¡¾Â©¶´Í¨¸æ¡¿INFRA:HALT: NicheStack TCP/IP ¶ÑÕ»¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2021-08-040x00 ©¶´¸ÅÊö
2021Äê8ÔÂ4ÈÕ£¬JFrogºÍForescout µÄÑо¿ÈËÔ±Ðû²¼ÁËÒ»·ÝÁªºÏ³ÂËߣ¬¹ûÈ»Åû¶ÁËÔÚNicheStack TCP/IP ¶ÑÕ»Öз¢ÏÖµÄ14¸öÄþ¾²Â©¶´(ͳ³ÆÎªINFRA:HALT)£¬ÕâЩ©¶´¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС¢¾Ü¾ø·þÎñ¡¢ÐÅϢй©¡¢TCP ÆÛÆ»òDNS »º´æÖж¾¡£
NicheStackÊÇÒ»¸ö³£ÓõÄTCP/IP¶ÑÕ»£¬ËüÖÁÉÙ±»200¼Ò¹©Ó¦ÉÌÓÃÓÚÉú²ú»·¾³£¬²¢±»²¿ÊðÔÚÖÆÔì³§¡¢·¢µç¡¢Ë®´¦ÖõÈÒªº¦»ù´¡ÉèÊ©ÁìÓòµÄÊý°ÙÍò¸ö²Ù×÷¼¼Êõ£¨OT£©É豸ÖС£
0x01 ©¶´ÏêÇé
NicheStack£¨ÓÖÃû InterNiche ¶ÑÕ»£©ÊÇÒ»¸ö³£Óõġ¢×¨ÓеÄǶÈëʽϵͳTCP/IPÐÒéÕ»£¬Ö¼ÔÚÌṩ»¥ÁªÍøÁ¬½Ó¹¤ÒµÉ豸£¬²¢±»Î÷ÃÅ×Ó¡¢°¬Ä¬Éú¡¢»ôÄáΤ¶û¡¢ÈýÁâµç»ú¡¢ÂÞ¿ËΤ¶û×Ô¶¯»¯ºÍÊ©ÄÍµÂµçÆøµÈÖ÷Òª¹¤Òµ×Ô¶¯»¯³§ÉÌÄÉÈëÆä¿É±à³ÌÂß¼¿ØÖÆÆ÷£¨PLC£©ºÍÆäËü²úÎïÖС£NicheStackÖ§³ÖµÄÐÒé°üÂÞ£º
Ñо¿ÈËÔ±ÌåÏÖ£¬ÀÖ³ÉÀûÓÃINFRA:HALT©¶´µÄ¹¥»÷Õß¿ÉÄÜ»áÆÆ»µ½¨ÖþÎïµÄ HVAC ϵͳ»ò½Ó¹ÜÓÃÓÚÖÆÔìºÍÆäËüÒªº¦»ù´¡ÉèÊ©µÄ¿ØÖÆÆ÷£¬µ¼Ö OT ºÍ ICS É豸ÀëÏß²¢±»½Ù³Ö£¬¶øÇÒ¹¥»÷Õß¿ÉÒÔͨ¹ý½Ù³ÖµÄÉ豸Á÷´«¶ñÒâÈí¼þ¡£
INFRA:HALT©¶´ÁбíÈçÏ£º
l CVE-2020-25928£¨CVSS ÆÀ·Ö£º9.8£©£º½âÎö DNS ÏìӦʱ·¢ÉúÔ½½ç¶Á/д£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
l CVE-2021-31226£¨CVSS ÆÀ·Ö£º9.1£©£º½âÎö HTTP post ÇëÇóʱµÄ¶Ñ»º³åÇøÒç³ö©¶´£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
l CVE-2020-25927£¨CVSS ÆÀ·Ö£º8.2£©£º½âÎö DNS ÏìӦʱԽ½ç¶ÁÈ¡£¬µ¼Ö¾ܾø·þÎñ¡£
l CVE-2020-25767£¨CVSS ÆÀ·Ö£º7.5£©£º½âÎö DNS ÓòÃûʱԽ½ç¶ÁÈ¡£¬¿Éµ¼Ö¾ܾø·þÎñºÍÐÅϢй¶¡£
l CVE-2021-31227£¨CVSS ÆÀ·Ö£º7.5£©£º½âÎö HTTP post ÇëÇóʱµÄ¶Ñ»º³åÇøÒç³ö©¶´£¬¿Éµ¼Ö¾ܾø·þÎñ¡£
l CVE-2021-31400£¨CVSS ÆÀ·Ö£º7.5£©£ºTCP´øÍâ½ô¼±Êý¾Ý´¦Öù¦Ð§ÖдæÔÚÎÞÏÞÑ»·Çé¿ö£¬µ¼Ö¾ܾø·þÎñ¡£
l CVE-2021-31401£¨CVSS ÆÀ·Ö£º7.5£©£ºTCP Í·²¿´¦ÖôúÂëÖеÄÕûÊýÒç³ö©¶´¡£
l CVE-2020-35683£¨CVSS ÆÀ·Ö£º7.5£©£º½âÎö ICMP Êý¾Ý°üʱԽ½ç¶ÁÈ¡£¬µ¼Ö¾ܾø·þÎñ¡£
l CVE-2020-35684£¨CVSS ÆÀ·Ö£º7.5£©£º½âÎö TCP Êý¾Ý°üʱԽ½ç¶ÁÈ¡£¬µ¼Ö¾ܾø·þÎñ¡£
l CVE-2020-35685£¨CVSS ÆÀ·Ö£º7.5£©£ºTCP Á¬½ÓÖпÉÔ¤²âµÄ³õʼÐòÁкŠ(ISN)£¬µ¼ÖÂTCP ÆÛÆ¡£
l CVE-2021-27565£¨CVSS ÆÀ·Ö£º7.5£©£ºÊÕµ½Î´Öª HTTP ÇëÇóʱ·ºÆð¾Ü¾ø·þÎñÇé¿ö¡£
l CVE-2021-36762£¨CVSS ÆÀ·Ö£º7.5£©£ºTFTP Êý¾Ý°ü´¦Öù¦Ð§ÖеÄÔ½½ç¶ÁÈ¡£¬µ¼Ö¾ܾø·þÎñ¡£
l CVE-2020-25926£¨CVSS ÆÀ·Ö£º4.0£©£ºDNS ¿Í»§¶ËûÓÐÉèÖÃ×ã¹»Ëæ»úµÄÊÂÎñ ID£¬µ¼Ö»º´æÖж¾¡£
l CVE-2021-31228 (CVSS ÆÀ·Ö: 4.0) £º ¿ÉÒÔÔ¤²âDNS²éѯµÄÔ´¶Ë¿Ú·¢ËÍαÔìµÄDNSÏìÓ¦°ü£¬µ¼Ö»º´æÖж¾¡£
ÕâÊǵÚÁù´ÎÔÚÊý°ÙÍòÁªÍøÉ豸ʹÓõÄÐÒéÕ»Öз¢ÏÖÄþ¾²Â©¶´¡£ÕâÌåÏÖ³öÁ˹㷺ʹÓÃµÄ TCP/IP ¶ÑÕ»Äþ¾²µÄÖØÒªÐÔ£¬ÒòΪÕâЩ¶ÑÕ»±»ÖÖÖÖ¹©Ó¦ÉÌÄÉÈëÆä¹Ì¼þÖÐÒÔÌṩ»¥ÁªÍøºÍÍøÂçÁ¬½Ó¹¦Ð§£¬Òò´ËÆäÓ°ÏìÊÇÈ«Çò·¶Î§Äڵġ£ÆäËü5¸ö©¶´¼¯·Ö±ðΪ£º
l URGENT/11
l Ripple20
l AMNESIA:33
l NUMBER:JACK
l NAME:WRECK
Ó°Ï췶Χ
NicheStack°æ±¾ < 4.3
0x02 ´¦Öý¨Òé
ÕâЩ©¶´ÒѾÔÚNicheStack v4.3ÖÐÐÞ¸´¡£Ä¿Ç°HCC Embedded£¨ÊÕ¹ºInterNiche Technologies£©ÒѾÐû²¼ÁËÏà¹Ø²¹¶¡£¬½¨ÒéÏà¹Ø¹©Ó¦ÉÌ£¨É漰ǶÈëÊ½ÍøÂ磩¼°Ê±Éý¼¶¸üС£
ÏÂÔØÁ´½Ó£º
https://www.hcc-embedded.com/support/security-advisories
»º½â´ëÊ©£º
Forescout Ðû²¼ÁËÒ»¸ö¿ªÔ´½Å±¾£¬¸Ã½Å±¾Ê¹ÓÃÖ÷¶¯Ö¸ÎÆÊ¶±ðÀ´¼ì²âÔËÐÐ NicheStack µÄÉ豸¡£ÏÂÔØÁ´½Ó£ºhttps://github.com/Forescout/project-memoria-detector
´ËÍ⣬½¨Òéʵʩ·Ö¶Î¿ØÖÆ£¬¼à¿Ø¶ñÒâÊý¾Ý°üµÄËùÓÐÍøÂçÁ÷Á¿£¬ÒÔ½µµÍÒ×Êܹ¥»÷É豸µÄ·çÏÕ¡£
0x03 ²Î¿¼Á´½Ó
https://jfrog.com/blog/infrahalt-14-new-security-vulnerabilities-found-in-nichestack/
https://thehackernews.com/2021/08/critical-flaws-affect-embedded-tcpip.html
https://www.hcc-embedded.com/support/security-advisories
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-04 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º