MikroTik RouterOSÉí·ÝÈÏ֤ȱʧ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-20

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-3924£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º7.5


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º 

MikroTik RouterOS <V6.43.12 (stable)ÒÔ¼°<V6.42.12 (long-term)


·ì϶¸ÅÊö


MikroTik RouterOSÊÇMikroTik¹«Ë¾£¨×ܲ¿Î»ÓÚÀ­ÍÑάÑÇ£©»ùÓÚLinuxÄں˿ª·¢µÄÒ»ÖÖ·ÓɲÙ×÷ϵͳ£¬Í¨¹ý×°ÖøÃϵͳ¿É½«³ß¶ÈµÄx86 PCÉ豸Ôì³Éרҵ·ÓÉÆ÷£¬¾ß±¸ÎÞÏß¡¢ÈÏÖ¤¡¢Õ½Êõ·ÓÉ¡¢´ø¿í½ÚÔìºÍ·À»ðǽ¹ýÂ˵ÈÖ°ÄÜ¡£


°²È«×êÑÐÈËÔ±·¢ÏÖ£¬MikroTik RouterOS 6.43.12 (stable) ÒÔ¼°6.42.12 (long-term)֮ǰµÄ°æ±¾´æÔÚδ¾­ÈÏÖ¤¿ÉÈÆ¹ý·À»ðǽ½Ó¼ûNATÄÚ²¿ÍøÂçµÄ·ì϶¡£·ÖÎöÅú×¢£¬¸Ã·ì϶ÊÇMikroTikÉ豸δ¶ÔÍøÂç̽Õë½øÐÐÇ¿ÔìÉí·ÝÈÏÖ¤Ôì³ÉµÄ£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓô˷ìÏ¶ÈÆ¹ý·ÓÉÆ÷µÄ·À»ðǽ£¬²¢½øÐÐÄÚ²¿ÍøÂçɨÃè»î¶¯¡£


½ØÖ¹µ±Ç°£¬·¢ÏÖ´óÁ¿Â¶³öÔÚ»¥ÁªÍøÉϵÄÓйØÉ豸£¬¾ßÌåÐÅÏ¢¼ûÏÂͼһ¡¢¶þ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ͼһ ¹úÄÚ¶³öÔÚ»¥ÁªÍøµÄ¸Ã·ì϶ÓйØÍøÂç×ʲúÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ¶þ ¹úÄÚ¶³öÔÚ»¥ÁªÍøµÄ¸Ã·ì϶ÓйØÍøÂç×ʲúÉ¢²¼Í¼


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼½â¾öÉÏÊö·ì϶µÄ°²È«·À»¤´ëÊ©£¬½¨ÒéÓйØÓû§ÊµÊ±²é³­¸üС£


ÏêÇéÇë¹Ø×¢³§ÉÌÍøÕ¾µÄÓйØÐÅÏ¢£ºhttps://mikrotik.com/download¡£

´Ë±í£¬½¨ÒéÓйØÓû§Ó¦²ÉÈ¡µÄÆäËû°²È«·À»¤´ëÊ©ÈçÏ£º

£¨1£©×î´óÏ޶ȵØÏ÷¼õËùÓÐϵͳÉ豸ºÍϵͳµÄÍøÂç¶³ö£¬²¢È·±£ÎÞ·¨´ÓInternet½Ó¼û¡£

£¨2£©¶¨Î»·À»ðǽ·À»¤µÄ½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸£¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀë¡£

£¨3£©µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬ÇëʹÓð²È«²½ÖèÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬ÒªÒâʶµ½VPN¿ÉÄÜ´æÔڵķì϶£¬Ð轫VPN¸üе½×îа汾¡£


²Î¿¼Á´½Ó


http://www.cnvd.org.cn/flaw/show/CNVD-2019-05572

https://nvd.nist.gov/vuln/detail/CVE-2019-3924#vulnCurrentDescriptionTitle