OWASP๋ ๊ฐ์ ํจ์น๋ฅผ โ์๋ ค์ง ์ทจ์ฝ์ ์ ์ ์ฉํ์ง ๋ชปํ๊ฒ ํ๋ ๋ณด์ ์ ์ฑ ์ํ ๊ณ์ธตโ์ด๋ผ๊ณ ์ ์ํฉ๋๋ค. Cato๋ Cato ๋จ์ผ ํจ์ค ํด๋ผ์ฐ๋ ์์ง(SPACE)์ IPS ๊ณ์ธต์ ํตํด ๊ฐ์ ํจ์นํฉ๋๋ค. Cato ์ ๋ฌธ๊ฐ๋ ์๋ก์ด IPS ๊ท์น์ ๋ฐฐํฌํ์ฌ ์๋ก์ด CVE์ ์ ์ํ ๋์ํ๋ฉฐ, ๊ณ ๊ฐ์ฌ๋ ๋ณ๋์ ์กฐ์น๋ฅผ ์ทจํ์ง ์์๋ ๋ฉ๋๋ค.
Name
CVE
Severity Score
Detect to Protect
Description
CVE-2024-9474๋ PAN-OS ์ฅ์น ๊ด๋ฆฌ ์น ์ธํฐํ์ด์ค์ ๊ถํ ์์น ์ทจ์ฝ์ ์ ๋๋ค. ์ธ์ฆ๋์ง ์์ ์๊ฒฉ ๊ณต๊ฒฉ์๋ CVE-2024-0012์ CVE-2024-9474๋ฅผ ์ฐ๊ฒฐํ์ฌ ์ทจ์ฝํ PAN-OS ์ฅ์น์์ ๋ฃจํธ ๊ถํ์ ์ป์ด ๋ช ๋ น์ ์คํํฉ๋๋ค.
Detection
2024๋ 11์ 18์ผ
Opt-in Protection
0 * ์ผ๋ฐ ์๋ช ์์ธ
Global Protection
0 * ์ผ๋ฐ ์๋ช ์์ธ
Name
CVE
Severity Score
Detect to Protect
Description
SolarWinds Serv-U ๋๋ ํฐ๋ฆฌ ์ ๊ทผ ๊ณต๊ฒฉ ํธ์คํธ ์ปดํจํฐ์์ ์ค์ํ ํ์ผ์ ์ฝ์ ์ ์๋๋ก ์ก์ธ์ค ํ์ฉ
Detection
2024๋ 6์ 7์ผ ์คํ 11:00
Opt-in Protection
0 * ์ผ๋ฐ ์๋ช ์์ธ
Global Protection
0 * ์ผ๋ฐ ์๋ช ์์ธ
Name
CVE
Severity Score
Detect to Protect
Description
ConnectWise ScreenConnect 23.9.7 ๋ฐ ์ด์ ๋ฒ์ ์ ๋์ฒด ๊ฒฝ๋ก ๋๋ ์ฑ๋์ ์ฌ์ฉํ๋ ์ธ์ฆ ์ฐํ ์ทจ์ฝ์ ์ ์ํฅ์ผ๋ก ๊ณต๊ฒฉ์๋ ๊ธฐ๋ฐ ์ ๋ณด ๋๋ ์ค์ ์์คํ ์ ์ง์ ์ก์ธ์คํ ์ ์์ต๋๋ค.
Detection
2024๋ 2์ 21์ผ
Opt-in Protection
2024๋ 2์ 23์ผ ์ค์ 10:45 UTC
Global Protection
2024๋ 2์ 25์ผ ์ค์ 09:00 UTC
Name
CVE
Severity Score
Detect to Protect
Description
Jenkins 2.441 ๋ฐ ์ด์ ๋ฒ์ , LTS 2.426.2 ๋ฐ ์ด์ ๋ฒ์ ์ ์ธ์์์ ํ์ผ ๊ฒฝ๋ก ๋ค์ '@' ๋ฌธ์๋ฅผ ํด๋น ํ์ผ์ ๋ด์ฉ์ผ๋ก ๋ฐ๊พธ๋ CLI ๋ช ๋ น ํ์์ ๊ธฐ๋ฅ์ด ๋นํ์ฑํ๋์ง ์์ ์ธ์ฆ๋์ง ์์ ๊ณต๊ฒฉ์๊ฐ Jenkins ์ปจํธ๋กค๋ฌ ํ์ผ ์์คํ ์์ ์์์ ํ์ผ์ ์ฝ์ ์ ์์ต๋๋ค.
Detection
2024๋ 1์ 27์ผ
Opt-in Protection
2024๋ 1์ 28์ผ ์คํ 9:50
Global Protection
2024๋ 1์ 29์ผ ์คํ 5:30
Name
CVE
Severity Score
Detect to Protect
Description
์ธ์ฆ๋์ง ์์ ๊ณต๊ฒฉ์๊ฐ ํ ํ๋ฆฟ ์ฝ์ ์ ํตํด RCE ์ก์ธ์ค ๊ถํ์ ์ป์ ์ ์๋ Atlassian Confluence ์๋ฒ ๋ฐ ๋ฐ์ดํฐ ์ผํฐ์ ์๊ฒฉ ์ฝ๋ ์คํ ์ทจ์ฝ์ ์ ๋๋ค.
Detection
2024๋ 1์ 22์ผ
Opt-in Protection
2024๋ 1์ 22์ผ ์คํ 7:00 UTC
Global Protection
2024๋ 1์ 23์ผ ์ค์ 11:00 UTC
Name
CVE
Severity Score
Detect to Protect
Description
Apache Struts 2 ์น ํ๋ ์์ํฌ์์ ๊ฒฐํจ์ด ์๋ ํ์ผ ์ ๋ก๋ ๋ก์ง์ ํตํด ์๊ฒฉ์ผ๋ก ์ฝ๋๋ฅผ ์คํํ๋ฉด ์์์ ํ์ผ์ ์ ๋ก๋ํ๊ณ ์ฝ๋๋ฅผ ์คํํ ์ ์์ต๋๋ค.
Detection
POC ์ฌ์ฉ ๊ฐ๋ฅ – 2023๋ 12์ 12์ผ
Opt-in Protection
2023๋ 12์ 12์ผ
Global Protection
2023๋ 12์ 13์ผ
Name
CVE
Severity Score
Detect to Protect
Description
IOS XE์ HTTP ์น UI ๊ธฐ๋ฅ์ด ์คํ ์ค์ด๋ฉฐ ์ธํฐ๋ท์ ์ฐ๊ฒฐ๋ Cisco ์ฅ์น์์ ๊ถํ ์์น ์ทจ์ฝ์ ์ด ๋ฐ์ํ ์ ์์ต๋๋ค
Detection
POC ์ฌ์ฉ ๊ฐ๋ฅ – 2023๋ 10์ 30์ผ 20:30 UTC
Opt-in Protection
2023๋ 10์ 31์ผ ์คํ 8:00 UTC
Global Protection
2023๋ 11์ 1์ผ ์คํ 8:00 UTC
Name
CVE
Severity Score
Detect to Protect
Description
SOCKS5 ํ๋ก์ ํธ๋์ ฐ์ดํฌ ์ค ํธ์คํธ ์ด๋ฆ ํ์ธ์์ ํ ๋ฒํผ ์ค๋ฒํ๋ก ์ทจ์ฝ์ ์ผ๋ก ์ธํด ์ทจ์ฝํ libcurl์ด ๊ตฌํ๋์ด ์ ์ฑ ์ฝ๋๊ฐ ์คํ๋ ์ ์์ต๋๋ค
Detection
2023๋ 10์ 11์ผ ์ค์ 6:30 UTC
Opt-in Protection
2023๋ 10์ 11์ผ ์คํ 8:00 UTC
Global Protection
2023๋ 10์ 12์ผ ์ค์ 9:30 UTC
Name
CVE
Severity Score
Detect to Protect
Description
๊ณต๊ฒฉ์๊ฐ ์ทจ์ฝํ ์๋ํฌ์ธํธ๋ฅผ ์ ์ฉํ์ฌ ๋ฌด๋จ์ผ๋ก ๊ด๋ฆฌ์๋ฅผ ์์ฑํ์ฌ ์๋ฒ ์ก์ธ์ค ๊ถํ์ ํ๋ํ ์ ์๋ Atlassian Confluence ์๋ฒ ๋ฐ ๋ฐ์ดํฐ ์ผํฐ์ ์จํ๋ ๋ฏธ์ค ๋ฒ์ ์ ๊ถํ ์์น ์ทจ์ฝ์ ์ ๋๋ค.
Detection
2023๋ 10์ 4์ผ ์คํ 1:00 UTC
Opt-in Protection
2023๋ 10์ 5์ผ ์ค์ 11:00 UTC
Global Protection
2023๋ 10์ 6์ผ ์ค์ 12:00 UTC
Name
CVE
Severity Score
Detect to Protect
Description
๊ด๋ฆฌํ ํ์ผ ์ ์ก(MFT) ์๋ฃจ์ ์ธ InProgress์ MOVEit Transfer์ SQLi๋ ๊ณต๊ฒฉ์๊ฐ SQL ๋ช ๋ น์ ์คํํ ์ ์๊ฒ ํด์ฃผ๋ฉฐ, ์ด๋ก ์ธํด RCE๋ฅผ ํ์ฉํ๋ ์ ์ฉ ๋ฐฑ๋์ด๊ฐ ์ค์น๋ ์ ์์ต๋๋ค.
Detection
2023๋ 6์ 6์ผ ์ค์ 8:00
Opt-in Protection
2023๋ 6์ 8์ผ ์คํ 4:30
Global Protection
2023๋ 6์ 9์ผ ์คํ 2:00
Name
CVE
Severity Score
Detect to Protect
Description
Microsoft Outlook ๊ถํ ์์น ์ทจ์ฝ์ * ์์ ์๊ฐ ์์: Cato ๋ฐฉํ๋ฒฝ์ ์์๋ฐ์ด๋ SMB ํธ๋ํฝ์ ๊ธฐ๋ณธ์ ์ผ๋ก ์ฐจ๋จํฉ๋๋ค
Detection
2023๋ 3์ 3์ผ ์ค์ 8:02
Opt-in Protection
2023๋ 3์ 3์ผ ์ค์ 8:02
Global Protection
2023๋ 3์ 3์ผ ์ค์ 8:02
Name
CVE
Severity Score
Detect to Protect
Description
ProxyNotShell ์ต์คํ๋ก์ ์ฒด์ธ์ ์ผ๋ถ์ธ MS Exchange ์ผ๋ถ ๋ฒ์ ์ RCE(์๊ฒฉ ์ฝ๋ ์คํ)์ ์ทจ์ฝํฉ๋๋ค.
Detection
2022๋ 12์ 21์ผ ์คํ 5:00
Opt-in Protection
2022๋ 12์ 21์ผ ์คํ 11:29
Global Protection
2022๋ 12์ 22์ผ ์คํ 4:45
Name
CVE
Severity Score
Detect to Protect
Description
Microsoft Exchange Server ๊ถํ ์์น ์ทจ์ฝ์
Detection
2022๋ 9์ 30์ผ ์คํ 1:19
Opt-in Protection
2022๋ 9์ 30์ผ ์คํ 11:25
Global Protection
2022๋ 10์ 2์ผ ์คํ 12:40
Name
CVE
Severity Score
Detect to Protect
Description
Microsoft Windows ์ง์ ์ง๋จ ๋๊ตฌ(MSDT) ์๊ฒฉ ์ฝ๋ ์คํ ์ทจ์ฝ์
Detection
2022๋ 8์ 10์ผ ์ค์ 11:22
Opt-in Protection
2022๋ 8์ 11์ผ ์คํ 6:38
Global Protection
2022๋ 8์ 12์ผ ์คํ 4:16
Name
CVE
Severity Score
Detect to Protect
Description
Apache Spark UI๋ ๊ตฌ์ฑ ์ต์ spark.acls.enable์ ํตํด ACLs๋ฅผ ํ์ฑํํ ์ ์๋ ๊ฐ๋ฅ์ฑ์ ์ ๊ณตํฉ๋๋ค. ์ธ์ฆ ํํฐ๋ฅผ ์ฌ์ฉํ๋ฉด ์ฌ์ฉ์์๊ฒ ์ ํ๋ฆฌ์ผ์ด์ ์ ๋ณด๊ฑฐ๋ ์์ ํ ์ ์๋ ์ก์ธ์ค ๊ถํ์ด ์๋์ง ํ์ธํ ์ ์์ต๋๋ค. ACLs๊ฐ ํ์ฑํ๋์ด ์๋ ๊ฒฝ์ฐ, HttpSecurityFilter์ ์ฝ๋ ๊ฒฝ๋ก๋ฅผ ํตํด ๋๊ตฐ๊ฐ ์์์ ์ฌ์ฉ์ ์ด๋ฆ์ผ๋ก ์ฌ์นญํ ์ ์์ต๋๋ค. ์ด ๊ฒฝ์ฐ ์ ์์ ์ธ ์ฌ์ฉ์๊ฐ ๊ถํ ํ์ธ ๊ธฐ๋ฅ์ ์ ๊ทผํ์ฌ ์ ๋ ฅ ๋ด์ฉ์ ๊ธฐ๋ฐ์ผ๋ก Unix ์ ธ ๋ช ๋ น์ด๋ฅผ ์์ฑํ๊ณ ์คํํ ์ ์์ต๋๋ค. ์ด๋ ๊ฒ ๋๋ฉด ํ์ฌ ์ฌ์ฉ์๊ฐ Spark๋ฅผ ์คํํ ๊ฒ์ฒ๋ผ ์์์ ์ ธ ๋ช ๋ น์ด ์คํ๋ฉ๋๋ค
Detection
2022๋ 7์ 19์ผ ์ค์ 10:06
Opt-in Protection
2022๋ 7์ 19์ผ ์คํ 7:25
Global Protection
2022๋ 7์ 20์ผ ์คํ 5:23
Name
CVE
Severity Score
Detect to Protect
Description
Microsoft Windows ์ง์ ์ง๋จ ๋๊ตฌ(MSDT) ์๊ฒฉ ์ฝ๋ ์คํ ์ทจ์ฝ์
Detection
2022๋ 5์ 31์ผ ์ค์ 8:43
Opt-in Protection
2022๋ 5์ 31์ผ ์คํ 10:06
Global Protection
2022๋ 6์ 1์ผ ์คํ 5:00
Name
CVE
Severity Score
Detect to Protect
Description
Spring Cloud Function ๋ฒ์ 3.1.6, 3.2.2 ๋ฐ ์ด์ ๋ฏธ์ง์ ๋ฒ์ ์์๋ ๋ผ์ฐํ ๊ธฐ๋ฅ์ ์ฌ์ฉํ ๋ ์ฌ์ฉ์๊ฐ ํน์ํ๊ฒ ์ ์๋ SpEL๋ฅผ ๋ผ์ฐํ ํํ์์ผ๋ก ์ ๊ณตํ์ฌ ์๊ฒฉ ์ฝ๋๋ฅผ ์คํํ๊ณ ๋ก์ปฌ ๋ฆฌ์์ค์ ์ก์ธ์คํ ์ ์์ต๋๋ค.
Detection
2022๋ 3์ 30์ผ ์คํ 6:00
Opt-in Protection
2022๋ 3์ 30์ผ ์คํ 11:09
Global Protection
2022๋ 4์ 1์ผ ์คํ 7:54
Name
CVE
Severity Score
Detect to Protect
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled
Detection
Dec 10th, 2021 at 8:45 PM
Opt-in Protection
December 11, 2021 at 3:16 AM
Global Protection
December 11, 2021 at 1:47 PM
Name
CVE
Severity Score
Detect to Protect
Description
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution
Detection
Oct 6th, 2021 at 7:19 AM
Opt-in Protection
October 7, 2021 at 2:01 PM
Global Protection
October 8, 2021 at 12:05 AM
Name
CVE
Severity Score
Detect to Protect
Name
CVE
Severity Score
Detect to Protect
Description
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file
Detection
Sep 23rd, 2021 at 8:36 AM
Opt-in Protection
September 23, 2021 at 6:23 PM
Global Protection
September 26, 2021 at 6:37 PM
Name
CVE
Severity Score
Detect to Protect
Description
Windows Print Spooler Elevation of Privilege Vulnerability
Detection
Jul 5th, 2021 at 12:16 PM
Opt-in Protection
July 11, 2021 at 10:52 AM
Global Protection
July 11, 2021 at 6:44 PM
Name
CVE
Severity Score
Detect to Protect
Description
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server
Detection
May 31, 2021 at 10:55 AM
Opt-in Protection
June 1, 2021 at 9:47 PM
Global Protection
June 3, 2021 at 10:24 PM
Name
CVE
Severity Score
Detect to Protect
Description
On specific versions of BIG-IP and BIG-IQ , the iControl REST interface has an unauthenticated remote command execution vulnerability
Detection
Mar 20th, 2021 at 11:43ย PM
Opt-in Protection
Mar 23rd, 2021 at 12:12ย PM
Global Protection
March 23, 2021 at 7:21 PM
Name
CVE
Severity Score
Detect to Protect
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Detection
March 3, 2021 at 11:03 AM
Opt-in Protection
March 4, 2021 at 10:48 PM
Global Protection
March 7, 2021 at 1:26 PM
Name
CVE
Severity Score
Detect to Protect
Description
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
Detection
February 25, 2021 at 10:06 AM
Opt-in Protection
February 25, 2021 at 7:16 PM
Global Protection
February 26, 2021 at 12:03 PM
์๋ก์ด CVE๋ก๋ถํฐ ๋คํธ์ํฌ๋ฅผ ๋ณดํธํ๋๋ฐ ์์๋๋ ํ๋ก์ธ์ค, ๋ฆฌ์์ค, ์๊ฐ์ผ๋ก ๋ง์ ๊ณ ๊ฐ์ฌ๊ฐ ์ด๋ ค์์ ๊ฒช์ต๋๋ค. ์ด์ ๋ ๋ค์๊ณผ ๊ฐ์ต๋๋ค.
๊ณต๊ธ์ ์ฒด๋ CVE๋ฅผ ์ฐ๊ตฌํ๊ณ ์๊ทธ๋์ฒ๋ฅผ ๊ฐ๋ฐํด์ผ ํฉ๋๋ค.
๊ณ ๊ฐ์ฌ๋ ์ ์ง ๊ด๋ฆฌ ๊ธฐ๊ฐ ์ด๋ด์ ์๊ทธ๋์ฒ๋ฅผ ํ ์คํธํด์ผ ํฉ๋๋ค.
๊ณ ๊ฐ ํ ์คํธ ์ ์๊ทธ๋์ฒ๊ฐ ํธ๋ํฝ์ ์ค๋จ์ํค๊ฑฐ๋ ๊ฒ์ฌ ์ฑ๋ฅ ๋๋ ์ฌ์ฉ์ ๊ฒฝํ์ ์ํฅ์ ๋ฏธ์น์ง ์๋์ง ํ์ธํด์ผ ํฉ๋๋ค.
ํ ์คํธ๋ฅผ ํต๊ณผํ ๊ฒฝ์ฐ์๋ง ์๊ทธ๋์ฒ๋ฅผ ํ์ฑํํ ์ ์์ต๋๋ค.
์ด ๋ฆฌ์์ค ์ง์ฝ์ ์ธ ํ๋ก์ธ์ค๋ก ์ธํด ๋ง์ ๊ณ ๊ฐ๋๋ค์ด ์นจ์ ๋ฐฉ์ง ์์คํ (IPS)์ ํ์ง ๋ชจ๋๋ก ์ ํํ๊ฑฐ๋ ์ต์ ์ ๋ณด์ ์ํ๋ฅผ ์ ์งํ๋ ๋ฐ ๋ค์ฒ์ง๊ฒ ๋ฉ๋๋ค. ๊ณต๊ฒฉ์๊ฐ ์ค๋๋ ์ทจ์ฝ์ ์ ํฌํจํ์ฌ ํจ์น๋์ง ์์ CVE๋ฅผ ์ ์ฉํ๋ ค๊ณ ์๋ํ๊ธฐ ๋๋ฌธ์ ์นจํด ์ํ์ด ์ปค์ง๋๋ค.
Cato ๋ณด์ํ์ด ์ํํ๋ ๊ฐ์ ํจ์น ํ๋ก์ธ์ค๋ ๋ค์ 4๋จ๊ณ๋ก ๊ตฌ์ฑ๋์ด ์์ต๋๋ค.
ํ๊ฐ
CVE์ ๋ฒ์๋ฅผ ํ๊ฐํ๊ณ ์ทจ์ฝ์ ์ ์กฐ์ฌํฉ๋๋ค. ํนํ, ์ค์ ๋ก ์ด CVE๋ฅผ ์ฌ์ฉํ ๊ณต๊ฒฉ์ด ๋ฐ์ํ ๊ฒฝ์ฐ๋ฅผ ํ๊ฐํฉ๋๋ค.
์ด๋ ์์คํ ์ด ์ํฅ์ ๋ฐ๋์ง์ ๊ณต๊ฒฉ์๊ฐ ์ด๋ป๊ฒ ๊ณต๊ฒฉ์ ํ๋์ง ํ์ ํฉ๋๋ค.
๊ฐ๋ฐ
์๋ก์ด IPS ๊ท์น์ ์์ฑํ์ฌ ์ทจ์ฝ์ ์ ๊ฐ์ ํจ์นํฉ๋๋ค.
ํธ๋ํฝ ๋ฉํ ๋ฐ์ดํ์ ๋ํ ๋ฐฑ ํ ์คํธ๋ฅผ ๊ธฐ๋ฐ์ผ๋ก ์คํ์ง๋ฅผ ์ ๊ฑฐํฉ๋๋ค.
์ตํธ์ธ ๋ณดํธ
โ์๋ฎฌ๋ ์ด์ ๋ชจ๋โ์์ ๊ฐ์ ํจ์น๋ฅผ ์ ํ์ ์ผ๋ก ๋ฐฐํฌํฉ๋๋ค.
ํน์ ๊ณ ๊ฐ์ ๋ํ ์ตํธ์ธ ๋ฐฉ์ง๋ฅผ ํ์ฑํํฉ๋๋ค.
๊ธ๋ก๋ฒ ๋ณดํธ
๊ฐ์ ํจ์น๋ฅผ ์๋ฐฉ ๋ชจ๋๋ก ์ ํํฉ๋๋ค.
๋ชจ๋ ๊ณ ๊ฐ๊ณผ ๋ชจ๋ ํธ๋ํฝ์ ๊ฐ์ ํจ์น๋ฅผ ์ ์ฉํฉ๋๋ค.
์ด ํ๋ก์ธ์ค๋ ๊ณ ๊ฐ์ฌ์ ๋ฆฌ์์ค๊ฐ ํ์ํ์ง ์์ผ๋ฉฐ ๊ณ ๊ฐ์ฌ์ ๋น์ฆ๋์ค ์ด์์ ์ง์ฅ ์์ด ์งํ๋ฉ๋๋ค.