OWASP๋ ๊ฐ์ ํจ์น๋ฅผ โ์๋ ค์ง ์ทจ์ฝ์ ์ ์ ์ฉํ์ง ๋ชปํ๊ฒ ํ๋ ๋ณด์ ์ ์ฑ ์ํ ๊ณ์ธตโ์ด๋ผ๊ณ ์ ์ํฉ๋๋ค. Cato๋ Cato ๋จ์ผ ํจ์ค ํด๋ผ์ฐ๋ ์์ง(SPACE)์ IPS ๊ณ์ธต์ ํตํด ๊ฐ์ ํจ์น๋ฅผ ์งํํฉ๋๋ค. Cato ์ ๋ฌธ๊ฐ๋ ์๋ก์ด IPS ๊ท์น์ ๋ฐฐํฌํ์ฌ ์๋ก์ด CVE์ ์ ์ํ ๋์ํ๋ฉฐ, ๊ณ ๊ฐ๋์ ๋ณ๋์ ์กฐ์น๋ฅผ ์ทจํ์ค ํ์๊ฐ ์์ต๋๋ค.
Name
CVE
Severity Score
Detect to Protect
Description
Apache Struts 2 ์น ํ๋ ์์ํฌ์์ ๊ฒฐํจ์ด ์๋ ํ์ผ ์ ๋ก๋ ๋ก์ง์ ํตํด ์๊ฒฉ์ผ๋ก ์ฝ๋๋ฅผ ์คํํ์ฌ ์์์ ํ์ผ์ ์ ๋ก๋ํ๊ณ ์ฝ๋๋ฅผ ์คํํ ์ ์์ต๋๋ค
Detection
POC ์ฌ์ฉ ๊ฐ๋ฅ – 2023๋ 12์ 12์ผ
Opt-in Protection
2023๋ 12์ 12์ผ
Global Protection
2023๋ 12์ 13์ผ
Name
CVE
Severity Score
Detect to Protect
Description
IOS XE์ HTTP ์น UI ๊ธฐ๋ฅ์ด ์คํ ์ค์ด๋ฉฐ ์ธํฐ๋ท์ ์ฐ๊ฒฐ๋ Cisco ๊ธฐ๊ธฐ์์ ๊ถํ ์์น ์ทจ์ฝ์ ์ด ๋ฐ์ํ ์ ์์ต๋๋ค
Detection
POC ์ฌ์ฉ ๊ฐ๋ฅ – 2023๋ 10์ 30์ผ 20:30(UTC)
Opt-in Protection
2023๋ 10์ 31์ผ 20:00(UTC)
Global Protection
2023๋ 11์ 1์ผ 20:00(UTC)
Name
CVE
Severity Score
Detect to Protect
Description
SOCKS5 ํ๋ก์ ํธ๋์ ฐ์ดํฌ ์ค ํธ์คํธ ์ด๋ฆ ํ์ธ์์ ํ ๋ฒํผ ์ค๋ฒํ๋ก ์ทจ์ฝ์ ์ผ๋ก ์ธํด ์ทจ์ฝํ libcurl์ด ๊ตฌํ๋์ด ์ ์์ ์ธ ์ฝ๋๊ฐ ์คํ๋ ์ ์์ต๋๋ค
Detection
2023๋ 10์ 11์ผ 06:30(UTC)
Opt-in Protection
2023๋ 10์ 11์ผ 20:00(UTC)
Global Protection
2023๋ 10์ 12์ผ 9:30(UTC)
Name
CVE
Severity Score
Detect to Protect
Description
๊ณต๊ฒฉ์๊ฐ ์ทจ์ฝํ ์๋ํฌ์ธํธ๋ฅผ ์ ์ฉํ์ฌ ๋ฌด๋จ์ผ๋ก ๊ด๋ฆฌ์๋ฅผ ์์ฑํ์ฌ ์๋ฒ ์ก์ธ์ค ๊ถํ์ ํ๋ํ ์ ์๋ Atlassian Confluence ์๋ฒ ๋ฐ ๋ฐ์ดํฐ ์ผํฐ์ ์จํ๋ ๋ฏธ์ค ๋ฒ์ ์ ๊ถํ ์์น ์ทจ์ฝ์ ์ ๋๋ค
Detection
2023๋ 10์ 4์ผ 13:00(UTC)
Opt-in Protection
2023๋ 10์ 5์ผ 11:00(UTC)
Global Protection
2023๋ 10์ 6์ผ 12:00(UTC)
Name
CVE
Severity Score
Detect to Protect
Description
๊ด๋ฆฌํ ํ์ผ ์ ์ก(MFT) ์๋ฃจ์ ์ธ InProgress์ MOVEit Transfer์ SQLi๋ ๊ณต๊ฒฉ์๊ฐ SQL ๋ช ๋ น์ ์คํํ ์ ์๊ฒ ํด์ฃผ๋ฉฐ, ์ด๋ก ์ธํด RCE๋ฅผ ํ์ฉํ๋ ์ ์ฉ ๋ฐฑ๋์ด๊ฐ ์ค์น๋ ์ ์์ต๋๋ค.
Detection
2023๋ 6์ 6์ผ ์ค์ 8:00
Opt-in Protection
2023๋ 6์ 8์ผ ์คํ 4:30
Global Protection
2023๋ 6์ 9์ผ ์คํ 2:00
Name
CVE
Severity Score
Detect to Protect
Description
Microsoft Outlook ๊ถํ ์์น ์ทจ์ฝ์ * ์์ ์๊ฐ ์์: Cato ๋ฐฉํ๋ฒฝ์ ์์๋ฐ์ด๋ SMB ํธ๋ํฝ์ ๊ธฐ๋ณธ์ ์ผ๋ก ์ฐจ๋จํฉ๋๋ค
Detection
2023๋ 3์ 3์ผ ์ค์ 8:02
Opt-in Protection
2023๋ 3์ 3์ผ ์ค์ 8:02
Global Protection
2023๋ 3์ 3์ผ ์ค์ 8:02
Name
CVE
Severity Score
Detect to Protect
Description
ProxyNotShell ์ต์คํ๋ก์ ์ฒด์ธ์ ์ผ๋ถ์ธ MS Exchange์ ์ผ๋ถ ๋ฒ์ ์ RCE(์๊ฒฉ ์ฝ๋ ์คํ)์ ์ทจ์ฝํฉ๋๋ค
Detection
2022๋ 12์ 21์ผ ์คํ 5:00
Opt-in Protection
2022๋ 12์ 21์ผ ์คํ 11:29
Global Protection
2022๋ 12์ 22์ผ ์คํ 4:45
Name
CVE
Severity Score
Detect to Protect
Description
Microsoft Exchange Server ๊ถํ ์์น ์ทจ์ฝ์
Detection
2022๋ 9์ 30์ผ ์คํ 1:19
Opt-in Protection
2022๋ 9์ 30์ผ ์คํ 11:25
Global Protection
2022๋ 10์ 2์ผ ์คํ 12:40
Name
CVE
Severity Score
Detect to Protect
Description
Microsoft Windows ์ง์ ์ง๋จ ๋๊ตฌ(MSDT) ์๊ฒฉ ์ฝ๋ ์คํ ์ทจ์ฝ์
Detection
2022๋ 8์ 10์ผ ์ค์ 11:22
Opt-in Protection
2022๋ 8์ 11์ผ ์คํ 6:38
Global Protection
2022๋ 8์ 12์ผ ์คํ 4:16
Name
CVE
Severity Score
Detect to Protect
Description
Apache Spark UI๋ ๊ตฌ์ฑ ์ต์ spark.acls.enable์ ํตํด ACLs๋ฅผ ํ์ฑํํ ์ ์๋ ๊ฐ๋ฅ์ฑ์ ์ ๊ณตํฉ๋๋ค. ์ธ์ฆ ํํฐ๋ฅผ ์ฌ์ฉํ๋ฉด ์ฌ์ฉ์์๊ฒ ์ ํ๋ฆฌ์ผ์ด์ ์ ๋ณด๊ฑฐ๋ ์์ ํ ์ ์๋ ์ก์ธ์ค ๊ถํ์ด ์๋์ง ํ์ธํ ์ ์์ต๋๋ค. ACLs๊ฐ ํ์ฑํ๋์ด ์๋ ๊ฒฝ์ฐ, HttpSecurityFilter์ ์ฝ๋ ๊ฒฝ๋ก๋ฅผ ํตํด ๋๊ตฐ๊ฐ ์์์ ์ฌ์ฉ์ ์ด๋ฆ์ผ๋ก ์ฌ์นญํ ์ ์์ต๋๋ค. ์ด ๊ฒฝ์ฐ ์ ์์ ์ธ ์ฌ์ฉ์๊ฐ ๊ถํ ํ์ธ ๊ธฐ๋ฅ์ ์ ๊ทผํ์ฌ ์ ๋ ฅ ๋ด์ฉ์ ๊ธฐ๋ฐ์ผ๋ก ์ ๋์ค ์ ธ ๋ช ๋ น์ ์์ฑํ๊ณ ์คํํ ์ ์์ต๋๋ค. ์ด๋ ๊ฒ ๋๋ฉด ํ์ฌ ์ฌ์ฉ์๊ฐ Spark๋ฅผ ์คํํ ๊ฒ์ฒ๋ผ ์์์ ์ ธ ๋ช ๋ น์ด ์คํ๋ฉ๋๋ค
Detection
2022๋ 7์ 19์ผ ์ค์ 10:06
Opt-in Protection
2022๋ 7์ 19์ผ ์คํ 7:25
Global Protection
2022๋ 7์ 20์ผ ์คํ 5:23
Name
CVE
Severity Score
Detect to Protect
Description
Microsoft Windows ์ง์ ์ง๋จ ๋๊ตฌ(MSDT) ์๊ฒฉ ์ฝ๋ ์คํ ์ทจ์ฝ์
Detection
2022๋ 5์ 31์ผ ์ค์ 8:43
Opt-in Protection
2022๋ 5์ 31์ผ ์คํ 10:06
Global Protection
2022๋ 6์ 1์ผ ์คํ 5:00
Name
CVE
Severity Score
Detect to Protect
Description
Spring Cloud Function ๋ฒ์ 3.1.6, 3.2.2 ๋ฐ ์ด์ ๋ฏธ์ง์ ๋ฒ์ ์์๋ ๋ผ์ฐํ ๊ธฐ๋ฅ์ ์ฌ์ฉํ ๋ ์ฌ์ฉ์๊ฐ ํน์ํ๊ฒ ์ ์๋ SpEL๋ฅผ ๋ผ์ฐํ ํํ์์ผ๋ก ์ ๊ณตํ์ฌ ์๊ฒฉ ์ฝ๋๋ฅผ ์คํํ๊ณ ๋ก์ปฌ ๋ฆฌ์์ค์ ์ก์ธ์คํ ์ ์์ต๋๋ค
Detection
2022๋ 3์ 30์ผ ์คํ 6:00
Opt-in Protection
2022๋ 3์ 30์ผ ์คํ 11:09
Global Protection
2022๋ 4์ 1์ผ ์คํ 7:54
Name
CVE
Severity Score
Detect to Protect
Description
๊ตฌ์ฑ, ๋ก๊ทธ ๋ฉ์์ง, ํ๋ผ๋ฏธํฐ์ ์ฌ์ฉ๋๋ Apache Log4j2 2.0-๋ฒ ํ9~2.15.0(๋ณด์ ๋ฆด๋ฆฌ์ค 2.12.2, 2.12.3, 2.3.1 ์ ์ธ) JNDI ๊ธฐ๋ฅ์ ๊ณต๊ฒฉ์๊ฐ ์ ์ดํ๋ LDAP ๋ฐ ๊ธฐํ JNDI ๊ด๋ จ ์๋ํฌ์ธํธ๋ฅผ ๋ณดํธํ์ง ๋ชปํฉ๋๋ค. ๋ก๊ทธ ๋ฉ์์ง ๋๋ ๋ก๊ทธ ๋ฉ์์ง ๋งค๊ฐ๋ณ์๋ฅผ ์ ์ดํ ์ ์๋ ๊ณต๊ฒฉ์๋ ๋ฉ์์ง ์กฐํ ๋์ฒด๊ฐ ํ์ฑํ๋ ๊ฒฝ์ฐ LDAP ์๋ฒ์์ ๋ถ๋ฌ์จ ์์์ ์ฝ๋๋ฅผ ์คํํ ์ ์์ต๋๋ค
Detection
2021๋ 12์ 10์ผ ์คํ 8:45
Opt-in Protection
2021๋ 12์ 11์ผ ์ค์ 3:16
Global Protection
2021๋ 12์ 11์ผ ์คํ 1:47
Name
CVE
Severity Score
Detect to Protect
Description
Apache HTTP Server 2.4.49์ ๊ฒฝ๋ก ์ ๊ทํ ๋ณ๊ฒฝ์์ ๊ฒฐํจ์ด ๋ฐ๊ฒฌ๋์์ต๋๋ค. ๊ณต๊ฒฉ์๋ ๊ฒฝ๋ก ํ์ ๊ณต๊ฒฉ์ผ๋ก ์์ผ๋ฆฌ์ด์ค ๊ฐ์ ์ง์๋ฌธ์ผ๋ก ๊ตฌ์ฑ๋ ๋๋ ํฐ๋ฆฌ ์ธ๋ถ์ ํ์ผ์ URL์ ๋งคํํ ์ ์์ต๋๋ค. ์ด๋ฌํ ๋๋ ํฐ๋ฆฌ ์ธ๋ถ์ ํ์ผ์ด ์ผ๋ฐ์ ์ธ ๊ธฐ๋ณธ ๊ตฌ์ฑ์ธ โ๋ชจ๋ ๊ฑฐ๋ถ ํ์โ๋ก ๋ณดํธ๋์ง ์๋ ๊ฒฝ์ฐ, ์ด๋ฌํ ๊ณต๊ฒฉ์ด ์ฑ๊ณตํ ์ ์์ต๋๋ค. ์ด๋ฌํ ์์ผ๋ฆฌ์ด์ค ๊ฒฝ๋ก์ ๋ํด CGI ์คํฌ๋ฆฝํธ๋ฅผ ํ์ฑํํ๋ฉด ์๊ฒฉ ์ฝ๋ ์คํ์ ํ ์ ์์ต๋๋ค
Detection
2021๋ 10์ 6์ผ ์ค์ 7:19
Opt-in Protection
2021๋ 10์ 7์ผ ์คํ 2:01
Global Protection
2021๋ 10์ 8์ผ ์ค์ 12:05
Name
CVE
Severity Score
Detect to Protect
Name
CVE
Severity Score
Detect to Protect
Description
vCenter Server์๋ ์ ๋๋ฆฌํฑ์ค ์๋น์ค์ ์์ ํ์ผ ์ ๋ก๋ ์ทจ์ฝ์ ์ด ํฌํจ๋์ด ์์ต๋๋ค. vCenter Server ํฌํธ 443์ ๋คํธ์ํฌ ์ก์ธ์ค ๊ถํ์ด ์๋ ์ ์์ ์ธ ๊ณต๊ฒฉ์๊ฐ ์ด ๋ฌธ์ ๋ฅผ ์ ์ฉํ์ฌ ํน์ํ๊ฒ ์กฐ์๋ ํ์ผ์ ์ ๋ก๋ํ์ฌ vCenter Server์์ ์ฝ๋๋ฅผ ์คํํ ์ ์์ต๋๋ค
Detection
2021๋ 9์ 23์ผ ์ค์ 8:36
Opt-in Protection
2021๋ 9์ 23์ผ ์คํ 6:23
Global Protection
2021๋ 9์ 26์ผ ์คํ 6:37
Name
CVE
Severity Score
Detect to Protect
Description
Windows Print Spooler ๊ถํ ์์น ์ทจ์ฝ์
Detection
2021๋ 7์ 5์ผ ์คํ 12:16
Opt-in Protection
2021๋ 7์ 11์ผ ์ค์ 10:52
Global Protection
2021๋ 7์ 11์ผ ์คํ 6:44
Name
CVE
Severity Score
Detect to Protect
Description
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server
Detection
May 31, 2021 at 10:55 AM
Opt-in Protection
June 1, 2021 at 9:47 PM
Global Protection
June 3, 2021 at 10:24 PM
Name
CVE
Severity Score
Detect to Protect
Description
On specific versions of BIG-IP and BIG-IQ , the iControl REST interface has an unauthenticated remote command execution vulnerability
Detection
Mar 20th, 2021 at 11:43ย PM
Opt-in Protection
Mar 23rd, 2021 at 12:12ย PM
Global Protection
March 23, 2021 at 7:21 PM
Name
CVE
Severity Score
Detect to Protect
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Detection
March 3, 2021 at 11:03 AM
Opt-in Protection
March 4, 2021 at 10:48 PM
Global Protection
March 7, 2021 at 1:26 PM
Name
CVE
Severity Score
Detect to Protect
Description
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
Detection
February 25, 2021 at 10:06 AM
Opt-in Protection
February 25, 2021 at 7:16 PM
Global Protection
February 26, 2021 at 12:03 PM
์๋ก์ด CVE๋ก๋ถํฐ ๋คํธ์ํฌ๋ฅผ ๋ณดํธํ๋๋ฐ ์์๋๋ ํ๋ก์ธ์ค, ๋ฆฌ์์ค, ์๊ฐ์ผ๋ก ๋ง์ ๊ณ ๊ฐ๋๋ค๊ป์ ์ด๋ ค์์ ๊ฒช์ต๋๋ค. ์ด์ ๋ ๋ค์๊ณผ ๊ฐ์ต๋๋ค.
๊ณต๊ธ์ ์ฒด๋ CVE๋ฅผ ์ฐ๊ตฌํ๊ณ ์๊ทธ๋์ฒ๋ฅผ ๊ฐ๋ฐํด์ผ ํฉ๋๋ค
๊ณ ๊ฐ์ ์ ์ง ๊ด๋ฆฌ ๊ธฐ๊ฐ ์ด๋ด์ ์๊ทธ๋์ฒ๋ฅผ ํ ์คํธํด์ผ ํฉ๋๋ค
๊ณ ๊ฐ ํ ์คํธ ์ ์๊ทธ๋์ฒ๊ฐ ํธ๋ํฝ์ ์ค๋จ์ํค๊ฑฐ๋ ๊ฒ์ฌ ์ฑ๋ฅ ๋๋ ์ฌ์ฉ์ ๊ฒฝํ์ ์ํฅ์ ๋ฏธ์น์ง ์๋์ง ํ์ธํด์ผ ํฉ๋๋ค
ํ ์คํธ์ ์ฑ๊ณตํ ๊ฒฝ์ฐ์๋ง ์๊ทธ๋์ฒ๋ฅผ ํ์ฑํํ ์ ์์ต๋๋ค
์ด ๋ฆฌ์์ค ์ง์ฝ์ ์ธ ํ๋ก์ธ์ค๋ก ์ธํด ๋ง์ ๊ณ ๊ฐ๋๋ค์ด ์นจ์ ๋ฐฉ์ง ์์คํ (IPS)์ ํ์ง ๋ชจ๋๋ก ์ ํํ๊ฑฐ๋ ์ต์ ์ ๋ณด์ ์ํ๋ฅผ ์ ์งํ๋ ๋ฐ ๋ค์ฒ์ง๊ฒ ๋ฉ๋๋ค. ๊ณต๊ฒฉ์๊ฐ ์ค๋๋ ์ทจ์ฝ์ ์ ํฌํจํ์ฌ ํจ์น๋์ง ์์ CVE๋ฅผ ์ ์ฉํ๋ ค๊ณ ์๋ํ๊ธฐ ๋๋ฌธ์ ์นจํด ์ํ์ด ์ปค์ง๋๋ค.
Cato ๋ณด์ํ์ด ์ํํ๋ ๊ฐ์ ํจ์น ํ๋ก์ธ์ค๋ ๋ค์ 4๋จ๊ณ๋ก ๊ตฌ์ฑ๋์ด ์์ต๋๋ค.
ํ๊ฐ
CVE์ ๋ฒ์๋ฅผ ํ๊ฐํ๊ณ ์ทจ์ฝ์ ์ ์กฐ์ฌํฉ๋๋ค. ํนํ, ์ค์ ๋ก ์ด CVE๋ฅผ ์ฌ์ฉํ ๊ณต๊ฒฉ์ด ๋ฐ์ํ ๊ฒฝ์ฐ๋ฅผ ํ๊ฐํฉ๋๋ค.
์ด๋ ์์คํ ์ด ์ํฅ์ ๋ฐ๋์ง์ ๊ณต๊ฒฉ์๊ฐ ์ด๋ป๊ฒ ๊ณต๊ฒฉ์ ํ๋์ง ์ดํดํฉ๋๋ค
๊ฐ๋ฐ
์๋ก์ด IPS ๊ท์น์ ์์ฑํ์ฌ ์ทจ์ฝ์ ์ ๊ฐ์ ํจ์นํฉ๋๋ค
ํธ๋ํฝ ๋ฉํ ๋ฐ์ดํฐ์ ๋ํ ๋ฐฑ ํ ์คํธ๋ฅผ ๊ธฐ๋ฐ์ผ๋ก ์คํ์ง๋ฅผ ์ ๊ฑฐํฉ๋๋ค
์ตํธ์ธ ๋ณดํธ
โ์๋ฎฌ๋ ์ด์ ๋ชจ๋โ์์ ๊ฐ์ ํจ์น๋ฅผ ์ ํ์ ์ผ๋ก ๋ฐฐํฌํฉ๋๋ค
ํน์ ๊ณ ๊ฐ์ ๋ํ ์ตํธ์ธ ๋ฐฉ์ง๋ฅผ ํ์ฑํํฉ๋๋ค
๊ธ๋ก๋ฒ ๋ณดํธ
๊ฐ์ ํจ์น๋ฅผ ์๋ฐฉ ๋ชจ๋๋ก ์ ํํฉ๋๋ค
๋ชจ๋ ๊ณ ๊ฐ๊ณผ ๋ชจ๋ ํธ๋ํฝ์ ๊ฐ์ ํจ์น๋ฅผ ์ ์ฉํฉ๋๋ค
์ด ํ๋ก์ธ์ค๋ ๊ณ ๊ฐ๋์ ๋ฆฌ์์ค๊ฐ ํ์ํ์ง ์์ผ๋ฉฐ ๊ณ ๊ฐ๋์ ๋น์ฆ๋์ค ์ด์์ ์ง์ฅ ์์ด ์งํ๋ฉ๋๋ค.