MikroTik ·ÓÉÆ÷¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-31

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-3976 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3977 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3978 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3979 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


RouterOS Stable 6.45.6 and below

RouterOS Long-term 6.44.5 and below


·ì϶¸ÅÊö


MikroTik RouterOSÊÇÀ­ÍÑάÑÇMikroTik¹«Ë¾µÄÒ»Ì×»ùÓÚLinux¿ª·¢µÄ·ÓÉÆ÷²Ù×÷ϵͳ¡£¸Ãϵͳ¿É²¿ÊðÔÚPCÖÐ £¬Ê¹ÆäÌṩ·ÓÉÆ÷Ö°ÄÜ¡£


MikroTik ·ÓÉÆ÷Öб»ÆØ¶à¸ö·ì϶ £¬¿Éµ¼Ö¹¥»÷Õß»ñµÃºóÃÅ¡£¸ÃÀûÓÃÁ´Ê¼ÓÚ DNS Ͷ¶¾ £¬¶øºó½µ¼¶Ëù×°ÖÃµÄ MikroTik RouterOS Èí¼þµÄ°æ±¾ £¬×îÖÕÆôÓúóÃÅ¡£


·ì϶¼òÊöÈçÏ£º


CVE-2019-3976 õè¾¶±éÀú·ì϶ £¬¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úƷδÄÜÕýÈ·µØ¹ýÂË×ÊÔ´»òÎļþõè¾¶ÖеÄÌØÊâÔªËØ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼ûÊÜÏÞĿ¼֮±íµÄµØÎ»¡£


CVE-2019-3977 ¸Ã·ì϶ԴÓÚ·¨Ê½Ã»Óгä·ÖÑéÖ¤¸üаüÏÂÔØµÄÆðÔ´¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñȡϵͳȫÊýµÄÓû§Ãû³ÆºÍÃÜÂë¡£


CVE-2019-3978 ¹¥»÷Õ߿ɽèÖú8291¶Ë¿ÚÀûÓø÷ì϶½øÐÐDNS²éÎÊ £¬¿ÉÄÜÔì³É»º´æÖж¾¡£


CVE-2019-3979 Ô¶³Ì¹¥»÷Õ߿ɽèÖú¶ñÒâµÄÏìÓ¦ÀûÓø÷ì϶´«È¾Â·ÓÉÆ÷µÄDNS»º´æ¡£


×êÑÐÈËÔ±½¨Òé½ûÓÃWinbox £¬¶ø¸ÄÓÃSSH £¬µ«ÒѾ­·¢ÏÖ³¬¹ý50Íò¸öWinboxÊ·ýÃæÏò»¥ÁªÍø¡£


·ì϶ÑéÖ¤


ͨ¹ýÀûÓÃÒÔÉÏ·ì϶ £¬Î´¾­ÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÄܽӼû·ÓÉÆ÷ÉϵĶ˿Ú8291 £¬Ö´ÐÐ RouterOS ½µ¼¶ £¬³ÁÐÂÉèÖÃϵͳÃÜÂë²¢¿ÉÄÜ»ñµÃ root shell¡£


·ì϶ÀûÓùý³ÌÈçÏ£º


1. DNS»º´æÖж¾


DNS·þÎñÆ÷ÔÚĬÈϽûÓõÄÇé¿öÏÂÈÔÓÐÆä×ÔÉíµÄDNS»º´æ £¬DNS²éÕÒÓÉ¡°½âÎöÆ÷¡±¶þ½øÔìÎļþ´¦Öà £¬¸Ã¶þ½øÔìÎļþÊǹҽÓÔÚRouterOSµÄWinboxºÍ̸ÖУ»


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

½ûÓõÄDNS·þÎñÆ÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

DNS»º´æ


·¢Ë͵½Winbox¶Ë¿ÚµÄÐÂÎÅÄܹ»·¢Ë͵½·ÖÆçµÄ¶þ½øÔìÎļþ¼°½âÎöÆ÷£»


¶øºóŲÓÃÈçÏÂͼƬÖеÄÈýÌõºÅÁ3 £¬4 £¬6£©¾ÍÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÓû§Í¨¹ý·ÓÉÆ÷Ïò×Ô¼ºÑ¡ÔñµÄDNS·þÎñÆ÷·¢ËÍDNSÒªÇó£»


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ºÅÁî3¡¢4¡¢6


ʹÓÃ×Ô½ç˵µÄ¶ñÒâDNS·þÎñÆ÷ £¬¹¥»÷ÕßÄܹ»½«Ò»ÏµÁжñÒâIPµØÖ·£¨Ô̺¬ÏÂÔØµØÖ·£©Ð´È뵽·ÓÉÆ÷µÄ»º´æÖÐ £¬µ±Â·ÓÉÆ÷Éý¼¶Ê± £¬½«×ªµ½¹¥»÷ÕߵĶñÒâÕ¾µã £¬ÆäÌṩRouterOSµÄÔçÆÚ°æ±¾¡£


2. ÖÎÀíÔ±Éí·ÝµÇ¼


´Ó6.43°æÆðÍ· £¬MikroTikÃÜÂë´¦ÖûúÔì×öÁ˸ü¸Ä £¬ÔÚMikroTikµÄÓйص÷»»ÈÕÖ¾ÖУº¡°½µ¼¶µ½6.43֮ǰµÄÈκΰ汾 £¬½«¶Ï¸ùËùÓÐЧ»§ÃÜÂë²¢ÔÊÐíÎÞÃÜÂëÉí·ÝÑéÖ¤¡±¡£


×êÑÐÈËԱ˵£º¡°µ±Óû§×°Öá®Ð¸üС¯Ê± £¬Èƹý²»ÈÝͨ¹ý¸üнµ¼¶µÄͨÀýÂß¼­ £¬²¢½µ¼¶µ½RouterOS 6.41.4 £¬ÓÉ´ËÖÎÀíÔ±ÃÜÂë³ÁÖõ½ÁËĬÈϵĿÕÃÜÂë £¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÖÎÀíÔ±Éí·ÝµÇ¼¡±¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Óû§²é³­¸üÐÂÏÔʾchangelog


3. ºóÃÅÆôÓÃÎļþ/Ŀ¼


¡°6.41.4°æ±¾ÏµÍ³´æÔÚºóÃÅ £¬¹¥»÷ÕßÄܹ»ÀûÓøúóÃÅ»ñÈ¡ÆëÈ«µÄbusybox shell¡± £¬¡°6.41.4µÄºóÃÅÆôÓÃÎļþ»òĿ¼¾ÍÊÇ/pckg/option £¬Ö»ÓиÃÎļþ»òĿ¼´æÔÚ £¬¾ÍÄܹ»ÆôÓúóÃÅ¡± £¬×êÑÐÈËÔ±°µÊ¾¡£


4. ´´½¨ËÁÒâĿ¼


×êÑÐÈËÔ±ÔÚÈí¼þ°üÖз¢ÏÖÁí±íÒ»¸ö·ì϶ £¬¸Ã·ì϶ʹ¹¥»÷ÕßÄܹ»ÔÚϵͳÉÏ´´½¨ËÁÒâĿ¼¡£MikroTikÔÚ¸üÐÂÆÚ¼ä´¦ÖÃ.NPKÎļþµÄ·½Ê½£ºÒ»µ©Óöµ½ÊðÃû²¿ÃÅ £¬½«ÖÕ³¡Èí¼þ°üÖÐSHA-1µÄÍÆËã £¬ÕâÖÖ´¦Ö÷½Ê½µ¼ÖÂÖ»½âÎö²¿ÃÅÐÅÏ¢×Ö¶Î £¬¿ÉÓÃÓÚÔÚ´ÅÅÌÉϵÄÈκεØÎ»´´½¨Ä¿Â¼¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

×êÑÐÈËÔ±±àдµÄÒ»¸öÃûΪoption_npkµÄ¹¤¾ß


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://mikrotik.com¡£


²Î¿¼Á´½Ó


https://www.securityweek.com/mikrotik-router-vulnerabilities-can-lead-backdoor-creation