¡¾·ì϶¹«¸æ¡¿INFRA:HALT: NicheStack TCP/IP ²Ö¿â¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-08-040x00 ·ì϶¸ÅÊö
2021Äê8ÔÂ4ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬JFrogºÍForescout µÄ×êÑÐÈËÔ±°ä²¼ÁËÒ»·Ý½áºÏ»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬¹«¿ªÅû¶ÁËÔÚNicheStack TCP/IP ²Ö¿âÖз¢ÏÖµÄ14¸ö°²È«·ì϶(ͳ³ÆÎªINFRA:HALT)£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×¢»Ø¾ø·þÎñ¡¢ÐÅϢй©¡¢TCP ºýŪ»òDNS »º´æÖж¾¡£¡£¡£¡£¡£¡£
NicheStackÊÇÒ»¸ö³£ÓõÄTCP/IP²Ö¿â£¬£¬£¬£¬£¬£¬£¬£¬ËüÖÁÉÙ±»200¼Ò¹©¸øÉÌÓÃÓÚ³ö²ú»·¾³£¬£¬£¬£¬£¬£¬£¬£¬²¢±»²¿ÊðÔÚÔì×÷³§¡¢·¢µç¡¢Ë®´¦Öõȹؼü»ù´¡ÉèÊ©ÁìÓòµÄÊý°ÙÍò¸ö²Ù×÷¼¼Êõ£¨OT£©É豸ÖС£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

NicheStack£¨±ðÃû InterNiche ²Ö¿â£©ÊÇÒ»¸ö³£Óõġ¢×¨ÓеÄǶÈëʽϵͳTCP/IPºÍ̸ջ£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÌṩ»¥ÁªÍøÏνӹ¤ÒµÉ豸£¬£¬£¬£¬£¬£¬£¬£¬²¢±»Î÷ÃÅ×Ó¡¢°¬Ä¬Éú¡¢»ôÄáΤ¶û¡¢ÈýÁâµç»ú¡¢ÂÞ¿ËΤ¶û×Ô¶¯»¯ºÍÊ©ÄÍµÂµçÆøµÈÖØÒª¹¤Òµ×Ô¶¯»¯³§ÉÌÄÉÈëÆä¿É±à³ÌÂß¼½ÚÔìÆ÷£¨PLC£©ºÍÆäËü²úÆ·ÖС£¡£¡£¡£¡£¡£NicheStackÖ§³ÖµÄºÍ̸Ô̺¬£º

×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓÃINFRA:HALT·ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á·ÛËé¹¹ÖþÎïµÄ HVAC ϵͳ»òÊÕÊÜÓÃÓÚÔì×÷ºÍÆäËü¹Ø¼ü»ù´¡ÉèÊ©µÄ½ÚÔìÆ÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö OT ºÍ ICS É豸ÀëÏß²¢±»½Ù³Ö£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¹¥»÷ÕßÄܹ»Í¨¹ý½Ù³ÖµÄÉ豸´«²¼¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£

INFRA:HALT·ì϶ÁбíÈçÏ£º
l CVE-2020-25928£¨CVSS ÆÀ·Ö£º9.8£©£º½âÎö DNS ÏìӦʱ²úÉúÔ½½ç¶Á/д£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
l CVE-2021-31226£¨CVSS ÆÀ·Ö£º9.1£©£º½âÎö HTTP post ÒªÇóʱµÄ¶Ñ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
l CVE-2020-25927£¨CVSS ÆÀ·Ö£º8.2£©£º½âÎö DNS ÏìӦʱԽ½ç¶ÁÈ¡£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£
l CVE-2020-25767£¨CVSS ÆÀ·Ö£º7.5£©£º½âÎö DNS ÓòÃûʱԽ½ç¶ÁÈ¡£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö»ؾø·þÎñºÍÐÅϢй¶¡£¡£¡£¡£¡£¡£
l CVE-2021-31227£¨CVSS ÆÀ·Ö£º7.5£©£º½âÎö HTTP post ÒªÇóʱµÄ¶Ñ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£
l CVE-2021-31400£¨CVSS ÆÀ·Ö£º7.5£©£ºTCP´ø±í´¹Î£Êý¾Ý´¦ÖÃÖ°ÄÜÖдæÔÚÎÞÏÞÑ»·Çé¿ö£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£
l CVE-2021-31401£¨CVSS ÆÀ·Ö£º7.5£©£ºTCP Í·²¿´¦ÖôúÂëÖеÄÕûÊýÒç¶Âí½Å¡£¡£¡£¡£¡£¡£
l CVE-2020-35683£¨CVSS ÆÀ·Ö£º7.5£©£º½âÎö ICMP Êý¾Ý°üʱԽ½ç¶ÁÈ¡£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£
l CVE-2020-35684£¨CVSS ÆÀ·Ö£º7.5£©£º½âÎö TCP Êý¾Ý°üʱԽ½ç¶ÁÈ¡£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£
l CVE-2020-35685£¨CVSS ÆÀ·Ö£º7.5£©£ºTCP ÏνÓÖпÉÔ¤²âµÄ³õʼÐòÁкŠ(ISN)£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂTCP ºýŪ¡£¡£¡£¡£¡£¡£
l CVE-2021-27565£¨CVSS ÆÀ·Ö£º7.5£©£ºÊÕµ½Î´Öª HTTP ÒªÇóʱ³öÏֻؾø·þÎñÇé¿ö¡£¡£¡£¡£¡£¡£
l CVE-2021-36762£¨CVSS ÆÀ·Ö£º7.5£©£ºTFTP Êý¾Ý°ü´¦ÖÃÖ°ÄÜÖеÄÔ½½ç¶ÁÈ¡£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£
l CVE-2020-25926£¨CVSS ÆÀ·Ö£º4.0£©£ºDNS ¿Í»§¶ËûÓÐÉèÖÃ×ã¹»Ëæ»úµÄÊÂÎñ ID£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö»º´æÖж¾¡£¡£¡£¡£¡£¡£
l CVE-2021-31228 (CVSS ÆÀ·Ö: 4.0) £º Äܹ»Ô¤²âDNS²éÎʵÄÔ´¶Ë¿Ú·¢ËÍαÔìµÄDNSÏìÓ¦°ü£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö»º´æÖж¾¡£¡£¡£¡£¡£¡£
ÕâÊǵÚÁù´ÎÔÚÊý°ÙÍòÁªÍøÉ豸ʹÓõĺÍ̸ջÖз¢ÏÖ°²È«·ì϶¡£¡£¡£¡£¡£¡£ÕâÌåÏÖ³öÁË¿í·ºÊ¹ÓÃµÄ TCP/IP ²Ö¿â°²È«µÄ³ÁÒªÐÔ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÕâЩ²Ö¿â±»¸÷À๩¸øÉÌÄÉÈëÆä¹Ì¼þÖÐÒÔÌṩ»¥ÁªÍøºÍÍøÂçÏνÓÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÆäÓ°ÏìÊÇÈ«ÇòÁìÓòÄڵġ£¡£¡£¡£¡£¡£ÆäËü5¸ö·ì϶¼¯±ðÀëΪ£º
l URGENT/11
l Ripple20
l AMNESIA:33
l NUMBER:JACK
l NAME:WRECK
Ó°ÏìÁìÓò
NicheStack°æ±¾ < 4.3
0x02 ´ëÖý¨Òé
ÕâЩ·ì϶ÒѾÔÚNicheStack v4.3Öн¨¸´¡£¡£¡£¡£¡£¡£Ä¿Ç°HCC Embedded£¨ÊÕ¹ºInterNiche Technologies£©ÒѾ°ä²¼ÁËÓйز¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓйع©¸øÉÌ£¨É漰ǶÈëÊ½ÍøÂ磩ʵʱÉý¼¶¸üС£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.hcc-embedded.com/support/security-advisories
»º½â´ëÊ©£º
Forescout °ä²¼ÁËÒ»¸ö¿ªÔ´¾ç±¾£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾Ê¹ÓÃ×Ô¶¯Ö¸ÎƼø±ðÀ´¼ì²âÔËÐÐ NicheStack µÄÉ豸¡£¡£¡£¡£¡£¡£ÏÂÔØÁ´½Ó£ºhttps://github.com/Forescout/project-memoria-detector
´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÖ´ÐзֶνÚÔ죬£¬£¬£¬£¬£¬£¬£¬¼à¿Ø¶ñÒâÊý¾Ý°üµÄËùÓÐÍøÂçÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ½µµÍÒ×Êܹ¥»÷É豸µÄ·çÏÕ¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://jfrog.com/blog/infrahalt-14-new-security-vulnerabilities-found-in-nichestack/
https://thehackernews.com/2021/08/critical-flaws-affect-embedded-tcpip.html
https://www.hcc-embedded.com/support/security-advisories
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-08-04 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ