Cato ๋ณด์•ˆ ๋ฆฌ์„œ์น˜์˜ ์‹ ์†ํ•œ CVE ์™„ํ™”

OWASP๋Š” ๊ฐ€์ƒ ํŒจ์น˜๋ฅผ โ€˜์•Œ๋ ค์ง„ ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜์ง€ ๋ชปํ•˜๊ฒŒ ํ•˜๋Š” ๋ณด์•ˆ ์ •์ฑ… ์‹œํ–‰ ๊ณ„์ธตโ€™์ด๋ผ๊ณ  ์ •์˜ํ•ฉ๋‹ˆ๋‹ค. Cato๋Š” Cato ๋‹จ์ผ ํŒจ์Šค ํด๋ผ์šฐ๋“œ ์—”์ง„(SPACE)์˜ IPS ๊ณ„์ธต์„ ํ†ตํ•ด ๊ฐ€์ƒ ํŒจ์น˜๋ฅผ ์ง„ํ–‰ํ•ฉ๋‹ˆ๋‹ค. Cato ์ „๋ฌธ๊ฐ€๋Š” ์ƒˆ๋กœ์šด IPS ๊ทœ์น™์„ ๋ฐฐํฌํ•˜์—ฌ ์ƒˆ๋กœ์šด CVE์— ์‹ ์†ํžˆ ๋Œ€์‘ํ•˜๋ฉฐ, ๊ณ ๊ฐ๋‹˜์€ ๋ณ„๋„์˜ ์กฐ์น˜๋ฅผ ์ทจํ•˜์‹ค ํ•„์š”๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค.

Cato๊ฐ€ ์™„ํ™”ํ•œ ์ผ๋ถ€ ์ค‘๋Œ€ CVE

Name

Apache Struts 2 ํŒŒ์ผ ์—…๋กœ๋“œ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2023-50164

Severity Score

9.8 (Critical)

Detect to Protect

1์ผ

Description

Apache Struts 2 ์›น ํ”„๋ ˆ์ž„์›Œํฌ์—์„œ ๊ฒฐํ•จ์ด ์žˆ๋Š” ํŒŒ์ผ ์—…๋กœ๋“œ ๋กœ์ง์„ ํ†ตํ•ด ์›๊ฒฉ์œผ๋กœ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์ž„์˜์˜ ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•˜๊ณ  ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

POC ์‚ฌ์šฉ ๊ฐ€๋Šฅ – 2023๋…„ 12์›” 12์ผ

Opt-in Protection

2023๋…„ 12์›” 12์ผ

Global Protection

2023๋…„ 12์›” 13์ผ

Name

Cisco IOS XE ์›น UI ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

CVE

CVE-2023-20198

Severity Score

10 (Critical)

Detect to Protect

2์ผ

Description

IOS XE์™€ HTTP ์›น UI ๊ธฐ๋Šฅ์ด ์‹คํ–‰ ์ค‘์ด๋ฉฐ ์ธํ„ฐ๋„ท์— ์—ฐ๊ฒฐ๋œ Cisco ๊ธฐ๊ธฐ์—์„œ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

POC ์‚ฌ์šฉ ๊ฐ€๋Šฅ – 2023๋…„ 10์›” 30์ผ 20:30(UTC)

Opt-in Protection

2023๋…„ 10์›” 31์ผ 20:00(UTC)

Global Protection

2023๋…„ 11์›” 1์ผ 20:00(UTC)

Name

cURL SOCKS5 ํ”„๋ก์‹œ ํž™ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ

CVE

CVE-2023-38545

Severity Score

7.5 (High)

Detect to Protect

1์ผ 3์‹œ๊ฐ„

Description

SOCKS5 ํ”„๋ก์‹œ ํ•ธ๋“œ์…ฐ์ดํฌ ์ค‘ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„ ํ™•์ธ์—์„œ ํž™ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ ์ทจ์•ฝ์ ์œผ๋กœ ์ธํ•ด ์ทจ์•ฝํ•œ libcurl์ด ๊ตฌํ˜„๋˜์–ด ์•…์˜์ ์ธ ์ฝ”๋“œ๊ฐ€ ์‹คํ–‰๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2023๋…„ 10์›” 11์ผ 06:30(UTC)

Opt-in Protection

2023๋…„ 10์›” 11์ผ 20:00(UTC)

Global Protection

2023๋…„ 10์›” 12์ผ 9:30(UTC)

Name

Atlassian Confluence ๋ฐ์ดํ„ฐ ์„ผํ„ฐ ๋ฐ ์„œ๋ฒ„ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

CVE

CVE-2023-22515

Severity Score

10 (Critical)

Detect to Protect

1์ผ 23์‹œ๊ฐ„

Description

๊ณต๊ฒฉ์ž๊ฐ€ ์ทจ์•ฝํ•œ ์—”๋“œํฌ์ธํŠธ๋ฅผ ์•…์šฉํ•˜์—ฌ ๋ฌด๋‹จ์œผ๋กœ ๊ด€๋ฆฌ์ž๋ฅผ ์ƒ์„ฑํ•˜์—ฌ ์„œ๋ฒ„ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ํš๋“ํ•  ์ˆ˜ ์žˆ๋Š” Atlassian Confluence ์„œ๋ฒ„ ๋ฐ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์˜ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ฒ„์ „์˜ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค

Detection

2023๋…„ 10์›” 4์ผ 13:00(UTC)

Opt-in Protection

2023๋…„ 10์›” 5์ผ 11:00(UTC)

Global Protection

2023๋…„ 10์›” 6์ผ 12:00(UTC)

Name

MOVEit Transfer SQLi

CVE

CVE-2023-34362

Severity Score

10 (Critical)

Detect to Protect

3์ผ 6์‹œ๊ฐ„

Description

๊ด€๋ฆฌํ˜• ํŒŒ์ผ ์ „์†ก(MFT) ์†”๋ฃจ์…˜์ธ InProgress์˜ MOVEit Transfer์˜ SQLi๋Š” ๊ณต๊ฒฉ์ž๊ฐ€ SQL ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋ฉฐ, ์ด๋กœ ์ธํ•ด RCE๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ์ „์šฉ ๋ฐฑ๋„์–ด๊ฐ€ ์„ค์น˜๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

2023๋…„ 6์›” 6์ผ ์˜ค์ „ 8:00

Opt-in Protection

2023๋…„ 6์›” 8์ผ ์˜คํ›„ 4:30

Global Protection

2023๋…„ 6์›” 9์ผ ์˜คํ›„ 2:00

Name

Microsoft Outlook ์›๊ฒฉ ํ•ด์‹œ ์ทจ์•ฝ์ 

CVE

CVE-2023-23397

Severity Score

9.8 (Critical)

Detect to Protect

0*

Description

Microsoft Outlook ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์  * ์†Œ์š” ์‹œ๊ฐ„ ์—†์Œ: Cato ๋ฐฉํ™”๋ฒฝ์€ ์•„์›ƒ๋ฐ”์šด๋“œ SMB ํŠธ๋ž˜ํ”ฝ์„ ๊ธฐ๋ณธ์ ์œผ๋กœ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค

Detection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Opt-in Protection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Global Protection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Name

OWASSRF, MS Exchange RCE

CVE

CVE-2022-41082

Severity Score

8.8 (High)

Detect to Protect

23์‹œ๊ฐ„ 45๋ถ„

Description

ProxyNotShell ์ต์Šคํ”Œ๋กœ์ž‡ ์ฒด์ธ์˜ ์ผ๋ถ€์ธ MS Exchange์˜ ์ผ๋ถ€ ๋ฒ„์ „์€ RCE(์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰)์— ์ทจ์•ฝํ•ฉ๋‹ˆ๋‹ค

Detection

2022๋…„ 12์›” 21์ผ ์˜คํ›„ 5:00

Opt-in Protection

2022๋…„ 12์›” 21์ผ ์˜คํ›„ 11:29

Global Protection

2022๋…„ 12์›” 22์ผ ์˜คํ›„ 4:45

Name

Microsoft Exchange ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-41040, CVE-2022-41082

Severity Score

8.8 (High)

Detect to Protect

2์ผ 10์‹œ๊ฐ„ 6๋ถ„

Description

Microsoft Exchange Server ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

Detection

2022๋…„ 9์›” 30์ผ ์˜คํ›„ 1:19

Opt-in Protection

2022๋…„ 9์›” 30์ผ ์˜คํ›„ 11:25

Global Protection

2022๋…„ 10์›” 2์ผ ์˜คํ›„ 12:40

Name

DogWalk – Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-34713

Severity Score

7.8 (High)

Detect to Protect

2์ผ 4์‹œ๊ฐ„ 54๋ถ„

Description

Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ(MSDT) ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ 

Detection

2022๋…„ 8์›” 10์ผ ์˜ค์ „ 11:22

Opt-in Protection

2022๋…„ 8์›” 11์ผ ์˜คํ›„ 6:38

Global Protection

2022๋…„ 8์›” 12์ผ ์˜คํ›„ 4:16

Name

Apache Spark ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-33891

Severity Score

8.8 (High)

Detect to Protect

1์ผ 7์‹œ๊ฐ„ 17๋ถ„

Description

Apache Spark UI๋Š” ๊ตฌ์„ฑ ์˜ต์…˜ spark.acls.enable์„ ํ†ตํ•ด ACLs๋ฅผ ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐ€๋Šฅ์„ฑ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ธ์ฆ ํ•„ํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์‚ฌ์šฉ์ž์—๊ฒŒ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋ณด๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ๋Š” ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ACLs๊ฐ€ ํ™œ์„ฑํ™”๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ, HttpSecurityFilter์˜ ์ฝ”๋“œ ๊ฒฝ๋กœ๋ฅผ ํ†ตํ•ด ๋ˆ„๊ตฐ๊ฐ€ ์ž„์˜์˜ ์‚ฌ์šฉ์ž ์ด๋ฆ„์œผ๋กœ ์‚ฌ์นญํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ์•…์˜์ ์ธ ์‚ฌ์šฉ์ž๊ฐ€ ๊ถŒํ•œ ํ™•์ธ ๊ธฐ๋Šฅ์— ์ ‘๊ทผํ•˜์—ฌ ์ž…๋ ฅ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ์œ ๋‹‰์Šค ์…ธ ๋ช…๋ น์„ ์ž‘์„ฑํ•˜๊ณ  ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ ‡๊ฒŒ ๋˜๋ฉด ํ˜„์žฌ ์‚ฌ์šฉ์ž๊ฐ€ Spark๋ฅผ ์‹คํ–‰ํ•œ ๊ฒƒ์ฒ˜๋Ÿผ ์ž„์˜์˜ ์…ธ ๋ช…๋ น์ด ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค

Detection

2022๋…„ 7์›” 19์ผ ์˜ค์ „ 10:06

Opt-in Protection

2022๋…„ 7์›” 19์ผ ์˜คํ›„ 7:25

Global Protection

2022๋…„ 7์›” 20์ผ ์˜คํ›„ 5:23

Name

Microsoft ์ง€์› ์ง„๋‹จ ๋„๊ตฌ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-30190

Severity Score

7.8 (High)

Detect to Protect

1์ผ 8์‹œ๊ฐ„ 17๋ถ„

Description

Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ(MSDT) ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ 

Detection

2022๋…„ 5์›” 31์ผ ์˜ค์ „ 8:43

Opt-in Protection

2022๋…„ 5์›” 31์ผ ์˜คํ›„ 10:06

Global Protection

2022๋…„ 6์›” 1์ผ ์˜คํ›„ 5:00

Name

VMware Tanzu Spring Cloud Function ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-22963

Severity Score

9.8 (Critical)

Detect to Protect

2์ผ 1์‹œ๊ฐ„ 54๋ถ„

Description

Spring Cloud Function ๋ฒ„์ „ 3.1.6, 3.2.2 ๋ฐ ์ด์ „ ๋ฏธ์ง€์› ๋ฒ„์ „์—์„œ๋Š” ๋ผ์šฐํŒ… ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•  ๋•Œ ์‚ฌ์šฉ์ž๊ฐ€ ํŠน์ˆ˜ํ•˜๊ฒŒ ์ œ์ž‘๋œ SpEL๋ฅผ ๋ผ์šฐํŒ… ํ‘œํ˜„์‹์œผ๋กœ ์ œ๊ณตํ•˜์—ฌ ์›๊ฒฉ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜๊ณ  ๋กœ์ปฌ ๋ฆฌ์†Œ์Šค์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2022๋…„ 3์›” 30์ผ ์˜คํ›„ 6:00

Opt-in Protection

2022๋…„ 3์›” 30์ผ ์˜คํ›„ 11:09

Global Protection

2022๋…„ 4์›” 1์ผ ์˜คํ›„ 7:54

Name

Log4shell

CVE

CVE-2021-44228

Severity Score

10.0 (Critical)

Detect to Protect

17์‹œ๊ฐ„ 2๋ถ„

Description

๊ตฌ์„ฑ, ๋กœ๊ทธ ๋ฉ”์‹œ์ง€, ํŒŒ๋ผ๋ฏธํ„ฐ์— ์‚ฌ์šฉ๋˜๋Š” Apache Log4j2 2.0-๋ฒ ํƒ€9~2.15.0(๋ณด์•ˆ ๋ฆด๋ฆฌ์Šค 2.12.2, 2.12.3, 2.3.1 ์ œ์™ธ) JNDI ๊ธฐ๋Šฅ์€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ œ์–ดํ•˜๋Š” LDAP ๋ฐ ๊ธฐํƒ€ JNDI ๊ด€๋ จ ์—”๋“œํฌ์ธํŠธ๋ฅผ ๋ณดํ˜ธํ•˜์ง€ ๋ชปํ•ฉ๋‹ˆ๋‹ค. ๋กœ๊ทธ ๋ฉ”์‹œ์ง€ ๋˜๋Š” ๋กœ๊ทธ ๋ฉ”์‹œ์ง€ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์ œ์–ดํ•  ์ˆ˜ ์žˆ๋Š” ๊ณต๊ฒฉ์ž๋Š” ๋ฉ”์‹œ์ง€ ์กฐํšŒ ๋Œ€์ฒด๊ฐ€ ํ™œ์„ฑํ™”๋œ ๊ฒฝ์šฐ LDAP ์„œ๋ฒ„์—์„œ ๋ถˆ๋Ÿฌ์˜จ ์ž„์˜์˜ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2021๋…„ 12์›” 10์ผ ์˜คํ›„ 8:45

Opt-in Protection

2021๋…„ 12์›” 11์ผ ์˜ค์ „ 3:16

Global Protection

2021๋…„ 12์›” 11์ผ ์˜คํ›„ 1:47

Name

Apache HTTP Server ๊ฒฝ๋กœ ํƒ์ƒ‰

CVE

CVE-2021-41773

Severity Score

7.5 (High)

Detect to Protect

1์ผ 16์‹œ๊ฐ„ 46๋ถ„

Description

Apache HTTP Server 2.4.49์˜ ๊ฒฝ๋กœ ์ •๊ทœํ™” ๋ณ€๊ฒฝ์—์„œ ๊ฒฐํ•จ์ด ๋ฐœ๊ฒฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ๊ฒฝ๋กœ ํƒ์ƒ‰ ๊ณต๊ฒฉ์œผ๋กœ ์—์ผ๋ฆฌ์–ด์Šค ๊ฐ™์€ ์ง€์‹œ๋ฌธ์œผ๋กœ ๊ตฌ์„ฑ๋œ ๋””๋ ‰ํ„ฐ๋ฆฌ ์™ธ๋ถ€์˜ ํŒŒ์ผ์— URL์„ ๋งคํ•‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๋””๋ ‰ํ„ฐ๋ฆฌ ์™ธ๋ถ€์˜ ํŒŒ์ผ์ด ์ผ๋ฐ˜์ ์ธ ๊ธฐ๋ณธ ๊ตฌ์„ฑ์ธ โ€˜๋ชจ๋‘ ๊ฑฐ๋ถ€ ํ•„์š”โ€™๋กœ ๋ณดํ˜ธ๋˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ, ์ด๋Ÿฌํ•œ ๊ณต๊ฒฉ์ด ์„ฑ๊ณตํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์—์ผ๋ฆฌ์–ด์Šค ๊ฒฝ๋กœ์— ๋Œ€ํ•ด CGI ์Šคํฌ๋ฆฝํŠธ๋ฅผ ํ™œ์„ฑํ™”ํ•˜๋ฉด ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰์„ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2021๋…„ 10์›” 6์ผ ์˜ค์ „ 7:19

Opt-in Protection

2021๋…„ 10์›” 7์ผ ์˜คํ›„ 2:01

Global Protection

2021๋…„ 10์›” 8์ผ ์˜ค์ „ 12:05

Name

Exchange Autodiscover ๋น„๋ฐ€๋ฒˆํ˜ธ

CVE

Severity Score

(Critical)

Detect to Protect

5์ผ 5์‹œ๊ฐ„ 30๋ถ„

Description

Detection

2021๋…„ 9์›” 30์ผ ์˜คํ›„ 2:33

Opt-in Protection

2022๋…„ 9์›” 30์ผ ์˜คํ›„ 5:40

Global Protection

2021๋…„ 10์›” 5์ผ ์˜คํ›„ 8:03

Name

VMware vCenter RCE (II)

CVE

CVE-2021-22005

Severity Score

9.8 (Critical)

Detect to Protect

3์ผ 10์‹œ๊ฐ„ 1๋ถ„

Description

vCenter Server์—๋Š” ์• ๋„๋ฆฌํ‹ฑ์Šค ์„œ๋น„์Šค์˜ ์ž„์˜ ํŒŒ์ผ ์—…๋กœ๋“œ ์ทจ์•ฝ์ ์ด ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. vCenter Server ํฌํŠธ 443์— ๋„คํŠธ์›Œํฌ ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ๋Š” ์•…์˜์ ์ธ ๊ณต๊ฒฉ์ž๊ฐ€ ์ด ๋ฌธ์ œ๋ฅผ ์•…์šฉํ•˜์—ฌ ํŠน์ˆ˜ํ•˜๊ฒŒ ์กฐ์ž‘๋œ ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•˜์—ฌ vCenter Server์—์„œ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2021๋…„ 9์›” 23์ผ ์˜ค์ „ 8:36

Opt-in Protection

2021๋…„ 9์›” 23์ผ ์˜คํ›„ 6:23

Global Protection

2021๋…„ 9์›” 26์ผ ์˜คํ›„ 6:37

Name

PrintNightmare Spooler RCE ์ทจ์•ฝ์ 

CVE

CVE-2021-1675

Severity Score

8.8 (High)

Detect to Protect

6์ผ 6์‹œ๊ฐ„ 28๋ถ„

Description

Windows Print Spooler ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

Detection

2021๋…„ 7์›” 5์ผ ์˜คํ›„ 12:16

Opt-in Protection

2021๋…„ 7์›” 11์ผ ์˜ค์ „ 10:52

Global Protection

2021๋…„ 7์›” 11์ผ ์˜คํ›„ 6:44

Name

Sphere Client (HTML5) Remote Code Execution

CVE

CVE-2021-21985

Severity Score

9.8 (Critical)

Detect to Protect

3 days, 11 hours, 29 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server

Detection

May 31, 2021 at 10:55 AM

Opt-in Protection

June 1, 2021 at 9:47 PM

Global Protection

June 3, 2021 at 10:24 PM

Name

F5 Vulnerability

CVE

CVE-2021-22986

Severity Score

9.8 (Critical)

Detect to Protect

2 days, 19 hours, 38 minutes

Description

On specific versions of BIG-IP and BIG-IQ , the iControl REST interface has an unauthenticated remote command execution vulnerability

Detection

Mar 20th, 2021 at 11:43ย PM

Opt-in Protection

Mar 23rd, 2021 at 12:12ย PM

Global Protection

March 23, 2021 at 7:21 PM

Name

MS Exchange SSRF

CVE

CVE-2021-26855

Severity Score

9.8 (Critical)

Detect to Protect

4 days, 2 hours, 23 minutes

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Detection

March 3, 2021 at 11:03 AM

Opt-in Protection

March 4, 2021 at 10:48 PM

Global Protection

March 7, 2021 at 1:26 PM

Name

VMWare VCenter RCE

CVE

CVE-2021-21972

Severity Score

9.8 (Critical)

Detect to Protect

1 day, 1 hour, 57 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

Detection

February 25, 2021 at 10:06 AM

Opt-in Protection

February 25, 2021 at 7:16 PM

Global Protection

February 26, 2021 at 12:03 PM

Name

Apache Struts 2 ํŒŒ์ผ ์—…๋กœ๋“œ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2023-50164

Severity Score

9.8

Detect to Protect

1์ผ

Description

Apache Struts 2 ์›น ํ”„๋ ˆ์ž„์›Œํฌ์—์„œ ๊ฒฐํ•จ์ด ์žˆ๋Š” ํŒŒ์ผ ์—…๋กœ๋“œ ๋กœ์ง์„ ํ†ตํ•ด ์›๊ฒฉ์œผ๋กœ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์ž„์˜์˜ ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•˜๊ณ  ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

POC ์‚ฌ์šฉ ๊ฐ€๋Šฅ – 2023๋…„ 12์›” 12์ผ

Opt-in Protection

2023๋…„ 12์›” 12์ผ

Global Protection

2023๋…„ 12์›” 13์ผ

Name

Cisco IOS XE ์›น UI ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

CVE

CVE-2023-20198

Severity Score

10

Detect to Protect

2์ผ

Description

IOS XE์™€ HTTP ์›น UI ๊ธฐ๋Šฅ์ด ์‹คํ–‰ ์ค‘์ด๋ฉฐ ์ธํ„ฐ๋„ท์— ์—ฐ๊ฒฐ๋œ Cisco ๊ธฐ๊ธฐ์—์„œ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

POC ์‚ฌ์šฉ ๊ฐ€๋Šฅ – 2023๋…„ 10์›” 30์ผ 20:30(UTC)

Opt-in Protection

2023๋…„ 10์›” 31์ผ 20:00(UTC)

Global Protection

2023๋…„ 11์›” 1์ผ 20:00(UTC)

Name

cURL SOCKS5 ํ”„๋ก์‹œ ํž™ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ

CVE

CVE-2023-38545

Severity Score

7.5

Detect to Protect

1์ผ 3์‹œ๊ฐ„

Description

SOCKS5 ํ”„๋ก์‹œ ํ•ธ๋“œ์…ฐ์ดํฌ ์ค‘ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„ ํ™•์ธ์—์„œ ํž™ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ ์ทจ์•ฝ์ ์œผ๋กœ ์ธํ•ด ์ทจ์•ฝํ•œ libcurl์ด ๊ตฌํ˜„๋˜์–ด ์•…์˜์ ์ธ ์ฝ”๋“œ๊ฐ€ ์‹คํ–‰๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2023๋…„ 10์›” 11์ผ 06:30(UTC)

Opt-in Protection

2023๋…„ 10์›” 11์ผ 20:00(UTC)

Global Protection

2023๋…„ 10์›” 12์ผ 9:30(UTC)

Name

Atlassian Confluence ๋ฐ์ดํ„ฐ ์„ผํ„ฐ ๋ฐ ์„œ๋ฒ„ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

CVE

CVE-2023-22515

Severity Score

10

Detect to Protect

1์ผ 23์‹œ๊ฐ„

Description

๊ณต๊ฒฉ์ž๊ฐ€ ์ทจ์•ฝํ•œ ์—”๋“œํฌ์ธํŠธ๋ฅผ ์•…์šฉํ•˜์—ฌ ๋ฌด๋‹จ์œผ๋กœ ๊ด€๋ฆฌ์ž๋ฅผ ์ƒ์„ฑํ•˜์—ฌ ์„œ๋ฒ„ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ํš๋“ํ•  ์ˆ˜ ์žˆ๋Š” Atlassian Confluence ์„œ๋ฒ„ ๋ฐ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์˜ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ฒ„์ „์˜ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค

Detection

2023๋…„ 10์›” 4์ผ 13:00(UTC)

Opt-in Protection

2023๋…„ 10์›” 5์ผ 11:00(UTC)

Global Protection

2023๋…„ 10์›” 6์ผ 12:00(UTC)

Name

MOVEit Transfer SQLi

CVE

CVE-2023-34362

Severity Score

10

Detect to Protect

3์ผ 6์‹œ๊ฐ„

Description

๊ด€๋ฆฌํ˜• ํŒŒ์ผ ์ „์†ก(MFT) ์†”๋ฃจ์…˜์ธ InProgress์˜ MOVEit Transfer์˜ SQLi๋Š” ๊ณต๊ฒฉ์ž๊ฐ€ SQL ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋ฉฐ, ์ด๋กœ ์ธํ•ด RCE๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ์ „์šฉ ๋ฐฑ๋„์–ด๊ฐ€ ์„ค์น˜๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

2023๋…„ 6์›” 6์ผ ์˜ค์ „ 8:00

Opt-in Protection

2023๋…„ 6์›” 8์ผ ์˜คํ›„ 4:30

Global Protection

2023๋…„ 6์›” 9์ผ ์˜คํ›„ 2:00

Name

Microsoft Outlook ์›๊ฒฉ ํ•ด์‹œ ์ทจ์•ฝ์ 

CVE

CVE-2023-23397

Severity Score

9.8

Detect to Protect

0*

Description

Microsoft Outlook ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์  * ์†Œ์š” ์‹œ๊ฐ„ ์—†์Œ: Cato ๋ฐฉํ™”๋ฒฝ์€ ์•„์›ƒ๋ฐ”์šด๋“œ SMB ํŠธ๋ž˜ํ”ฝ์„ ๊ธฐ๋ณธ์ ์œผ๋กœ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค

Detection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Opt-in Protection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Global Protection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Name

OWASSRF, MS Exchange RCE

CVE

CVE-2022-41082

Severity Score

8.8

Detect to Protect

23์‹œ๊ฐ„ 45๋ถ„

Description

ProxyNotShell ์ต์Šคํ”Œ๋กœ์ž‡ ์ฒด์ธ์˜ ์ผ๋ถ€์ธ MS Exchange์˜ ์ผ๋ถ€ ๋ฒ„์ „์€ RCE(์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰)์— ์ทจ์•ฝํ•ฉ๋‹ˆ๋‹ค

Detection

2022๋…„ 12์›” 21์ผ ์˜คํ›„ 5:00

Opt-in Protection

2022๋…„ 12์›” 21์ผ ์˜คํ›„ 11:29

Global Protection

2022๋…„ 12์›” 22์ผ ์˜คํ›„ 4:45

Name

Microsoft Exchange ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-41040, CVE-2022-41082

Severity Score

8.8

Detect to Protect

2์ผ 10์‹œ๊ฐ„ 6๋ถ„

Description

Microsoft Exchange Server ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

Detection

2022๋…„ 9์›” 30์ผ ์˜คํ›„ 1:19

Opt-in Protection

2022๋…„ 9์›” 30์ผ ์˜คํ›„ 11:25

Global Protection

2022๋…„ 10์›” 2์ผ ์˜คํ›„ 12:40

Name

DogWalk – Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-34713

Severity Score

7.8

Detect to Protect

2์ผ 4์‹œ๊ฐ„ 54๋ถ„

Description

Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ(MSDT) ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ 

Detection

2022๋…„ 8์›” 10์ผ ์˜ค์ „ 11:22

Opt-in Protection

2022๋…„ 8์›” 11์ผ ์˜คํ›„ 6:38

Global Protection

2022๋…„ 8์›” 12์ผ ์˜คํ›„ 4:16

Name

Apache Spark ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-33891

Severity Score

8.8

Detect to Protect

1์ผ 7์‹œ๊ฐ„ 17๋ถ„

Description

Apache Spark UI๋Š” ๊ตฌ์„ฑ ์˜ต์…˜ spark.acls.enable์„ ํ†ตํ•ด ACLs๋ฅผ ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐ€๋Šฅ์„ฑ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ธ์ฆ ํ•„ํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์‚ฌ์šฉ์ž์—๊ฒŒ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋ณด๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ๋Š” ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ACLs๊ฐ€ ํ™œ์„ฑํ™”๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ, HttpSecurityFilter์˜ ์ฝ”๋“œ ๊ฒฝ๋กœ๋ฅผ ํ†ตํ•ด ๋ˆ„๊ตฐ๊ฐ€ ์ž„์˜์˜ ์‚ฌ์šฉ์ž ์ด๋ฆ„์œผ๋กœ ์‚ฌ์นญํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ์•…์˜์ ์ธ ์‚ฌ์šฉ์ž๊ฐ€ ๊ถŒํ•œ ํ™•์ธ ๊ธฐ๋Šฅ์— ์ ‘๊ทผํ•˜์—ฌ ์ž…๋ ฅ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ์œ ๋‹‰์Šค ์…ธ ๋ช…๋ น์„ ์ž‘์„ฑํ•˜๊ณ  ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ ‡๊ฒŒ ๋˜๋ฉด ํ˜„์žฌ ์‚ฌ์šฉ์ž๊ฐ€ Spark๋ฅผ ์‹คํ–‰ํ•œ ๊ฒƒ์ฒ˜๋Ÿผ ์ž„์˜์˜ ์…ธ ๋ช…๋ น์ด ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค

Detection

2022๋…„ 7์›” 19์ผ ์˜ค์ „ 10:06

Opt-in Protection

2022๋…„ 7์›” 19์ผ ์˜คํ›„ 7:25

Global Protection

2022๋…„ 7์›” 20์ผ ์˜คํ›„ 5:23

Name

Microsoft ์ง€์› ์ง„๋‹จ ๋„๊ตฌ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-30190

Severity Score

7.8

Detect to Protect

1์ผ 8์‹œ๊ฐ„ 17๋ถ„

Description

Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ(MSDT) ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ 

Detection

2022๋…„ 5์›” 31์ผ ์˜ค์ „ 8:43

Opt-in Protection

2022๋…„ 5์›” 31์ผ ์˜คํ›„ 10:06

Global Protection

2022๋…„ 6์›” 1์ผ ์˜คํ›„ 5:00

Name

VMware Tanzu Spring Cloud Function ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-22963

Severity Score

9.8

Detect to Protect

2์ผ 1์‹œ๊ฐ„ 54๋ถ„

Description

Spring Cloud Function ๋ฒ„์ „ 3.1.6, 3.2.2 ๋ฐ ์ด์ „ ๋ฏธ์ง€์› ๋ฒ„์ „์—์„œ๋Š” ๋ผ์šฐํŒ… ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•  ๋•Œ ์‚ฌ์šฉ์ž๊ฐ€ ํŠน์ˆ˜ํ•˜๊ฒŒ ์ œ์ž‘๋œ SpEL๋ฅผ ๋ผ์šฐํŒ… ํ‘œํ˜„์‹์œผ๋กœ ์ œ๊ณตํ•˜์—ฌ ์›๊ฒฉ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜๊ณ  ๋กœ์ปฌ ๋ฆฌ์†Œ์Šค์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2022๋…„ 3์›” 30์ผ ์˜คํ›„ 6:00

Opt-in Protection

2022๋…„ 3์›” 30์ผ ์˜คํ›„ 11:09

Global Protection

2022๋…„ 4์›” 1์ผ ์˜คํ›„ 7:54

Name

Log4shell

CVE

CVE-2021-44228

Severity Score

10.0

Detect to Protect

17์‹œ๊ฐ„ 2๋ถ„

Description

๊ตฌ์„ฑ, ๋กœ๊ทธ ๋ฉ”์‹œ์ง€, ํŒŒ๋ผ๋ฏธํ„ฐ์— ์‚ฌ์šฉ๋˜๋Š” Apache Log4j2 2.0-๋ฒ ํƒ€9~2.15.0(๋ณด์•ˆ ๋ฆด๋ฆฌ์Šค 2.12.2, 2.12.3, 2.3.1 ์ œ์™ธ) JNDI ๊ธฐ๋Šฅ์€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ œ์–ดํ•˜๋Š” LDAP ๋ฐ ๊ธฐํƒ€ JNDI ๊ด€๋ จ ์—”๋“œํฌ์ธํŠธ๋ฅผ ๋ณดํ˜ธํ•˜์ง€ ๋ชปํ•ฉ๋‹ˆ๋‹ค. ๋กœ๊ทธ ๋ฉ”์‹œ์ง€ ๋˜๋Š” ๋กœ๊ทธ ๋ฉ”์‹œ์ง€ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์ œ์–ดํ•  ์ˆ˜ ์žˆ๋Š” ๊ณต๊ฒฉ์ž๋Š” ๋ฉ”์‹œ์ง€ ์กฐํšŒ ๋Œ€์ฒด๊ฐ€ ํ™œ์„ฑํ™”๋œ ๊ฒฝ์šฐ LDAP ์„œ๋ฒ„์—์„œ ๋ถˆ๋Ÿฌ์˜จ ์ž„์˜์˜ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2021๋…„ 12์›” 10์ผ ์˜คํ›„ 8:45

Opt-in Protection

2021๋…„ 12์›” 11์ผ ์˜ค์ „ 3:16

Global Protection

2021๋…„ 12์›” 11์ผ ์˜คํ›„ 1:47

Name

Apache HTTP Server ๊ฒฝ๋กœ ํƒ์ƒ‰

CVE

CVE-2021-41773

Severity Score

7.5

Detect to Protect

1์ผ 16์‹œ๊ฐ„ 46๋ถ„

Description

Apache HTTP Server 2.4.49์˜ ๊ฒฝ๋กœ ์ •๊ทœํ™” ๋ณ€๊ฒฝ์—์„œ ๊ฒฐํ•จ์ด ๋ฐœ๊ฒฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ๊ฒฝ๋กœ ํƒ์ƒ‰ ๊ณต๊ฒฉ์œผ๋กœ ์—์ผ๋ฆฌ์–ด์Šค ๊ฐ™์€ ์ง€์‹œ๋ฌธ์œผ๋กœ ๊ตฌ์„ฑ๋œ ๋””๋ ‰ํ„ฐ๋ฆฌ ์™ธ๋ถ€์˜ ํŒŒ์ผ์— URL์„ ๋งคํ•‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๋””๋ ‰ํ„ฐ๋ฆฌ ์™ธ๋ถ€์˜ ํŒŒ์ผ์ด ์ผ๋ฐ˜์ ์ธ ๊ธฐ๋ณธ ๊ตฌ์„ฑ์ธ โ€˜๋ชจ๋‘ ๊ฑฐ๋ถ€ ํ•„์š”โ€™๋กœ ๋ณดํ˜ธ๋˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ, ์ด๋Ÿฌํ•œ ๊ณต๊ฒฉ์ด ์„ฑ๊ณตํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์—์ผ๋ฆฌ์–ด์Šค ๊ฒฝ๋กœ์— ๋Œ€ํ•ด CGI ์Šคํฌ๋ฆฝํŠธ๋ฅผ ํ™œ์„ฑํ™”ํ•˜๋ฉด ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰์„ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2021๋…„ 10์›” 6์ผ ์˜ค์ „ 7:19

Opt-in Protection

2021๋…„ 10์›” 7์ผ ์˜คํ›„ 2:01

Global Protection

2021๋…„ 10์›” 8์ผ ์˜ค์ „ 12:05

Name

Exchange Autodiscover ๋น„๋ฐ€๋ฒˆํ˜ธ

CVE

Severity Score

Detect to Protect

5์ผ 5์‹œ๊ฐ„ 30๋ถ„

Description

Detection

2021๋…„ 9์›” 30์ผ ์˜คํ›„ 2:33

Opt-in Protection

2022๋…„ 9์›” 30์ผ ์˜คํ›„ 5:40

Global Protection

2021๋…„ 10์›” 5์ผ ์˜คํ›„ 8:03

Name

VMware vCenter RCE (II)

CVE

CVE-2021-22005

Severity Score

9.8

Detect to Protect

3์ผ 10์‹œ๊ฐ„ 1๋ถ„

Description

vCenter Server์—๋Š” ์• ๋„๋ฆฌํ‹ฑ์Šค ์„œ๋น„์Šค์˜ ์ž„์˜ ํŒŒ์ผ ์—…๋กœ๋“œ ์ทจ์•ฝ์ ์ด ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. vCenter Server ํฌํŠธ 443์— ๋„คํŠธ์›Œํฌ ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ๋Š” ์•…์˜์ ์ธ ๊ณต๊ฒฉ์ž๊ฐ€ ์ด ๋ฌธ์ œ๋ฅผ ์•…์šฉํ•˜์—ฌ ํŠน์ˆ˜ํ•˜๊ฒŒ ์กฐ์ž‘๋œ ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•˜์—ฌ vCenter Server์—์„œ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2021๋…„ 9์›” 23์ผ ์˜ค์ „ 8:36

Opt-in Protection

2021๋…„ 9์›” 23์ผ ์˜คํ›„ 6:23

Global Protection

2021๋…„ 9์›” 26์ผ ์˜คํ›„ 6:37

Name

PrintNightmare Spooler RCE ์ทจ์•ฝ์ 

CVE

CVE-2021-1675

Severity Score

8.8

Detect to Protect

6์ผ 6์‹œ๊ฐ„ 28๋ถ„

Description

Windows Print Spooler ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

Detection

2021๋…„ 7์›” 5์ผ ์˜คํ›„ 12:16

Opt-in Protection

2021๋…„ 7์›” 11์ผ ์˜ค์ „ 10:52

Global Protection

2021๋…„ 7์›” 11์ผ ์˜คํ›„ 6:44

Name

Sphere Client (HTML5) Remote Code Execution

CVE

CVE-2021-21985

Severity Score

9.8

Detect to Protect

3 days, 11 hours, 29 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server

Detection

May 31, 2021 at 10:55 AM

Opt-in Protection

June 1, 2021 at 9:47 PM

Global Protection

June 3, 2021 at 10:24 PM

Name

F5 Vulnerability

CVE

CVE-2021-22986

Severity Score

9.8

Detect to Protect

2 days, 19 hours, 38 minutes

Description

On specific versions of BIG-IP and BIG-IQ , the iControl REST interface has an unauthenticated remote command execution vulnerability

Detection

Mar 20th, 2021 at 11:43ย PM

Opt-in Protection

Mar 23rd, 2021 at 12:12ย PM

Global Protection

March 23, 2021 at 7:21 PM

Name

MS Exchange SSRF

CVE

CVE-2021-26855

Severity Score

9.8

Detect to Protect

4 days, 2 hours, 23 minutes

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Detection

March 3, 2021 at 11:03 AM

Opt-in Protection

March 4, 2021 at 10:48 PM

Global Protection

March 7, 2021 at 1:26 PM

Name

VMWare VCenter RCE

CVE

CVE-2021-21972

Severity Score

9.8

Detect to Protect

1 day, 1 hour, 57 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

Detection

February 25, 2021 at 10:06 AM

Opt-in Protection

February 25, 2021 at 7:16 PM

Global Protection

February 26, 2021 at 12:03 PM

CVE ์™„ํ™”๊ฐ€ ์–ด๋ ค์šด ์ด์œ ๋Š” ๋ฌด์—‡์ผ๊นŒ์š”?

์ƒˆ๋กœ์šด CVE๋กœ๋ถ€ํ„ฐ ๋„คํŠธ์›Œํฌ๋ฅผ ๋ณดํ˜ธํ•˜๋Š”๋ฐ ์†Œ์š”๋˜๋Š” ํ”„๋กœ์„ธ์Šค, ๋ฆฌ์†Œ์Šค, ์‹œ๊ฐ„์œผ๋กœ ๋งŽ์€ ๊ณ ๊ฐ๋‹˜๋“ค๊ป˜์„œ ์–ด๋ ค์›€์„ ๊ฒช์Šต๋‹ˆ๋‹ค. ์ด์œ ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

๊ณต๊ธ‰์—…์ฒด๋Š” CVE๋ฅผ ์—ฐ๊ตฌํ•˜๊ณ  ์‹œ๊ทธ๋‹ˆ์ฒ˜๋ฅผ ๊ฐœ๋ฐœํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค

๊ณ ๊ฐ์€ ์œ ์ง€ ๊ด€๋ฆฌ ๊ธฐ๊ฐ„ ์ด๋‚ด์— ์‹œ๊ทธ๋‹ˆ์ฒ˜๋ฅผ ํ…Œ์ŠคํŠธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค

๊ณ ๊ฐ ํ…Œ์ŠคํŠธ ์‹œ ์‹œ๊ทธ๋‹ˆ์ฒ˜๊ฐ€ ํŠธ๋ž˜ํ”ฝ์„ ์ค‘๋‹จ์‹œํ‚ค๊ฑฐ๋‚˜ ๊ฒ€์‚ฌ ์„ฑ๋Šฅ ๋˜๋Š” ์‚ฌ์šฉ์ž ๊ฒฝํ—˜์— ์˜ํ–ฅ์„ ๋ฏธ์น˜์ง€ ์•Š๋Š”์ง€ ํ™•์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค

ํ…Œ์ŠคํŠธ์— ์„ฑ๊ณตํ•œ ๊ฒฝ์šฐ์—๋งŒ ์‹œ๊ทธ๋‹ˆ์ฒ˜๋ฅผ ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

์ด ๋ฆฌ์†Œ์Šค ์ง‘์•ฝ์ ์ธ ํ”„๋กœ์„ธ์Šค๋กœ ์ธํ•ด ๋งŽ์€ ๊ณ ๊ฐ๋‹˜๋“ค์ด ์นจ์ž… ๋ฐฉ์ง€ ์‹œ์Šคํ…œ(IPS)์„ ํƒ์ง€ ๋ชจ๋“œ๋กœ ์ „ํ™˜ํ•˜๊ฑฐ๋‚˜ ์ตœ์ ์˜ ๋ณด์•ˆ ์ƒํƒœ๋ฅผ ์œ ์ง€ํ•˜๋Š” ๋ฐ ๋’ค์ฒ˜์ง€๊ฒŒ ๋ฉ๋‹ˆ๋‹ค. ๊ณต๊ฒฉ์ž๊ฐ€ ์˜ค๋ž˜๋œ ์ทจ์•ฝ์ ์„ ํฌํ•จํ•˜์—ฌ ํŒจ์น˜๋˜์ง€ ์•Š์€ CVE๋ฅผ ์•…์šฉํ•˜๋ ค๊ณ  ์‹œ๋„ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์นจํ•ด ์œ„ํ—˜์ด ์ปค์ง‘๋‹ˆ๋‹ค.

Cato Networks์˜ ์ƒˆ๋กœ์šด CVE์— ๋Œ€ํ•œ ์™„์ „ ์ž๋™ํ™”๋œ ๊ฐ€์ƒ ํŒจ์น˜

Cato ๋ณด์•ˆํŒ€์ด ์ˆ˜ํ–‰ํ•˜๋Š” ๊ฐ€์ƒ ํŒจ์น˜ ํ”„๋กœ์„ธ์Šค๋Š” ๋‹ค์Œ 4๋‹จ๊ณ„๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

ํ‰๊ฐ€

CVE์˜ ๋ฒ”์œ„๋ฅผ ํ‰๊ฐ€ํ•˜๊ณ  ์ทจ์•ฝ์ ์„ ์กฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ํŠนํžˆ, ์‹ค์ œ๋กœ ์ด CVE๋ฅผ ์‚ฌ์šฉํ•œ ๊ณต๊ฒฉ์ด ๋ฐœ์ƒํ•œ ๊ฒฝ์šฐ๋ฅผ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

์–ด๋А ์‹œ์Šคํ…œ์ด ์˜ํ–ฅ์„ ๋ฐ›๋Š”์ง€์™€ ๊ณต๊ฒฉ์ž๊ฐ€ ์–ด๋–ป๊ฒŒ ๊ณต๊ฒฉ์„ ํ•˜๋Š”์ง€ ์ดํ•ดํ•ฉ๋‹ˆ๋‹ค

๊ฐœ๋ฐœ

์ƒˆ๋กœ์šด IPS ๊ทœ์น™์„ ์ƒ์„ฑํ•˜์—ฌ ์ทจ์•ฝ์ ์„ ๊ฐ€์ƒ ํŒจ์น˜ํ•ฉ๋‹ˆ๋‹ค

ํŠธ๋ž˜ํ”ฝ ๋ฉ”ํƒ€ ๋ฐ์ดํ„ฐ์— ๋Œ€ํ•œ ๋ฐฑ ํ…Œ์ŠคํŠธ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์˜คํƒ์ง€๋ฅผ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค

์˜ตํŠธ์ธ ๋ณดํ˜ธ

โ€˜์‹œ๋ฎฌ๋ ˆ์ด์…˜ ๋ชจ๋“œโ€™์—์„œ ๊ฐ€์ƒ ํŒจ์น˜๋ฅผ ์„ ํƒ์ ์œผ๋กœ ๋ฐฐํฌํ•ฉ๋‹ˆ๋‹ค

ํŠน์ • ๊ณ ๊ฐ์— ๋Œ€ํ•œ ์˜ตํŠธ์ธ ๋ฐฉ์ง€๋ฅผ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค

๊ธ€๋กœ๋ฒŒ ๋ณดํ˜ธ

๊ฐ€์ƒ ํŒจ์น˜๋ฅผ ์˜ˆ๋ฐฉ ๋ชจ๋“œ๋กœ ์ „ํ™˜ํ•ฉ๋‹ˆ๋‹ค

๋ชจ๋“  ๊ณ ๊ฐ๊ณผ ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ์— ๊ฐ€์ƒ ํŒจ์น˜๋ฅผ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค

์ด ํ”„๋กœ์„ธ์Šค๋Š” ๊ณ ๊ฐ๋‹˜์˜ ๋ฆฌ์†Œ์Šค๊ฐ€ ํ•„์š”ํ•˜์ง€ ์•Š์œผ๋ฉฐ ๊ณ ๊ฐ๋‹˜์˜ ๋น„์ฆˆ๋‹ˆ์Šค ์šด์˜์— ์ง€์žฅ ์—†์ด ์ง„ํ–‰๋ฉ๋‹ˆ๋‹ค.

Request a Demo