Community discussions

MikroTik App
 
Wyz4k
Member Candidate
Member Candidate
Topic Author
Posts: 240
Joined: Fri Jul 10, 2009 10:23 am

Ripple20 - Treck stack vulnerabilities

Mon Jun 22, 2020 6:28 am

https://www.cisecurity.org/advisory/mul ... _2020-083/

Does Mikrotik make use of the Treck stack on any of their hardware?
 
dke
newbie
Posts: 47
Joined: Tue Dec 10, 2019 11:30 pm
Location: Austria

Re: Ripple20 - Treck stack vulnerabilities

Tue Sep 22, 2020 9:26 am

Any updates on this topic?
 
Wyz4k
Member Candidate
Member Candidate
Topic Author
Posts: 240
Joined: Fri Jul 10, 2009 10:23 am

Re: Ripple20 - Treck stack vulnerabilities

Tue Sep 22, 2020 9:32 am

I requested and tested the scripts on my MikroTiks and they weren't found to be vulnerable.
 
dke
newbie
Posts: 47
Joined: Tue Dec 10, 2019 11:30 pm
Location: Austria

Re: Ripple20 - Treck stack vulnerabilities

Tue Sep 22, 2020 10:03 am

Thank you very much for this information. Not that I would not believe, but do you have any more insights (e.g. the scripts to test, a report or something similar)?
 
Wyz4k
Member Candidate
Member Candidate
Topic Author
Posts: 240
Joined: Fri Jul 10, 2009 10:23 am

Re: Ripple20 - Treck stack vulnerabilities

Tue Sep 22, 2020 10:28 am

It's wise for each person to test it as their configuration may be different. You can contact them at sari @ jsof-tech dot com to request the latest scripts.

The scripts only output text, so it wouldn't qualify as a report.
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11594
Joined: Thu Mar 03, 2016 10:23 pm

Re: Ripple20 - Treck stack vulnerabilities

Tue Sep 22, 2020 10:49 am

Does Mikrotik make use of the Treck stack on any of their hardware?

Highly unlikely. ROS runs pretty stock Linux kernel with more or less stock IP stack which doesn't have any relation to Treck IP stack. In that regard, ROS is not embedded system, it's rather full-blown Linux device.
SwOS is different, but given MT's expertise with Linux kernel I'd expect them to take Linux as a base for SwOS IP stack.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7053
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: Ripple20 - Treck stack vulnerabilities

Tue Sep 22, 2020 12:25 pm

MT products are safe against Ripple20. And we do not use Treck IP stack anywhere.

Who is online

Users browsing this forum: Bing [Bot], GoogleOther [Bot], jhradl, mfischer, tlamik and 95 guests