Cato ๋ณด์•ˆ ๋ฆฌ์„œ์น˜์˜ ์‹ ์†ํ•œ CVE ์™„ํ™”

OWASP๋Š” ๊ฐ€์ƒ ํŒจ์น˜๋ฅผ โ€˜์•Œ๋ ค์ง„ ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜์ง€ ๋ชปํ•˜๊ฒŒ ํ•˜๋Š” ๋ณด์•ˆ ์ •์ฑ… ์‹œํ–‰ ๊ณ„์ธตโ€™์ด๋ผ๊ณ  ์ •์˜ํ•ฉ๋‹ˆ๋‹ค. Cato๋Š” Cato ๋‹จ์ผ ํŒจ์Šค ํด๋ผ์šฐ๋“œ ์—”์ง„(SPACE)์˜ IPS ๊ณ„์ธต์„ ํ†ตํ•ด ๊ฐ€์ƒ ํŒจ์น˜ํ•ฉ๋‹ˆ๋‹ค. Cato ์ „๋ฌธ๊ฐ€๋Š” ์ƒˆ๋กœ์šด IPS ๊ทœ์น™์„ ๋ฐฐํฌํ•˜์—ฌ ์ƒˆ๋กœ์šด CVE์— ์‹ ์†ํžˆ ๋Œ€์‘ํ•˜๋ฉฐ, ๊ณ ๊ฐ์‚ฌ๋Š” ๋ณ„๋„์˜ ์กฐ์น˜๋ฅผ ์ทจํ•˜์ง€ ์•Š์•„๋„ ๋ฉ๋‹ˆ๋‹ค.

Cato๊ฐ€ ์™„ํ™”ํ•œ ์ผ๋ถ€ ์ค‘์š” CVE

Name

์ธ์ฆ๋˜์ง€ ์•Š์€ ์›๊ฒฉ ๋ช…๋ น์–ด ์ฃผ์ž…์˜ ์ทจ์•ฝ์ 

CVE

CVE-2024-9474

Severity Score

7.2 (High)

Detect to Protect

0์ผ

Description

CVE-2024-9474๋Š” PAN-OS ์žฅ์น˜ ๊ด€๋ฆฌ ์›น ์ธํ„ฐํŽ˜์ด์Šค์˜ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค. ์ธ์ฆ๋˜์ง€ ์•Š์€ ์›๊ฒฉ ๊ณต๊ฒฉ์ž๋Š” CVE-2024-0012์™€ CVE-2024-9474๋ฅผ ์—ฐ๊ฒฐํ•˜์—ฌ ์ทจ์•ฝํ•œ PAN-OS ์žฅ์น˜์—์„œ ๋ฃจํŠธ ๊ถŒํ•œ์„ ์–ป์–ด ๋ช…๋ น์„ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

Detection

2024๋…„ 11์›” 18์ผ

Opt-in Protection

0 * ์ผ๋ฐ˜ ์„œ๋ช… ์›์ธ

Global Protection

0 * ์ผ๋ฐ˜ ์„œ๋ช… ์›์ธ

Name

Solarwind SERV-U ๋””๋ ‰ํ„ฐ๋ฆฌ ์ ‘๊ทผ ๊ณต๊ฒฉ

CVE

CVE-2024-28995

Severity Score

10 (Critical)

Detect to Protect

0 * ์ผ๋ฐ˜ ์„œ๋ช… ์›์ธ

Description

SolarWinds Serv-U ๋””๋ ‰ํ„ฐ๋ฆฌ ์ ‘๊ทผ ๊ณต๊ฒฉ ํ˜ธ์ŠคํŠธ ์ปดํ“จํ„ฐ์—์„œ ์ค‘์š”ํ•œ ํŒŒ์ผ์„ ์ฝ์„ ์ˆ˜ ์žˆ๋„๋ก ์•ก์„ธ์Šค ํ—ˆ์šฉ

Detection

2024๋…„ 6์›” 7์ผ ์˜คํ›„ 11:00

Opt-in Protection

0 * ์ผ๋ฐ˜ ์„œ๋ช… ์›์ธ

Global Protection

0 * ์ผ๋ฐ˜ ์„œ๋ช… ์›์ธ

Name

ConnectWise ScreenConnect ์ธ์ฆ ์šฐํšŒ

CVE

CVE-2024-1709

Severity Score

10 (Critical)

Detect to Protect

4์ผ

Description

ConnectWise ScreenConnect 23.9.7 ๋ฐ ์ด์ „ ๋ฒ„์ „์€ ๋Œ€์ฒด ๊ฒฝ๋กœ ๋˜๋Š” ์ฑ„๋„์„ ์‚ฌ์šฉํ•˜๋Š” ์ธ์ฆ ์šฐํšŒ ์ทจ์•ฝ์ ์˜ ์˜ํ–ฅ์œผ๋กœ ๊ณต๊ฒฉ์ž๋Š” ๊ธฐ๋ฐ€ ์ •๋ณด ๋˜๋Š” ์ค‘์š” ์‹œ์Šคํ…œ์— ์ง์ ‘ ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

2024๋…„ 2์›” 21์ผ

Opt-in Protection

2024๋…„ 2์›” 23์ผ ์˜ค์ „ 10:45 UTC

Global Protection

2024๋…„ 2์›” 25์ผ ์˜ค์ „ 09:00 UTC

Name

Jenkins ์ž„์˜ ํŒŒ์ผ ์ฝ๊ธฐ

CVE

CVE-2024-23897

Severity Score

9.8 (Critical)

Detect to Protect

2์ผ

Description

Jenkins 2.441 ๋ฐ ์ด์ „ ๋ฒ„์ „, LTS 2.426.2 ๋ฐ ์ด์ „ ๋ฒ„์ „์€ ์ธ์ˆ˜์—์„œ ํŒŒ์ผ ๊ฒฝ๋กœ ๋’ค์— '@' ๋ฌธ์ž๋ฅผ ํ•ด๋‹น ํŒŒ์ผ์˜ ๋‚ด์šฉ์œผ๋กœ ๋ฐ”๊พธ๋Š” CLI ๋ช…๋ น ํŒŒ์„œ์˜ ๊ธฐ๋Šฅ์ด ๋น„ํ™œ์„ฑํ™”๋˜์ง€ ์•Š์•„ ์ธ์ฆ๋˜์ง€ ์•Š์€ ๊ณต๊ฒฉ์ž๊ฐ€ Jenkins ์ปจํŠธ๋กค๋Ÿฌ ํŒŒ์ผ ์‹œ์Šคํ…œ์—์„œ ์ž„์˜์˜ ํŒŒ์ผ์„ ์ฝ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

2024๋…„ 1์›” 27์ผ

Opt-in Protection

2024๋…„ 1์›” 28์ผ ์˜คํ›„ 9:50

Global Protection

2024๋…„ 1์›” 29์ผ ์˜คํ›„ 5:30

Name

Atlassian Confluence ๋ฐ์ดํ„ฐ ์„ผํ„ฐ ๋ฐ ์„œ๋ฒ„ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2023-22527

Severity Score

10 (Critical)

Detect to Protect

1์ผ

Description

์ธ์ฆ๋˜์ง€ ์•Š์€ ๊ณต๊ฒฉ์ž๊ฐ€ ํ…œํ”Œ๋ฆฟ ์‚ฝ์ž…์„ ํ†ตํ•ด RCE ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์–ป์„ ์ˆ˜ ์žˆ๋Š” Atlassian Confluence ์„œ๋ฒ„ ๋ฐ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์˜ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค.

Detection

2024๋…„ 1์›” 22์ผ

Opt-in Protection

2024๋…„ 1์›” 22์ผ ์˜คํ›„ 7:00 UTC

Global Protection

2024๋…„ 1์›” 23์ผ ์˜ค์ „ 11:00 UTC

Name

Apache Struts 2 ํŒŒ์ผ ์—…๋กœ๋“œ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2023-50164

Severity Score

9.8 (Critical)

Detect to Protect

1์ผ

Description

Apache Struts 2 ์›น ํ”„๋ ˆ์ž„์›Œํฌ์—์„œ ๊ฒฐํ•จ์ด ์žˆ๋Š” ํŒŒ์ผ ์—…๋กœ๋“œ ๋กœ์ง์„ ํ†ตํ•ด ์›๊ฒฉ์œผ๋กœ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜๋ฉด ์ž„์˜์˜ ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•˜๊ณ  ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

POC ์‚ฌ์šฉ ๊ฐ€๋Šฅ – 2023๋…„ 12์›” 12์ผ

Opt-in Protection

2023๋…„ 12์›” 12์ผ

Global Protection

2023๋…„ 12์›” 13์ผ

Name

Cisco IOS XE ์›น UI ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

CVE

CVE-2023-20198

Severity Score

10 (Critical)

Detect to Protect

2์ผ

Description

IOS XE์™€ HTTP ์›น UI ๊ธฐ๋Šฅ์ด ์‹คํ–‰ ์ค‘์ด๋ฉฐ ์ธํ„ฐ๋„ท์— ์—ฐ๊ฒฐ๋œ Cisco ์žฅ์น˜์—์„œ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

POC ์‚ฌ์šฉ ๊ฐ€๋Šฅ – 2023๋…„ 10์›” 30์ผ 20:30 UTC

Opt-in Protection

2023๋…„ 10์›” 31์ผ ์˜คํ›„ 8:00 UTC

Global Protection

2023๋…„ 11์›” 1์ผ ์˜คํ›„ 8:00 UTC

Name

cURL SOCKS5 ํ”„๋ก์‹œ ํž™ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ

CVE

CVE-2023-38545

Severity Score

7.5 (High)

Detect to Protect

1์ผ 3์‹œ๊ฐ„

Description

SOCKS5 ํ”„๋ก์‹œ ํ•ธ๋“œ์…ฐ์ดํฌ ์ค‘ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„ ํ™•์ธ์—์„œ ํž™ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ ์ทจ์•ฝ์ ์œผ๋กœ ์ธํ•ด ์ทจ์•ฝํ•œ libcurl์ด ๊ตฌํ˜„๋˜์–ด ์•…์„ฑ ์ฝ”๋“œ๊ฐ€ ์‹คํ–‰๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2023๋…„ 10์›” 11์ผ ์˜ค์ „ 6:30 UTC

Opt-in Protection

2023๋…„ 10์›” 11์ผ ์˜คํ›„ 8:00 UTC

Global Protection

2023๋…„ 10์›” 12์ผ ์˜ค์ „ 9:30 UTC

Name

Atlassian Confluence ๋ฐ์ดํ„ฐ ์„ผํ„ฐ ๋ฐ ์„œ๋ฒ„ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

CVE

CVE-2023-22515

Severity Score

10 (Critical)

Detect to Protect

1์ผ 23์‹œ๊ฐ„

Description

๊ณต๊ฒฉ์ž๊ฐ€ ์ทจ์•ฝํ•œ ์—”๋“œํฌ์ธํŠธ๋ฅผ ์•…์šฉํ•˜์—ฌ ๋ฌด๋‹จ์œผ๋กœ ๊ด€๋ฆฌ์ž๋ฅผ ์ƒ์„ฑํ•˜์—ฌ ์„œ๋ฒ„ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ํš๋“ํ•  ์ˆ˜ ์žˆ๋Š” Atlassian Confluence ์„œ๋ฒ„ ๋ฐ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์˜ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ฒ„์ „์˜ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค.

Detection

2023๋…„ 10์›” 4์ผ ์˜คํ›„ 1:00 UTC

Opt-in Protection

2023๋…„ 10์›” 5์ผ ์˜ค์ „ 11:00 UTC

Global Protection

2023๋…„ 10์›” 6์ผ ์˜ค์ „ 12:00 UTC

Name

MOVEit Transfer SQLi

CVE

CVE-2023-34362

Severity Score

10 (Critical)

Detect to Protect

3์ผ 6์‹œ๊ฐ„

Description

๊ด€๋ฆฌํ˜• ํŒŒ์ผ ์ „์†ก(MFT) ์†”๋ฃจ์…˜์ธ InProgress์˜ MOVEit Transfer์˜ SQLi๋Š” ๊ณต๊ฒฉ์ž๊ฐ€ SQL ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋ฉฐ, ์ด๋กœ ์ธํ•ด RCE๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ์ „์šฉ ๋ฐฑ๋„์–ด๊ฐ€ ์„ค์น˜๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

2023๋…„ 6์›” 6์ผ ์˜ค์ „ 8:00

Opt-in Protection

2023๋…„ 6์›” 8์ผ ์˜คํ›„ 4:30

Global Protection

2023๋…„ 6์›” 9์ผ ์˜คํ›„ 2:00

Name

Microsoft Outlook ์›๊ฒฉ ํ•ด์‹œ ์ทจ์•ฝ์ 

CVE

CVE-2023-23397

Severity Score

9.8 (Critical)

Detect to Protect

0*

Description

Microsoft Outlook ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์  * ์†Œ์š” ์‹œ๊ฐ„ ์—†์Œ: Cato ๋ฐฉํ™”๋ฒฝ์€ ์•„์›ƒ๋ฐ”์šด๋“œ SMB ํŠธ๋ž˜ํ”ฝ์„ ๊ธฐ๋ณธ์ ์œผ๋กœ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค

Detection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Opt-in Protection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Global Protection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Name

OWASSRF, MS Exchange RCE

CVE

CVE-2022-41082

Severity Score

8.8 (High)

Detect to Protect

23์‹œ๊ฐ„ 45๋ถ„

Description

ProxyNotShell ์ต์Šคํ”Œ๋กœ์ž‡ ์ฒด์ธ์˜ ์ผ๋ถ€์ธ MS Exchange ์ผ๋ถ€ ๋ฒ„์ „์€ RCE(์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰)์— ์ทจ์•ฝํ•ฉ๋‹ˆ๋‹ค.

Detection

2022๋…„ 12์›” 21์ผ ์˜คํ›„ 5:00

Opt-in Protection

2022๋…„ 12์›” 21์ผ ์˜คํ›„ 11:29

Global Protection

2022๋…„ 12์›” 22์ผ ์˜คํ›„ 4:45

Name

Microsoft Exchange ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-41040, CVE-2022-41082

Severity Score

8.8 (High)

Detect to Protect

2์ผ 10์‹œ๊ฐ„ 6๋ถ„

Description

Microsoft Exchange Server ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

Detection

2022๋…„ 9์›” 30์ผ ์˜คํ›„ 1:19

Opt-in Protection

2022๋…„ 9์›” 30์ผ ์˜คํ›„ 11:25

Global Protection

2022๋…„ 10์›” 2์ผ ์˜คํ›„ 12:40

Name

DogWalk – Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-34713

Severity Score

7.8 (High)

Detect to Protect

2์ผ 4์‹œ๊ฐ„ 54๋ถ„

Description

Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ(MSDT) ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ 

Detection

2022๋…„ 8์›” 10์ผ ์˜ค์ „ 11:22

Opt-in Protection

2022๋…„ 8์›” 11์ผ ์˜คํ›„ 6:38

Global Protection

2022๋…„ 8์›” 12์ผ ์˜คํ›„ 4:16

Name

Apache Spark ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-33891

Severity Score

8.8 (High)

Detect to Protect

1์ผ 7์‹œ๊ฐ„ 17๋ถ„

Description

Apache Spark UI๋Š” ๊ตฌ์„ฑ ์˜ต์…˜ spark.acls.enable์„ ํ†ตํ•ด ACLs๋ฅผ ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐ€๋Šฅ์„ฑ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ธ์ฆ ํ•„ํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์‚ฌ์šฉ์ž์—๊ฒŒ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋ณด๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ๋Š” ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ACLs๊ฐ€ ํ™œ์„ฑํ™”๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ, HttpSecurityFilter์˜ ์ฝ”๋“œ ๊ฒฝ๋กœ๋ฅผ ํ†ตํ•ด ๋ˆ„๊ตฐ๊ฐ€ ์ž„์˜์˜ ์‚ฌ์šฉ์ž ์ด๋ฆ„์œผ๋กœ ์‚ฌ์นญํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ์•…์˜์ ์ธ ์‚ฌ์šฉ์ž๊ฐ€ ๊ถŒํ•œ ํ™•์ธ ๊ธฐ๋Šฅ์— ์ ‘๊ทผํ•˜์—ฌ ์ž…๋ ฅ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ Unix ์…ธ ๋ช…๋ น์–ด๋ฅผ ์ž‘์„ฑํ•˜๊ณ  ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ ‡๊ฒŒ ๋˜๋ฉด ํ˜„์žฌ ์‚ฌ์šฉ์ž๊ฐ€ Spark๋ฅผ ์‹คํ–‰ํ•œ ๊ฒƒ์ฒ˜๋Ÿผ ์ž„์˜์˜ ์…ธ ๋ช…๋ น์ด ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค

Detection

2022๋…„ 7์›” 19์ผ ์˜ค์ „ 10:06

Opt-in Protection

2022๋…„ 7์›” 19์ผ ์˜คํ›„ 7:25

Global Protection

2022๋…„ 7์›” 20์ผ ์˜คํ›„ 5:23

Name

Microsoft ์ง€์› ์ง„๋‹จ ๋„๊ตฌ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-30190

Severity Score

7.8 (High)

Detect to Protect

1์ผ 8์‹œ๊ฐ„ 17๋ถ„

Description

Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ(MSDT) ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ 

Detection

2022๋…„ 5์›” 31์ผ ์˜ค์ „ 8:43

Opt-in Protection

2022๋…„ 5์›” 31์ผ ์˜คํ›„ 10:06

Global Protection

2022๋…„ 6์›” 1์ผ ์˜คํ›„ 5:00

Name

VMware Tanzu Spring Cloud Function ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-22963

Severity Score

9.8 (Critical)

Detect to Protect

2์ผ 1์‹œ๊ฐ„ 54๋ถ„

Description

Spring Cloud Function ๋ฒ„์ „ 3.1.6, 3.2.2 ๋ฐ ์ด์ „ ๋ฏธ์ง€์› ๋ฒ„์ „์—์„œ๋Š” ๋ผ์šฐํŒ… ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•  ๋•Œ ์‚ฌ์šฉ์ž๊ฐ€ ํŠน์ˆ˜ํ•˜๊ฒŒ ์ œ์ž‘๋œ SpEL๋ฅผ ๋ผ์šฐํŒ… ํ‘œํ˜„์‹์œผ๋กœ ์ œ๊ณตํ•˜์—ฌ ์›๊ฒฉ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜๊ณ  ๋กœ์ปฌ ๋ฆฌ์†Œ์Šค์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

2022๋…„ 3์›” 30์ผ ์˜คํ›„ 6:00

Opt-in Protection

2022๋…„ 3์›” 30์ผ ์˜คํ›„ 11:09

Global Protection

2022๋…„ 4์›” 1์ผ ์˜คํ›„ 7:54

Name

Log4shell

CVE

CVE-2021-44228

Severity Score

10.0 (Critical)

Detect to Protect

17 hours, 2 minutes

Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled

Detection

Dec 10th, 2021 at 8:45 PM

Opt-in Protection

December 11, 2021 at 3:16 AM

Global Protection

December 11, 2021 at 1:47 PM

Name

Apache HTTP Server Path Traversal

CVE

CVE-2021-41773

Severity Score

7.5 (High)

Detect to Protect

1 day, 16 hours, 46 minutes

Description

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution

Detection

Oct 6th, 2021 at 7:19 AM

Opt-in Protection

October 7, 2021 at 2:01 PM

Global Protection

October 8, 2021 at 12:05 AM

Name

Exchange Autodiscover Password

CVE

Severity Score

(Critical)

Detect to Protect

5 days, 5 hours, 30 minutes

Description

Detection

Sep 30th, 2021 at 2:33 PM

Opt-in Protection

September 30, 2021 at 5:40 PM

Global Protection

October 5, 2021 at 8:03 PM

Name

VMware vCenter RCE (II)

CVE

CVE-2021-22005

Severity Score

9.8 (Critical)

Detect to Protect

3 days, 10 hours, 1 minute

Description

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file

Detection

Sep 23rd, 2021 at 8:36 AM

Opt-in Protection

September 23, 2021 at 6:23 PM

Global Protection

September 26, 2021 at 6:37 PM

Name

PrintNightmare Spooler RCE Vulnerability

CVE

CVE-2021-1675

Severity Score

8.8 (High)

Detect to Protect

6 days, 6 hours, 28 minutes

Description

Windows Print Spooler Elevation of Privilege Vulnerability

Detection

Jul 5th, 2021 at 12:16 PM

Opt-in Protection

July 11, 2021 at 10:52 AM

Global Protection

July 11, 2021 at 6:44 PM

Name

Sphere Client (HTML5) Remote Code Execution

CVE

CVE-2021-21985

Severity Score

9.8 (Critical)

Detect to Protect

3 days, 11 hours, 29 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server

Detection

May 31, 2021 at 10:55 AM

Opt-in Protection

June 1, 2021 at 9:47 PM

Global Protection

June 3, 2021 at 10:24 PM

Name

F5 Vulnerability

CVE

CVE-2021-22986

Severity Score

9.8 (Critical)

Detect to Protect

2 days, 19 hours, 38 minutes

Description

On specific versions of BIG-IP and BIG-IQ , the iControl REST interface has an unauthenticated remote command execution vulnerability

Detection

Mar 20th, 2021 at 11:43ย PM

Opt-in Protection

Mar 23rd, 2021 at 12:12ย PM

Global Protection

March 23, 2021 at 7:21 PM

Name

MS Exchange SSRF

CVE

CVE-2021-26855

Severity Score

9.8 (Critical)

Detect to Protect

4 days, 2 hours, 23 minutes

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Detection

March 3, 2021 at 11:03 AM

Opt-in Protection

March 4, 2021 at 10:48 PM

Global Protection

March 7, 2021 at 1:26 PM

Name

VMWare VCenter RCE

CVE

CVE-2021-21972

Severity Score

9.8 (Critical)

Detect to Protect

1 day, 1 hour, 57 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

Detection

February 25, 2021 at 10:06 AM

Opt-in Protection

February 25, 2021 at 7:16 PM

Global Protection

February 26, 2021 at 12:03 PM

Name

์ธ์ฆ๋˜์ง€ ์•Š์€ ์›๊ฒฉ ๋ช…๋ น์–ด ์ฃผ์ž…์˜ ์ทจ์•ฝ์ 

CVE

CVE-2024-9474

Severity Score

7.2

Detect to Protect

0์ผ

Description

CVE-2024-9474๋Š” PAN-OS ์žฅ์น˜ ๊ด€๋ฆฌ ์›น ์ธํ„ฐํŽ˜์ด์Šค์˜ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค. ์ธ์ฆ๋˜์ง€ ์•Š์€ ์›๊ฒฉ ๊ณต๊ฒฉ์ž๋Š” CVE-2024-0012์™€ CVE-2024-9474๋ฅผ ์—ฐ๊ฒฐํ•˜์—ฌ ์ทจ์•ฝํ•œ PAN-OS ์žฅ์น˜์—์„œ ๋ฃจํŠธ ๊ถŒํ•œ์„ ์–ป์–ด ๋ช…๋ น์„ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

Detection

2024๋…„ 11์›” 18์ผ

Opt-in Protection

0 * ์ผ๋ฐ˜ ์„œ๋ช… ์›์ธ

Global Protection

0 * ์ผ๋ฐ˜ ์„œ๋ช… ์›์ธ

Name

Solarwind SERV-U ๋””๋ ‰ํ„ฐ๋ฆฌ ์ ‘๊ทผ ๊ณต๊ฒฉ

CVE

CVE-2024-28995

Severity Score

10

Detect to Protect

0 * ์ผ๋ฐ˜ ์„œ๋ช… ์›์ธ

Description

SolarWinds Serv-U ๋””๋ ‰ํ„ฐ๋ฆฌ ์ ‘๊ทผ ๊ณต๊ฒฉ ํ˜ธ์ŠคํŠธ ์ปดํ“จํ„ฐ์—์„œ ์ค‘์š”ํ•œ ํŒŒ์ผ์„ ์ฝ์„ ์ˆ˜ ์žˆ๋„๋ก ์•ก์„ธ์Šค ํ—ˆ์šฉ

Detection

2024๋…„ 6์›” 7์ผ ์˜คํ›„ 11:00

Opt-in Protection

0 * ์ผ๋ฐ˜ ์„œ๋ช… ์›์ธ

Global Protection

0 * ์ผ๋ฐ˜ ์„œ๋ช… ์›์ธ

Name

ConnectWise ScreenConnect ์ธ์ฆ ์šฐํšŒ

CVE

CVE-2024-1709

Severity Score

10

Detect to Protect

4์ผ

Description

ConnectWise ScreenConnect 23.9.7 ๋ฐ ์ด์ „ ๋ฒ„์ „์€ ๋Œ€์ฒด ๊ฒฝ๋กœ ๋˜๋Š” ์ฑ„๋„์„ ์‚ฌ์šฉํ•˜๋Š” ์ธ์ฆ ์šฐํšŒ ์ทจ์•ฝ์ ์˜ ์˜ํ–ฅ์œผ๋กœ ๊ณต๊ฒฉ์ž๋Š” ๊ธฐ๋ฐ€ ์ •๋ณด ๋˜๋Š” ์ค‘์š” ์‹œ์Šคํ…œ์— ์ง์ ‘ ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

2024๋…„ 2์›” 21์ผ

Opt-in Protection

2024๋…„ 2์›” 23์ผ ์˜ค์ „ 10:45 UTC

Global Protection

2024๋…„ 2์›” 25์ผ ์˜ค์ „ 09:00 UTC

Name

Jenkins ์ž„์˜ ํŒŒ์ผ ์ฝ๊ธฐ

CVE

CVE-2024-23897

Severity Score

9.8

Detect to Protect

2์ผ

Description

Jenkins 2.441 ๋ฐ ์ด์ „ ๋ฒ„์ „, LTS 2.426.2 ๋ฐ ์ด์ „ ๋ฒ„์ „์€ ์ธ์ˆ˜์—์„œ ํŒŒ์ผ ๊ฒฝ๋กœ ๋’ค์— '@' ๋ฌธ์ž๋ฅผ ํ•ด๋‹น ํŒŒ์ผ์˜ ๋‚ด์šฉ์œผ๋กœ ๋ฐ”๊พธ๋Š” CLI ๋ช…๋ น ํŒŒ์„œ์˜ ๊ธฐ๋Šฅ์ด ๋น„ํ™œ์„ฑํ™”๋˜์ง€ ์•Š์•„ ์ธ์ฆ๋˜์ง€ ์•Š์€ ๊ณต๊ฒฉ์ž๊ฐ€ Jenkins ์ปจํŠธ๋กค๋Ÿฌ ํŒŒ์ผ ์‹œ์Šคํ…œ์—์„œ ์ž„์˜์˜ ํŒŒ์ผ์„ ์ฝ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

2024๋…„ 1์›” 27์ผ

Opt-in Protection

2024๋…„ 1์›” 28์ผ ์˜คํ›„ 9:50

Global Protection

2024๋…„ 1์›” 29์ผ ์˜คํ›„ 5:30

Name

Atlassian Confluence ๋ฐ์ดํ„ฐ ์„ผํ„ฐ ๋ฐ ์„œ๋ฒ„ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2023-22527

Severity Score

10

Detect to Protect

1์ผ

Description

์ธ์ฆ๋˜์ง€ ์•Š์€ ๊ณต๊ฒฉ์ž๊ฐ€ ํ…œํ”Œ๋ฆฟ ์‚ฝ์ž…์„ ํ†ตํ•ด RCE ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์–ป์„ ์ˆ˜ ์žˆ๋Š” Atlassian Confluence ์„œ๋ฒ„ ๋ฐ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์˜ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค.

Detection

2024๋…„ 1์›” 22์ผ

Opt-in Protection

2024๋…„ 1์›” 22์ผ ์˜คํ›„ 7:00 UTC

Global Protection

2024๋…„ 1์›” 23์ผ ์˜ค์ „ 11:00 UTC

Name

Apache Struts 2 ํŒŒ์ผ ์—…๋กœ๋“œ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2023-50164

Severity Score

9.8

Detect to Protect

1์ผ

Description

Apache Struts 2 ์›น ํ”„๋ ˆ์ž„์›Œํฌ์—์„œ ๊ฒฐํ•จ์ด ์žˆ๋Š” ํŒŒ์ผ ์—…๋กœ๋“œ ๋กœ์ง์„ ํ†ตํ•ด ์›๊ฒฉ์œผ๋กœ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜๋ฉด ์ž„์˜์˜ ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•˜๊ณ  ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

POC ์‚ฌ์šฉ ๊ฐ€๋Šฅ – 2023๋…„ 12์›” 12์ผ

Opt-in Protection

2023๋…„ 12์›” 12์ผ

Global Protection

2023๋…„ 12์›” 13์ผ

Name

Cisco IOS XE ์›น UI ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

CVE

CVE-2023-20198

Severity Score

10

Detect to Protect

2์ผ

Description

IOS XE์™€ HTTP ์›น UI ๊ธฐ๋Šฅ์ด ์‹คํ–‰ ์ค‘์ด๋ฉฐ ์ธํ„ฐ๋„ท์— ์—ฐ๊ฒฐ๋œ Cisco ์žฅ์น˜์—์„œ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

POC ์‚ฌ์šฉ ๊ฐ€๋Šฅ – 2023๋…„ 10์›” 30์ผ 20:30 UTC

Opt-in Protection

2023๋…„ 10์›” 31์ผ ์˜คํ›„ 8:00 UTC

Global Protection

2023๋…„ 11์›” 1์ผ ์˜คํ›„ 8:00 UTC

Name

cURL SOCKS5 ํ”„๋ก์‹œ ํž™ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ

CVE

CVE-2023-38545

Severity Score

7.5

Detect to Protect

1์ผ 3์‹œ๊ฐ„

Description

SOCKS5 ํ”„๋ก์‹œ ํ•ธ๋“œ์…ฐ์ดํฌ ์ค‘ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„ ํ™•์ธ์—์„œ ํž™ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ ์ทจ์•ฝ์ ์œผ๋กœ ์ธํ•ด ์ทจ์•ฝํ•œ libcurl์ด ๊ตฌํ˜„๋˜์–ด ์•…์„ฑ ์ฝ”๋“œ๊ฐ€ ์‹คํ–‰๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค

Detection

2023๋…„ 10์›” 11์ผ ์˜ค์ „ 6:30 UTC

Opt-in Protection

2023๋…„ 10์›” 11์ผ ์˜คํ›„ 8:00 UTC

Global Protection

2023๋…„ 10์›” 12์ผ ์˜ค์ „ 9:30 UTC

Name

Atlassian Confluence ๋ฐ์ดํ„ฐ ์„ผํ„ฐ ๋ฐ ์„œ๋ฒ„ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

CVE

CVE-2023-22515

Severity Score

10

Detect to Protect

1์ผ 23์‹œ๊ฐ„

Description

๊ณต๊ฒฉ์ž๊ฐ€ ์ทจ์•ฝํ•œ ์—”๋“œํฌ์ธํŠธ๋ฅผ ์•…์šฉํ•˜์—ฌ ๋ฌด๋‹จ์œผ๋กœ ๊ด€๋ฆฌ์ž๋ฅผ ์ƒ์„ฑํ•˜์—ฌ ์„œ๋ฒ„ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ํš๋“ํ•  ์ˆ˜ ์žˆ๋Š” Atlassian Confluence ์„œ๋ฒ„ ๋ฐ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์˜ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ฒ„์ „์˜ ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค.

Detection

2023๋…„ 10์›” 4์ผ ์˜คํ›„ 1:00 UTC

Opt-in Protection

2023๋…„ 10์›” 5์ผ ์˜ค์ „ 11:00 UTC

Global Protection

2023๋…„ 10์›” 6์ผ ์˜ค์ „ 12:00 UTC

Name

MOVEit Transfer SQLi

CVE

CVE-2023-34362

Severity Score

10

Detect to Protect

3์ผ 6์‹œ๊ฐ„

Description

๊ด€๋ฆฌํ˜• ํŒŒ์ผ ์ „์†ก(MFT) ์†”๋ฃจ์…˜์ธ InProgress์˜ MOVEit Transfer์˜ SQLi๋Š” ๊ณต๊ฒฉ์ž๊ฐ€ SQL ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋ฉฐ, ์ด๋กœ ์ธํ•ด RCE๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ์ „์šฉ ๋ฐฑ๋„์–ด๊ฐ€ ์„ค์น˜๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

2023๋…„ 6์›” 6์ผ ์˜ค์ „ 8:00

Opt-in Protection

2023๋…„ 6์›” 8์ผ ์˜คํ›„ 4:30

Global Protection

2023๋…„ 6์›” 9์ผ ์˜คํ›„ 2:00

Name

Microsoft Outlook ์›๊ฒฉ ํ•ด์‹œ ์ทจ์•ฝ์ 

CVE

CVE-2023-23397

Severity Score

9.8

Detect to Protect

0*

Description

Microsoft Outlook ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์  * ์†Œ์š” ์‹œ๊ฐ„ ์—†์Œ: Cato ๋ฐฉํ™”๋ฒฝ์€ ์•„์›ƒ๋ฐ”์šด๋“œ SMB ํŠธ๋ž˜ํ”ฝ์„ ๊ธฐ๋ณธ์ ์œผ๋กœ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค

Detection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Opt-in Protection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Global Protection

2023๋…„ 3์›” 3์ผ ์˜ค์ „ 8:02

Name

OWASSRF, MS Exchange RCE

CVE

CVE-2022-41082

Severity Score

8.8

Detect to Protect

23์‹œ๊ฐ„ 45๋ถ„

Description

ProxyNotShell ์ต์Šคํ”Œ๋กœ์ž‡ ์ฒด์ธ์˜ ์ผ๋ถ€์ธ MS Exchange ์ผ๋ถ€ ๋ฒ„์ „์€ RCE(์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰)์— ์ทจ์•ฝํ•ฉ๋‹ˆ๋‹ค.

Detection

2022๋…„ 12์›” 21์ผ ์˜คํ›„ 5:00

Opt-in Protection

2022๋…„ 12์›” 21์ผ ์˜คํ›„ 11:29

Global Protection

2022๋…„ 12์›” 22์ผ ์˜คํ›„ 4:45

Name

Microsoft Exchange ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-41040, CVE-2022-41082

Severity Score

8.8

Detect to Protect

2์ผ 10์‹œ๊ฐ„ 6๋ถ„

Description

Microsoft Exchange Server ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ 

Detection

2022๋…„ 9์›” 30์ผ ์˜คํ›„ 1:19

Opt-in Protection

2022๋…„ 9์›” 30์ผ ์˜คํ›„ 11:25

Global Protection

2022๋…„ 10์›” 2์ผ ์˜คํ›„ 12:40

Name

DogWalk – Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-34713

Severity Score

7.8

Detect to Protect

2์ผ 4์‹œ๊ฐ„ 54๋ถ„

Description

Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ(MSDT) ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ 

Detection

2022๋…„ 8์›” 10์ผ ์˜ค์ „ 11:22

Opt-in Protection

2022๋…„ 8์›” 11์ผ ์˜คํ›„ 6:38

Global Protection

2022๋…„ 8์›” 12์ผ ์˜คํ›„ 4:16

Name

Apache Spark ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-33891

Severity Score

8.8

Detect to Protect

1์ผ 7์‹œ๊ฐ„ 17๋ถ„

Description

Apache Spark UI๋Š” ๊ตฌ์„ฑ ์˜ต์…˜ spark.acls.enable์„ ํ†ตํ•ด ACLs๋ฅผ ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐ€๋Šฅ์„ฑ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ธ์ฆ ํ•„ํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์‚ฌ์šฉ์ž์—๊ฒŒ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋ณด๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ๋Š” ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ACLs๊ฐ€ ํ™œ์„ฑํ™”๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ, HttpSecurityFilter์˜ ์ฝ”๋“œ ๊ฒฝ๋กœ๋ฅผ ํ†ตํ•ด ๋ˆ„๊ตฐ๊ฐ€ ์ž„์˜์˜ ์‚ฌ์šฉ์ž ์ด๋ฆ„์œผ๋กœ ์‚ฌ์นญํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ์•…์˜์ ์ธ ์‚ฌ์šฉ์ž๊ฐ€ ๊ถŒํ•œ ํ™•์ธ ๊ธฐ๋Šฅ์— ์ ‘๊ทผํ•˜์—ฌ ์ž…๋ ฅ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ Unix ์…ธ ๋ช…๋ น์–ด๋ฅผ ์ž‘์„ฑํ•˜๊ณ  ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ ‡๊ฒŒ ๋˜๋ฉด ํ˜„์žฌ ์‚ฌ์šฉ์ž๊ฐ€ Spark๋ฅผ ์‹คํ–‰ํ•œ ๊ฒƒ์ฒ˜๋Ÿผ ์ž„์˜์˜ ์…ธ ๋ช…๋ น์ด ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค

Detection

2022๋…„ 7์›” 19์ผ ์˜ค์ „ 10:06

Opt-in Protection

2022๋…„ 7์›” 19์ผ ์˜คํ›„ 7:25

Global Protection

2022๋…„ 7์›” 20์ผ ์˜คํ›„ 5:23

Name

Microsoft ์ง€์› ์ง„๋‹จ ๋„๊ตฌ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-30190

Severity Score

7.8

Detect to Protect

1์ผ 8์‹œ๊ฐ„ 17๋ถ„

Description

Microsoft Windows ์ง€์› ์ง„๋‹จ ๋„๊ตฌ(MSDT) ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ 

Detection

2022๋…„ 5์›” 31์ผ ์˜ค์ „ 8:43

Opt-in Protection

2022๋…„ 5์›” 31์ผ ์˜คํ›„ 10:06

Global Protection

2022๋…„ 6์›” 1์ผ ์˜คํ›„ 5:00

Name

VMware Tanzu Spring Cloud Function ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰

CVE

CVE-2022-22963

Severity Score

9.8

Detect to Protect

2์ผ 1์‹œ๊ฐ„ 54๋ถ„

Description

Spring Cloud Function ๋ฒ„์ „ 3.1.6, 3.2.2 ๋ฐ ์ด์ „ ๋ฏธ์ง€์› ๋ฒ„์ „์—์„œ๋Š” ๋ผ์šฐํŒ… ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•  ๋•Œ ์‚ฌ์šฉ์ž๊ฐ€ ํŠน์ˆ˜ํ•˜๊ฒŒ ์ œ์ž‘๋œ SpEL๋ฅผ ๋ผ์šฐํŒ… ํ‘œํ˜„์‹์œผ๋กœ ์ œ๊ณตํ•˜์—ฌ ์›๊ฒฉ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜๊ณ  ๋กœ์ปฌ ๋ฆฌ์†Œ์Šค์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Detection

2022๋…„ 3์›” 30์ผ ์˜คํ›„ 6:00

Opt-in Protection

2022๋…„ 3์›” 30์ผ ์˜คํ›„ 11:09

Global Protection

2022๋…„ 4์›” 1์ผ ์˜คํ›„ 7:54

Name

Log4shell

CVE

CVE-2021-44228

Severity Score

10.0

Detect to Protect

17 hours, 2 minutes

Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled

Detection

Dec 10th, 2021 at 8:45 PM

Opt-in Protection

December 11, 2021 at 3:16 AM

Global Protection

December 11, 2021 at 1:47 PM

Name

Apache HTTP Server Path Traversal

CVE

CVE-2021-41773

Severity Score

7.5

Detect to Protect

1 day, 16 hours, 46 minutes

Description

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution

Detection

Oct 6th, 2021 at 7:19 AM

Opt-in Protection

October 7, 2021 at 2:01 PM

Global Protection

October 8, 2021 at 12:05 AM

Name

Exchange Autodiscover Password

CVE

Severity Score

Detect to Protect

5 days, 5 hours, 30 minutes

Description

Detection

Sep 30th, 2021 at 2:33 PM

Opt-in Protection

September 30, 2021 at 5:40 PM

Global Protection

October 5, 2021 at 8:03 PM

Name

VMware vCenter RCE (II)

CVE

CVE-2021-22005

Severity Score

9.8

Detect to Protect

3 days, 10 hours, 1 minute

Description

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file

Detection

Sep 23rd, 2021 at 8:36 AM

Opt-in Protection

September 23, 2021 at 6:23 PM

Global Protection

September 26, 2021 at 6:37 PM

Name

PrintNightmare Spooler RCE Vulnerability

CVE

CVE-2021-1675

Severity Score

8.8

Detect to Protect

6 days, 6 hours, 28 minutes

Description

Windows Print Spooler Elevation of Privilege Vulnerability

Detection

Jul 5th, 2021 at 12:16 PM

Opt-in Protection

July 11, 2021 at 10:52 AM

Global Protection

July 11, 2021 at 6:44 PM

Name

Sphere Client (HTML5) Remote Code Execution

CVE

CVE-2021-21985

Severity Score

9.8

Detect to Protect

3 days, 11 hours, 29 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server

Detection

May 31, 2021 at 10:55 AM

Opt-in Protection

June 1, 2021 at 9:47 PM

Global Protection

June 3, 2021 at 10:24 PM

Name

F5 Vulnerability

CVE

CVE-2021-22986

Severity Score

9.8

Detect to Protect

2 days, 19 hours, 38 minutes

Description

On specific versions of BIG-IP and BIG-IQ , the iControl REST interface has an unauthenticated remote command execution vulnerability

Detection

Mar 20th, 2021 at 11:43ย PM

Opt-in Protection

Mar 23rd, 2021 at 12:12ย PM

Global Protection

March 23, 2021 at 7:21 PM

Name

MS Exchange SSRF

CVE

CVE-2021-26855

Severity Score

9.8

Detect to Protect

4 days, 2 hours, 23 minutes

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Detection

March 3, 2021 at 11:03 AM

Opt-in Protection

March 4, 2021 at 10:48 PM

Global Protection

March 7, 2021 at 1:26 PM

Name

VMWare VCenter RCE

CVE

CVE-2021-21972

Severity Score

9.8

Detect to Protect

1 day, 1 hour, 57 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

Detection

February 25, 2021 at 10:06 AM

Opt-in Protection

February 25, 2021 at 7:16 PM

Global Protection

February 26, 2021 at 12:03 PM

CVE ์™„ํ™”๊ฐ€ ์–ด๋ ค์šด ์ด์œ ๋Š” ๋ฌด์—‡์ผ๊นŒ์š”?

์ƒˆ๋กœ์šด CVE๋กœ๋ถ€ํ„ฐ ๋„คํŠธ์›Œํฌ๋ฅผ ๋ณดํ˜ธํ•˜๋Š”๋ฐ ์†Œ์š”๋˜๋Š” ํ”„๋กœ์„ธ์Šค, ๋ฆฌ์†Œ์Šค, ์‹œ๊ฐ„์œผ๋กœ ๋งŽ์€ ๊ณ ๊ฐ์‚ฌ๊ฐ€ ์–ด๋ ค์›€์„ ๊ฒช์Šต๋‹ˆ๋‹ค. ์ด์œ ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

๊ณต๊ธ‰์—…์ฒด๋Š” CVE๋ฅผ ์—ฐ๊ตฌํ•˜๊ณ  ์‹œ๊ทธ๋‹ˆ์ฒ˜๋ฅผ ๊ฐœ๋ฐœํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๊ณ ๊ฐ์‚ฌ๋Š” ์œ ์ง€ ๊ด€๋ฆฌ ๊ธฐ๊ฐ„ ์ด๋‚ด์— ์‹œ๊ทธ๋‹ˆ์ฒ˜๋ฅผ ํ…Œ์ŠคํŠธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๊ณ ๊ฐ ํ…Œ์ŠคํŠธ ์‹œ ์‹œ๊ทธ๋‹ˆ์ฒ˜๊ฐ€ ํŠธ๋ž˜ํ”ฝ์„ ์ค‘๋‹จ์‹œํ‚ค๊ฑฐ๋‚˜ ๊ฒ€์‚ฌ ์„ฑ๋Šฅ ๋˜๋Š” ์‚ฌ์šฉ์ž ๊ฒฝํ—˜์— ์˜ํ–ฅ์„ ๋ฏธ์น˜์ง€ ์•Š๋Š”์ง€ ํ™•์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ํ…Œ์ŠคํŠธ๋ฅผ ํ†ต๊ณผํ•œ ๊ฒฝ์šฐ์—๋งŒ ์‹œ๊ทธ๋‹ˆ์ฒ˜๋ฅผ ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ๋ฆฌ์†Œ์Šค ์ง‘์•ฝ์ ์ธ ํ”„๋กœ์„ธ์Šค๋กœ ์ธํ•ด ๋งŽ์€ ๊ณ ๊ฐ๋‹˜๋“ค์ด ์นจ์ž… ๋ฐฉ์ง€ ์‹œ์Šคํ…œ(IPS)์„ ํƒ์ง€ ๋ชจ๋“œ๋กœ ์ „ํ™˜ํ•˜๊ฑฐ๋‚˜ ์ตœ์ ์˜ ๋ณด์•ˆ ์ƒํƒœ๋ฅผ ์œ ์ง€ํ•˜๋Š” ๋ฐ ๋’ค์ฒ˜์ง€๊ฒŒ ๋ฉ๋‹ˆ๋‹ค. ๊ณต๊ฒฉ์ž๊ฐ€ ์˜ค๋ž˜๋œ ์ทจ์•ฝ์ ์„ ํฌํ•จํ•˜์—ฌ ํŒจ์น˜๋˜์ง€ ์•Š์€ CVE๋ฅผ ์•…์šฉํ•˜๋ ค๊ณ  ์‹œ๋„ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์นจํ•ด ์œ„ํ—˜์ด ์ปค์ง‘๋‹ˆ๋‹ค.

Cato Networks๋ฅผ ํ†ตํ•œ ์‹ ๊ทœ CVE์˜ ์™„์ „ ์ž๋™ํ™”๋œ ๊ฐ€์ƒ ํŒจ์น˜

Cato ๋ณด์•ˆํŒ€์ด ์ˆ˜ํ–‰ํ•˜๋Š” ๊ฐ€์ƒ ํŒจ์น˜ ํ”„๋กœ์„ธ์Šค๋Š” ๋‹ค์Œ 4๋‹จ๊ณ„๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

ํ‰๊ฐ€

CVE์˜ ๋ฒ”์œ„๋ฅผ ํ‰๊ฐ€ํ•˜๊ณ  ์ทจ์•ฝ์ ์„ ์กฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ํŠนํžˆ, ์‹ค์ œ๋กœ ์ด CVE๋ฅผ ์‚ฌ์šฉํ•œ ๊ณต๊ฒฉ์ด ๋ฐœ์ƒํ•œ ๊ฒฝ์šฐ๋ฅผ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

์–ด๋А ์‹œ์Šคํ…œ์ด ์˜ํ–ฅ์„ ๋ฐ›๋Š”์ง€์™€ ๊ณต๊ฒฉ์ž๊ฐ€ ์–ด๋–ป๊ฒŒ ๊ณต๊ฒฉ์„ ํ•˜๋Š”์ง€ ํŒŒ์•…ํ•ฉ๋‹ˆ๋‹ค.

๊ฐœ๋ฐœ

์ƒˆ๋กœ์šด IPS ๊ทœ์น™์„ ์ƒ์„ฑํ•˜์—ฌ ์ทจ์•ฝ์ ์„ ๊ฐ€์ƒ ํŒจ์น˜ํ•ฉ๋‹ˆ๋‹ค.

ํŠธ๋ž˜ํ”ฝ ๋ฉ”ํƒ€ ๋ฐ์ดํƒ€์— ๋Œ€ํ•œ ๋ฐฑ ํ…Œ์ŠคํŠธ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์˜คํƒ์ง€๋ฅผ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค.

์˜ตํŠธ์ธ ๋ณดํ˜ธ

โ€˜์‹œ๋ฎฌ๋ ˆ์ด์…˜ ๋ชจ๋“œโ€™์—์„œ ๊ฐ€์ƒ ํŒจ์น˜๋ฅผ ์„ ํƒ์ ์œผ๋กœ ๋ฐฐํฌํ•ฉ๋‹ˆ๋‹ค.

ํŠน์ • ๊ณ ๊ฐ์— ๋Œ€ํ•œ ์˜ตํŠธ์ธ ๋ฐฉ์ง€๋ฅผ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.

๊ธ€๋กœ๋ฒŒ ๋ณดํ˜ธ

๊ฐ€์ƒ ํŒจ์น˜๋ฅผ ์˜ˆ๋ฐฉ ๋ชจ๋“œ๋กœ ์ „ํ™˜ํ•ฉ๋‹ˆ๋‹ค.

๋ชจ๋“  ๊ณ ๊ฐ๊ณผ ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ์— ๊ฐ€์ƒ ํŒจ์น˜๋ฅผ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค.

์ด ํ”„๋กœ์„ธ์Šค๋Š” ๊ณ ๊ฐ์‚ฌ์˜ ๋ฆฌ์†Œ์Šค๊ฐ€ ํ•„์š”ํ•˜์ง€ ์•Š์œผ๋ฉฐ ๊ณ ๊ฐ์‚ฌ์˜ ๋น„์ฆˆ๋‹ˆ์Šค ์šด์˜์— ์ง€์žฅ ์—†์ด ์ง„ํ–‰๋ฉ๋‹ˆ๋‹ค.

Request a Demo