÈÝͨ¹ý¸üнµ¼¶µÄͨÀýÂß¼­£¬£¬£¬ £¬ £¬²¢½µ¼¶µ½RouterOS 6.41.4£¬£¬£¬ £¬ £¬ÓÉ´ËÖÎÀíÔ±ÃÜÂë³ÁÖõ½ÁËĬÈϵĿÕÃÜÂ룬£¬£¬ £¬ £¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÖÎÀíÔ±Éí·ÝµÇ¼¡±¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Óû§²é³­¸üÐÂÏÔʾchangelog


3. ºóÃÅÆôÓÃÎļþ/Ŀ¼


¡°6.41.4°æ±¾ÏµÍ³´æÔÚºóÃÅ£¬£¬£¬ £¬ £¬¹¥»÷ÕßÄܹ»ÀûÓøúóÃÅ»ñÈ¡ÆëÈ«µÄbusybox shell¡±£¬£¬£¬ £¬ £¬¡°6.41.4µÄºóÃÅÆôÓÃÎļþ»òĿ¼¾ÍÊÇ/pckg/option£¬£¬£¬ £¬ £¬Ö»ÓиÃÎļþ»òĿ¼´æÔÚ£¬£¬£¬ £¬ £¬¾ÍÄܹ»ÆôÓúóÃÅ¡±£¬£¬£¬ £¬ £¬×êÑÐÈËÔ±°µÊ¾¡£¡£¡£¡£¡£¡£¡£¡£


4. ´´½¨ËÁÒâĿ¼


×êÑÐÈËÔ±ÔÚÈí¼þ°üÖз¢ÏÖÁí±íÒ»¸ö·ì϶£¬£¬£¬ £¬ £¬¸Ã·ì϶ʹ¹¥»÷ÕßÄܹ»ÔÚϵͳÉÏ´´½¨ËÁÒâĿ¼¡£¡£¡£¡£¡£¡£¡£¡£MikroTikÔÚ¸üÐÂÆÚ¼ä´¦ÖÃ.NPKÎļþµÄ·½Ê½£ºÒ»µ©Óöµ½ÊðÃû²¿ÃÅ£¬£¬£¬ £¬ £¬½«ÖÕ³¡Èí¼þ°üÖÐSHA-1µÄÍÆË㣬£¬£¬ £¬ £¬ÕâÖÖ´¦Ö÷½Ê½µ¼ÖÂÖ»½âÎö²¿ÃÅÐÅÏ¢×ֶΣ¬£¬£¬ £¬ £¬¿ÉÓÃÓÚÔÚ´ÅÅÌÉϵÄÈκεØÎ»´´½¨Ä¿Â¼¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

×êÑÐÈËÔ±±àдµÄÒ»¸öÃûΪoption_npkµÄ¹¤¾ß


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬ £¬ £¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://mikrotik.com¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.securityweek.com/mikrotik-router-vulnerabilities-can-lead-backdoor-creation