²©Í¨Äں˷ì϶Cable Haunt | CVE-2019-19494
°ä²¼¹¦·ò 2020-01-15

1.²¼¾°ÃèÊö
½üÈÕ£¬µ¤Âó×êÑÐÍŶÓLyrebirds ApS·¢ÏÖÁ˲©Í¨£¨Broadcom£©µ÷Ôì½âµ÷Æ÷оƬÄں˰²È«·ì϶£¬¸Ã·ì϶ΪCable Haunt£¨CVE-2019-19494£©£¬²¢°ä²¼Á˾ßÌå×¢Ã÷¹Ø¼üÎÊÌâµÄ°×ƤÊ飬²¢ÇÒ»¹´´½¨ÁËÒ»¸öÊÓÆµ¡£½öÔÚÅ·ÖÞ¾ÍԼĪ2ÒÚ¸öµçÀµ÷Ôì½âµ÷Æ÷Ãæ¶Ô·çÏÕ¡£
2.Ó°ÏìÁìÓò
3.·ì϶ÏêÇé
¸Ã·ì϶ÊÇÓÉBroadcomоƬµÄ³ß¶È×é¼þ£¨³ÆÎªÆµÆ×·ÖÎöÒÇ£©ÖеÄÒ»¸öÎÊÌâµ¼Öµġ£ÆµÆ×·ÖÎöÒÇÊÇÒ»ÖÖÈí¼þºÍÓ²¼þ×é¼þ£¬Ö¼ÔÚ±£»¤Ä£ÐÍÃâÊÜͬÖáµçÀ¿ÉÄܲúÉúµÄÐźÅÀËÓ¿ºÍ×ÌÈŵÄÓ°Ïì¡£ÏÖʵÉÏISP²¿ÊðÁË´Ë×é¼þÒÔµ÷ÊÔÏνÓÖÊÁ¿¡£
BroadcomоƬƵÆ×·ÖÎöÒÇûÓÐÕë¶ÔDNS³Áа󶨹¥»÷½øÐÐÊʵ±µÄ±£»¤¡£´Ë±í£¬Ëü»¹Ê¹ÓÃĬÈÏÍ´´¦£¬²¢ÇÒÆä¹Ì¼þÔ̺¬±à³ÌÃýÎó¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÄ£Ð͵Ķ˵ã¼ä½ÓÔÚµ÷Ôì½âµ÷Æ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£ÓÉÓÚµ÷Ôì½âµ÷Æ÷ÕÆ¹ÜÍøÂçÉÏËùÓÐÉ豸µÄ»¥ÁªÍøÁ÷Á¿£¬Òò¶øÄܹ»ÀûÓÃCable HauntÀ¹½Ø¸öÈËͨѶ£¬³Á¶¨ÏòÁ÷Á¿»ò½«É豸Ôö³¤µ½½©Ê¬ÍøÂç¡£
ͨ¹ýÓÕʹÓû§Í¨¹ýä¯ÀÀÆ÷½Ó¼û¶ñÒâÒ³Ãæ£¬¹¥»÷ÕßÄܹ»ÀûÓÃä¯ÀÀÆ÷¶ÔËù·ÖÎöµÄÃýÎ󯵯׽øÐÐÀûÓá£Á˾ֽ«ÊÇÔÚÉ豸ÉÏÖ´ÐкÅÁî¡£¼ò¶øÑÔÖ®£¬Äܹ»ÀûÓÃCable Hunt·ì϶ִÐÐÒÔ϶ñÒâ»î¶¯£º
¸ü¸ÄĬÈÏDNS·þÎñÆ÷
½øÐÐÔ¶³ÌÖÐÑëÈ˹¥»÷
ÈȲå°Î´úÂëÉõÖÁÕû¸ö¹Ì¼þ
¾²Ä¬ÉÏ´«£¬Ë¢ÐºÍÉý¼¶¹Ì¼þ
½ûÓÃISP¹Ì¼þÉý¼¶
¸ü¸Äÿ¸öÅäÖÃÎļþºÍÉèÖÃ
»ñÈ¡ºÍÉèÖÃSNMP OIDÖµ
¸ü¸ÄËùÓйØÁªµÄMACµØÖ·
¸ü¸ÄÐòÁкÅ
½«É豸²ÎÓë½©Ê¬ÍøÂç
4.½¨¸´½ø¶È
ĿǰŲÍþºÍÈðµäµÄËĸöISP·þÎñÉÌÒѰ䲼Á˲¹¶¡·¨Ê½£¨Telia£¬TDC£¬Get ASºÍStofa£©¡£
5.²Î¿¼Á´½Ó
https://cablehaunt.com
https://www.broadcom.com
https://sensorstechforum.com/cve-2019-19494-cable-haunt-flaw/
https://github.com/Lyrebirds/Cable-Haunt-Report/releases/download/2.4/report.pdf


¾©¹«Íø°²±¸11010802024551ºÅ