MikroTik RouterOSÉí·ÝÈÏ֤ȱʧÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-20

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-3924£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬ CVSS·ÖÖµ£º7.5


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º 

MikroTik RouterOS <V6.43.12 (stable)ÒÔ¼°<V6.42.12 (long-term)


Îó²î¸ÅÊö


MikroTik RouterOSÊÇMikroTik¹«Ë¾£¨×ܲ¿Î»ÓÚÀ­ÍÑάÑÇ£©»ùÓÚLinuxÄں˿ª·¢µÄÒ»ÖÖ·ÓɲÙ×÷ϵͳ£¬ £¬£¬Í¨¹ý×°ÖøÃϵͳ¿É½«±ê×¼µÄx86 PC×°±¸Äð³Éרҵ·ÓÉÆ÷£¬ £¬£¬¾ß±¸ÎÞÏß¡¢ÈÏÖ¤¡¢Õ½ÂÔ·ÓÉ¡¢´ø¿í¿ØÖƺͷÀ»ðǽ¹ýÂ˵ȹ¦Ð§¡£¡£¡£¡£¡£


Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬ £¬£¬MikroTik RouterOS 6.43.12 (stable) ÒÔ¼°6.42.12 (long-term)֮ǰµÄ°æ±¾±£´æÎ´¾­ÈÏÖ¤¿ÉÈÆ¹ý·À»ðǽ»á¼ûNATÄÚ²¿ÍøÂçµÄÎó²î¡£¡£¡£¡£¡£ÆÊÎöÅú×¢£¬ £¬£¬¸ÃÎó²îÊÇMikroTik×°±¸Î´¶ÔÍøÂç̽Õë¾ÙÐÐÇ¿ÖÆÉí·ÝÈÏÖ¤Ôì³ÉµÄ£¬ £¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÈÆ¹ý·ÓÉÆ÷µÄ·À»ðǽ£¬ £¬£¬²¢¾ÙÐÐÄÚ²¿ÍøÂçɨÃè»î¶¯¡£¡£¡£¡£¡£


×èֹĿ½ñ£¬ £¬£¬·¢Ã÷´ó×Ú̻¶ÔÚ»¥ÁªÍøÉϵÄÏà¹Ø×°±¸£¬ £¬£¬ÏêϸÐÅÏ¢¼ûÏÂͼһ¡¢¶þ¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



ͼһ º£ÄÚ̻¶ÔÚ»¥ÁªÍøµÄ¸ÃÎó²îÏà¹ØÍøÂç×ʲúÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ¶þ º£ÄÚ̻¶ÔÚ»¥ÁªÍøµÄ¸ÃÎó²îÏà¹ØÍøÂç×ʲúÂþÑÜͼ


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼½â¾öÉÏÊöÎó²îµÄÇå¾²·À»¤²½·¥£¬ £¬£¬½¨ÒéÏà¹ØÓû§ÊµÊ±¼ì²é¸üС£¡£¡£¡£¡£


ÏêÇéÇë¹Ø×¢³§ÉÌÍøÕ¾µÄÏà¹ØÐÅÏ¢£ºhttps://mikrotik.com/download¡£¡£¡£¡£¡£

±ðµÄ£¬ £¬£¬½¨ÒéÏà¹ØÓû§Ó¦½ÓÄɵįäËûÇå¾²·À»¤²½·¥ÈçÏ£º

£¨1£©×î´óÏ޶ȵØïÔÌ­ËùÓÐϵͳװ±¸ºÍϵͳµÄÍøÂç̻¶£¬ £¬£¬²¢È·±£ÎÞ·¨´ÓInternet»á¼û¡£¡£¡£¡£¡£

£¨2£©¶¨Î»·À»ðǽ·À»¤µÄ¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸£¬ £¬£¬²¢½«ÆäÓëÓªÒµÍøÂç¸ôÀë¡£¡£¡£¡£¡£

£¨3£©µ±ÐèÒªÔ¶³Ì»á¼ûʱ£¬ £¬£¬ÇëʹÓÃÇå¾²ÒªÁìÈçÐéÄâרÓÃÍøÂ磨VPN£©£¬ £¬£¬ÒªÊìϤµ½VPN¿ÉÄܱ£´æµÄÎó²î£¬ £¬£¬Ð轫VPN¸üе½×îа汾¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


http://www.cnvd.org.cn/flaw/show/CNVD-2019-05572

https://nvd.nist.gov/vuln/detail/CVE-2019-3924#vulnCurrentDescriptionTitle