{"id":122107,"date":"2024-05-15T14:56:42","date_gmt":"2024-05-15T14:56:42","guid":{"rendered":"https:\/\/bas-ip.com\/?page_id=122107"},"modified":"2024-11-05T10:51:18","modified_gmt":"2024-11-05T10:51:18","slug":"bsa-000001","status":"publish","type":"page","link":"https:\/\/bas-ip.com\/sl\/bsa-000001\/","title":{"rendered":"BSA-000001"},"content":{"rendered":"<h2 class=\"wp-block-heading\" id=\"bsa-000001\">Pregled<\/h2>\n\n\n\n<p>V ve\u010d interkomskih napravah BAS-IP je bila odkrita te\u017eava. Napadalec lahko z dostopom do spletnega vmesnika ali vmesnika API naprave pridobi gesla za stre\u017enik RTSP in ra\u010dun SIP naprave.<\/p>\n\n\n\n<p>Dru\u017eba BAS-IP te ranljivosti uvr\u0161\u010da med srednje te\u017eke in strankam priporo\u010da, da prizadete modele BAS-IP nadgradijo z najnovej\u0161o razli\u010dico vdelane programske opreme.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"risk-assessment\">Ocena tveganja<\/h2>\n\n\n\n<p>Morebitni nasprotnik potrebuje omre\u017eni dostop do naprave, da lahko izkoristi ranljivosti. Nasprotnik za uspe\u0161no kompromitiranje naprave potrebuje poverilnice. Tveganje je odvisno od tega, kako izpostavljena je naprava. Pri napravah, ki so obrnjene proti internetu (npr. izpostavljene prek usmerjevalnika port-forward), je tveganje veliko. Pri izdelkih, name\u0161\u010denih v za\u0161\u010ditenem lokalnem omre\u017eju, je tveganje manj\u0161e.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"risk-mitigation\">Zmanj\u0161evanje tveganja<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Priporo\u010dljivo je, da prizadete modele nadgradite z najnovej\u0161o vdelano programsko opremo.<\/li>\n\n\n\n<li>Naprav ni priporo\u010dljivo neposredno izpostavljati internetu (posredovanje vrat).<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"affected-models-and-patched-firmware\">Prizadeti modeli in popravljena vdelana programska oprema<\/h2>\n\n\n\n<p>Seznam prizadetih modelov:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>AV-01D<\/li>\n\n\n\n<li>AV-01MD<\/li>\n\n\n\n<li>AV-01MFD<\/li>\n\n\n\n<li>AV-01ED<\/li>\n\n\n\n<li>AV-01KD<\/li>\n\n\n\n<li>AV-01BD<\/li>\n\n\n\n<li>AV-01KBD<\/li>\n\n\n\n<li>AV-02D<\/li>\n\n\n\n<li>AV-02IDE<\/li>\n\n\n\n<li>AV-02IDR<\/li>\n\n\n\n<li>AV-02IPD<\/li>\n\n\n\n<li>AV-02FDE<\/li>\n\n\n\n<li>AV-02FDR<\/li>\n\n\n\n<li>AV-03D<\/li>\n\n\n\n<li>AV-03BD<\/li>\n\n\n\n<li>AV-04AFD<\/li>\n\n\n\n<li>AV-04ASD<\/li>\n\n\n\n<li>AV-04FD<\/li>\n\n\n\n<li>AV-04SD<\/li>\n\n\n\n<li>AV-05FD<\/li>\n\n\n\n<li>AV-05SD<\/li>\n\n\n\n<li>AA-07BD<\/li>\n\n\n\n<li>AA-07BDI<\/li>\n\n\n\n<li>BA-04BD<\/li>\n\n\n\n<li>BA-04MD<\/li>\n\n\n\n<li>BA-08BD<\/li>\n\n\n\n<li>BA-08MD<\/li>\n\n\n\n<li>BA-12BD<\/li>\n\n\n\n<li>BA-12MD<\/li>\n\n\n\n<li>CR-02BD<\/li>\n<\/ul>\n\n\n\n<p>Popravljena razli\u010dica vdelane programske opreme:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>3.9.2<\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Pregled V ve\u010d interkomskih napravah BAS-IP je bila odkrita te\u017eava. Napadalec lahko z dostopom do spletnega vmesnika ali vmesnika API naprave pridobi gesla za stre\u017enik RTSP in ra\u010dun SIP naprave. Dru\u017eba BAS-IP te ranljivosti uvr\u0161\u010da med srednje te\u017eke in strankam priporo\u010da, da prizadete modele BAS-IP nadgradijo z najnovej\u0161o razli\u010dico vdelane programske opreme. Ocena tveganja Morebitni [&hellip;]<\/p>","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-122107","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/bas-ip.com\/sl\/wp-json\/wp\/v2\/pages\/122107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bas-ip.com\/sl\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/bas-ip.com\/sl\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/sl\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/sl\/wp-json\/wp\/v2\/comments?post=122107"}],"version-history":[{"count":1,"href":"https:\/\/bas-ip.com\/sl\/wp-json\/wp\/v2\/pages\/122107\/revisions"}],"predecessor-version":[{"id":122108,"href":"https:\/\/bas-ip.com\/sl\/wp-json\/wp\/v2\/pages\/122107\/revisions\/122108"}],"wp:attachment":[{"href":"https:\/\/bas-ip.com\/sl\/wp-json\/wp\/v2\/media?parent=122107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}