MikroTik RouterOSÉí·ÝÈÏ֤ȱʧÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-20

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-3924 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ CVSS·ÖÖµ£º7.5


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º 

MikroTik RouterOS <V6.43.12 (stable)ÒÔ¼°<V6.42.12 (long-term)


Îó²î¸ÅÊö


MikroTik RouterOSÊÇMikroTik¹«Ë¾£¨×ܲ¿Î»ÓÚÀ­ÍÑάÑÇ£©»ùÓÚLinuxÄں˿ª·¢µÄÒ»ÖÖ·ÓɲÙ×÷ϵͳ £¬Í¨¹ý×°ÖøÃϵͳ¿É½«±ê×¼µÄx86 PC×°±¸Äð³Éרҵ·ÓÉÆ÷ £¬¾ß±¸ÎÞÏß¡¢ÈÏÖ¤¡¢Õ½ÂÔ·ÓÉ¡¢´ø¿í¿ØÖƺͷÀ»ðǽ¹ýÂ˵ȹ¦Ð§¡£


Çå¾²Ñо¿Ö°Ô±·¢Ã÷ £¬MikroTik RouterOS 6.43.12 (stable) ÒÔ¼°6.42.12 (long-term)֮ǰµÄ°æ±¾±£´æÎ´¾­ÈÏÖ¤¿ÉÈÆ¹ý·À»ðǽ»á¼ûNATÄÚ²¿ÍøÂçµÄÎó²î¡£ÆÊÎöÅú×¢ £¬¸ÃÎó²îÊÇMikroTik×°±¸Î´¶ÔÍøÂç̽Õë¾ÙÐÐÇ¿ÖÆÉí·ÝÈÏÖ¤Ôì³ÉµÄ £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÈÆ¹ý·ÓÉÆ÷µÄ·À»ðǽ £¬²¢¾ÙÐÐÄÚ²¿ÍøÂçɨÃèÔ˶¯¡£


×èֹĿ½ñ £¬·¢Ã÷´ó×Ú̻¶ÔÚ»¥ÁªÍøÉϵÄÏà¹Ø×°±¸ £¬ÏêϸÐÅÏ¢¼ûÏÂͼһ¡¢¶þ¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



ͼһ º£ÄÚ̻¶ÔÚ»¥ÁªÍøµÄ¸ÃÎó²îÏà¹ØÍøÂç×ʲúÐÅÏ¢


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ͼ¶þ º£ÄÚ̻¶ÔÚ»¥ÁªÍøµÄ¸ÃÎó²îÏà¹ØÍøÂç×ʲúÂþÑÜͼ


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼½â¾öÉÏÊöÎó²îµÄÇå¾²·À»¤²½·¥ £¬½¨ÒéÏà¹ØÓû§ÊµÊ±¼ì²é¸üС£


ÏêÇéÇë¹Ø×¢³§ÉÌÍøÕ¾µÄÏà¹ØÐÅÏ¢£ºhttps://mikrotik.com/download¡£

±ðµÄ £¬½¨ÒéÏà¹ØÓû§Ó¦½ÓÄɵįäËûÇå¾²·À»¤²½·¥ÈçÏ£º

£¨1£©×î´óÏ޶ȵØïÔÌ­ËùÓÐϵͳװ±¸ºÍϵͳµÄÍøÂç̻¶ £¬²¢È·±£ÎÞ·¨´ÓInternet»á¼û¡£

£¨2£©¶¨Î»·À»ðǽ·À»¤µÄ¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸ £¬²¢½«ÆäÓëÓªÒµÍøÂç¸ôÀë¡£

£¨3£©µ±ÐèÒªÔ¶³Ì»á¼ûʱ £¬ÇëʹÓÃÇå¾²ÒªÁìÈçÐéÄâרÓÃÍøÂ磨VPN£© £¬ÒªÊìϤµ½VPN¿ÉÄܱ£´æµÄÎó²î £¬Ð轫VPN¸üе½×îа汾¡£


²Î¿¼Á´½Ó


http://www.cnvd.org.cn/flaw/show/CNVD-2019-05572

https://nvd.nist.gov/vuln/detail/CVE-2019-3924#vulnCurrentDescriptionTitle