Cato åŽ‰å…¨į ”įŠļæäž›įš„åŋĢ速 CVE įˇŠč§Ŗ

OWASP åŽšįžŠč™›æ“Ŧ誜䏁į‚ēã€Œä¸€åą¤åŽ‰å…¨æ”ŋį­–åŸˇčĄŒæŠŸåˆļīŧŒčƒŊ防æ­ĸ厞įŸĨæŧæ´žé­åˆ°åˆŠį”¨ã€‚」Cato 透過 Cato å–Žä¸€é€šé“é›˛åŧ•擎īŧˆSPACEīŧ‰ä¸­įš„å…Ĩäžĩ防įĻĻįŗģįĩąåą¤é€˛čĄŒč™›æ“ŦčŖœä¸č™•į†ã€‚Cato įš„å°ˆåŽļ會部įŊ˛æ–°įš„ IPS čĻå‰‡īŧŒåžžč€ŒåŋĢé€ŸéŠæ‡‰æ–°įš„ CVEīŧŒč€Œį„Ąéœ€åŽĸæˆļįš„åƒčˆ‡ã€‚

Cato åˇ˛æˆåŠŸįˇŠč§Ŗįš„į‰šåŽšé—œéĩ CVE

Name

æœĒįļ“čĒč­‰įš„é įĢ¯æŒ‡ä줿ŗ¨å…Ĩæŧæ´ž

CVE

CVE-2024-9474

Severity Score

7.2 (High)

Detect to Protect

0 夊

Description

CVE-2024-9474 是 PAN-OS čŖįŊŽįŽĄį†įļ˛é äģ‹éĸä¸­įš„æŦŠé™æå‡æŧæ´žã€‚æœĒįļ“čēĢäģŊéŠ—č­‰įš„é į̝æ”ģæ“Šč€…īŧŒå¯äģĨ將 CVE-2024-0012 和 CVE-2024-9474 æŧæ´žä¸˛č¯čĩˇäž†īŧŒåžžč€Œåœ¨æ˜“受æ”ģæ“Šįš„ PAN-OS čŖįŊŽä¸Šį˛åž— root æŦŠé™ä¸ĻåŸˇčĄŒæŒ‡äģ¤ã€‚

Detection

2024 åš´ 11 月 18 æ—Ĩ

Opt-in Protection

0 * į”ąæ–ŧé€šį”¨į°Ŋ名

Global Protection

0 * į”ąæ–ŧé€šį”¨į°Ŋ名

Name

SolarWinds SERV-U į›ŽéŒ„éæ­ˇ

CVE

CVE-2024-28995

Severity Score

10 (Critical)

Detect to Protect

0 * į”ąæ–ŧé€šį”¨į°Ŋ名

Description

SolarWinds SERV-U į›ŽéŒ„éæ­ˇå…č¨ąå­˜å–ä¸ĻčŽ€å–ä¸ģæŠŸä¸Šįš„æ•æ„ŸæĒ”æĄˆã€‚

Detection

2024 åš´ 6 月 7 æ—Ĩ 下午 11:00

Opt-in Protection

0 * į”ąæ–ŧé€šį”¨į°Ŋ名

Global Protection

0 * į”ąæ–ŧé€šį”¨į°Ŋ名

Name

ConnectWise ScreenConnect čĒč­‰įšžéŽ

CVE

CVE-2024-1709

Severity Score

10 (Critical)

Detect to Protect

4 夊

Description

ConnectWise ScreenConnect 23.9.7 åŠäš‹å‰įš„į‰ˆæœŦ存在一個čĒč­‰įšžéŽæŧæ´žīŧŒæ”ģæ“Šč€…可äģĨ透過æ›ŋäģŖčˇ¯åž‘æˆ–é€šé“įšžéŽčĒč­‰īŧŒé€˛č€Œį›´æŽĨå­˜å–æŠŸå¯†čŗ‡č¨Šæˆ–é—œéĩįŗģįĩąã€‚

Detection

2024 åš´ 2 月 21 æ—Ĩ

Opt-in Protection

2024 åš´ 2 月 23 æ—Ĩ 上午 10:45 UTC

Global Protection

2024 åš´ 2 月 25 æ—Ĩ 上午 9:00 UTC

Name

Jenkins äģģæ„æĒ”æĄˆčŽ€å–

CVE

CVE-2024-23897

Severity Score

9.8 (Critical)

Detect to Protect

2 夊

Description

Jenkins 2.441 åŠäš‹å‰į‰ˆæœŦīŧŒäģĨ及 LTS 2.426.2 åŠäš‹å‰į‰ˆæœŦīŧŒæœĒįρᔍå…ļ CLI å‘Ŋäģ¤č§Ŗæžå™¨ä¸­įš„一個功čƒŊīŧŒčО功čƒŊæœƒå°‡åƒæ•¸ä¸­įš„ '@' 字įŦĻ及å…ļåžŒįš„æĒ”æĄˆčˇ¯åž‘æ›ŋ換į‚ēæĒ”æĄˆįš„å…§åŽšīŧŒäŊŋæœĒįļ“čĒč­‰įš„æ”ģæ“Šč€…čƒŊå¤ čŽ€å– Jenkins äŧ翜å™¨æĒ”æĄˆįŗģįĩąä¸­įš„äģģæ„æĒ”æĄˆã€‚

Detection

2024 åš´ 1 月 27 æ—Ĩ

Opt-in Protection

2024 åš´ 1 月 28 æ—Ĩ 下午 9:50

Global Protection

2024 åš´ 1 月 29 æ—Ĩ 下午 5:30

Name

Atlassian Confluence Data Center 與äŧ翜å™¨é į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2023-22527

Severity Score

10 (Critical)

Detect to Protect

1 夊

Description

Atlassian Confluence äŧ翜å™¨čˆ‡čŗ‡æ–™ä¸­åŋƒå­˜åœ¨ä¸€å€‹é į̝ፋåŧįĸŧåŸˇčĄŒæŧæ´žīŧŒæœĒįļ“čēĢäģŊéŠ—č­‰įš„æ”ģæ“Šč€…å¯é€éŽæ¨Ąæŋæŗ¨å…Ĩį˛åž—é į̝ፋåŧįĸŧåŸˇčĄŒįš„æŦŠé™ã€‚

Detection

2024 åš´ 1 月 22 æ—Ĩ

Opt-in Protection

2024 åš´ 1 月 22 æ—Ĩ 下午 7:00 UTC

Global Protection

2024 åš´ 1 月 23 æ—Ĩ 下午 11:00 UTC

Name

Apache Struts 2 æĒ”æĄˆä¸Šå‚ŗé į̝ፋåŧįĸŧåŸˇčĄŒæŧæ´ž

CVE

CVE-2023-50164

Severity Score

9.8 (Critical)

Detect to Protect

1 夊

Description

透過 Apache Struts 2 įļ˛é æĄ†æžļä¸­įš„æĒ”æĄˆä¸Šå‚ŗé‚čŧ¯æŧæ´žīŧŒæ”ģæ“Šč€…å¯é€˛čĄŒäģģæ„æĒ”æĄˆä¸Šå‚ŗä¸ĻåŸˇčĄŒį¨‹åŧįĸŧ

Detection

POC å¯į”¨ – 2023 åš´ 12 月 12 æ—Ĩ

Opt-in Protection

2023 åš´ 12 月 12 æ—Ĩ

Global Protection

2023 åš´ 12 月 13 æ—Ĩ

Name

æ€į§‘ IOS XE įļ˛é äģ‹éĸæŦŠé™æå‡æŧæ´ž

CVE

CVE-2023-20198

Severity Score

10 (Critical)

Detect to Protect

2 夊

Description

針對įļ˛éš›įļ˛čˇ¯įš„æ€į§‘荭備䏭īŧŒč‹Ĩ運行 IOS XE ä¸”å•Ÿį”¨äē† HTTP įļ˛é äģ‹éĸ功čƒŊīŧŒå‰‡å¯čƒŊį™ŧį”ŸæŦŠé™æå‡æŧæ´ž

Detection

POC å¯į”¨ – 2023 åš´ 10 月 30 æ—Ĩ 20:30 UTC

Opt-in Protection

2023 åš´ 10 月 31 æ—Ĩ 20:00 UTC

Global Protection

2023 åš´ 11 月 1 æ—Ĩ 20:00 UTC

Name

cURL SOCKS5 äģŖį†å †į–ŠįˇŠčĄå€æēĸäŊ

CVE

CVE-2023-38545

Severity Score

7.5 (High)

Detect to Protect

1 夊 3 小時

Description

在 SOCKS5 äģŖį†äŧ翜å™¨é€Ŗįˇšå”å•†éŽį¨‹ä¸­īŧŒä¸ģæŠŸåį¨ąč§Ŗæžįš„å †į–ŠįˇŠčĄå€æēĸäŊæŧæ´žå¯čƒŊå°Žč‡´åœ¨æ˜“å—æ”ģæ“Šįš„ libcurl å¯ĻäŊœä¸­åŸˇčĄŒæƒĄæ„į¨‹åŧįĸŧ

Detection

2023 åš´ 10 月 11 æ—Ĩ 6:30 UTC

Opt-in Protection

2023 åš´ 10 月 11 æ—Ĩ 20:00 UTC

Global Protection

2023 åš´ 10 月 12 æ—Ĩ 9:30 UTC

Name

Atlassian Confluence Data Center 與 Server æŦŠé™æå‡æŧæ´ž

CVE

CVE-2023-22515

Severity Score

10 (Critical)

Detect to Protect

1 夊 23 小時

Description

Atlassian Confluence Server 與 Data Center æœŦåœ°į‰ˆæœŦįš„æŦŠé™æå‡æŧæ´žīŧŒæ”ģæ“Šč€…可äģĨåˆŠį”¨æ˜“å—æ”ģæ“Šįš„įĩ‚įĢ¯čŖįŊŽīŧŒå‰ĩåģ翜ĒįŽˆæŦŠįš„įŽĄį†å“Ąå¸ŗæˆļä¸Ļį˛å–äŧ翜å™¨å­˜å–æŦŠé™

Detection

2023 åš´ 10 月 4 æ—Ĩ 13:00 UTC

Opt-in Protection

2023 åš´ 10 月 5 æ—Ĩ 11:00 UTC

Global Protection

2023 åš´ 10 月 6 æ—Ĩ 12:00 UTC

Name

MOVEit Transfer SQL

CVE

CVE-2023-34362

Severity Score

10 (Critical)

Detect to Protect

3 夊 6 小時

Description

InProgress įš„įŽĄį†æĒ”æĄˆå‚ŗčŧ¸ (MFT) č§Ŗæąēæ–šæĄˆ MOVEit Transfer 存在 SQL æŗ¨å…Ĩæŧæ´žīŧŒæ”ģæ“Šč€…å¯åŸˇčĄŒ SQL å‘Ŋäģ¤īŧŒä¸Ļ可čƒŊå°Žč‡´åŽ‰čŖå°ˆį”¨åžŒé–€īŧŒé€˛č€Œå¯Ļįžé į̝ፋåŧįĸŧåŸˇčĄŒã€‚

Detection

2023 åš´ 6 月 6 æ—Ĩ 上午 8:00

Opt-in Protection

2023 åš´ 6 月 8 æ—Ĩ 下午 4:30

Global Protection

2023 åš´ 6 月 9 æ—Ĩ 下午 2:00

Name

Microsoft Outlook 遠įĢ¯å“ˆå¸Œæŧæ´ž

CVE

CVE-2023-23397

Severity Score

9.8 (Critical)

Detect to Protect

0*

Description

Microsoft Outlook 提升æŦŠé™æŧæ´ž * 在é›ļ時éģžīŧšCato įš„é˜˛įĢį‰†é č¨­æœƒå°éŽ–å¤–éƒ¨įš„ SMB æĩé‡

Detection

2023 åš´ 3 月 3 æ—Ĩ 上午 8:02

Opt-in Protection

2023 åš´ 3 月 3 æ—Ĩ 上午 8:02

Global Protection

2023 åš´ 3 月 3 æ—Ĩ 上午 8:02

Name

OWASSRFīŧŒMS Exchange RCE

CVE

CVE-2022-41082

Severity Score

8.8 (High)

Detect to Protect

23 小時 45 分鐘

Description

äŊœį‚ē ProxyNotShell æ”ģæ“Šéˆįš„一部分īŧŒæŸäē›į‰ˆæœŦįš„ MS Exchange 存在 RCEīŧˆé į̝ፋåŧįĸŧåŸˇčĄŒīŧ‰

Detection

2022 åš´ 12 月 21 æ—Ĩ 下午 5:00

Opt-in Protection

2022 åš´ 12 月 21 æ—Ĩ 下午 11:29

Global Protection

2022 åš´ 12 月 22 æ—Ĩ 下午 4:45

Name

Microsoft Exchange 遠į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2022-41040, CVE-2022-41082

Severity Score

8.8 (High)

Detect to Protect

2夊 10小時 6分鐘

Description

Microsoft Outlook 提升æŦŠé™æŧæ´ž

Detection

2022 åš´ 9 月 30 æ—Ĩ 下午 1:19

Opt-in Protection

2022 åš´ 9 月 30 æ—Ĩ 下午 11:25

Global Protection

2022 åš´ 10 月 2 æ—Ĩ 下午 12:40

Name

DogWalk – 垎čģŸ Windows 支援č¨ēæ–ˇåˇĨ兎遠į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2022-34713

Severity Score

7.8 (High)

Detect to Protect

2夊 4小時 54分鐘

Description

垎čģŸ Windows 支援č¨ēæ–ˇåˇĨå…ˇ (MSDT) 遠į̝ፋåŧįĸŧåŸˇčĄŒæŧæ´ž

Detection

2022 åš´ 8 月 10 æ—Ĩ 上午 11:22

Opt-in Protection

2022 åš´ 8 月 11 æ—Ĩ 下午 6:38

Global Protection

2022 åš´ 8 月 12 æ—Ĩ 下午 4:16

Name

Apache Spark 遠į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2022-33891

Severity Score

8.8 (High)

Detect to Protect

1夊 7小時 17分鐘

Description

Apache Spark äŊŋᔍ者äģ‹éĸ提䞛äē†é€éŽč¨­åŽšé¸é … spark.acls.enable å•Ÿį”¨ ACLs įš„åŠŸčƒŊã€‚é€éŽéŠ—č­‰į¯Šé¸å™¨īŧŒįŗģįĩ࿜ƒæĒĸæŸĨᔍæˆļ是åĻ兎備æŸĨįœ‹æˆ–äŋŽæ”𿇉ᔍፋåŧįš„存取æŦŠé™ã€‚åĻ‚æžœå•Ÿį”¨äē† ACLs 則 HttpSecurityFilter ä¸­įš„æŸäē›į¨‹åŧįĸŧčˇ¯åž‘å¯čƒŊæœƒčŽ“æ”ģæ“Šč€…透過提䞛äģģæ„įš„äŊŋį”¨č€…åį¨ąé€˛čĄŒå†’å……ã€‚æƒĄæ„į”¨æˆļ可čƒŊæœƒåˆŠį”¨æ­¤æŧæ´žīŧŒé€˛č€Œč§¸į™ŧ一個æŦŠé™æĒĸæŸĨ功čƒŊīŧŒčО功čƒŊ最įĩ‚æœƒæ šæ“šį”¨æˆļįš„čŧ¸å…Ĩåģēį̋䏀æĸ Unix Shell 指äģ¤ä¸ĻåŸˇčĄŒã€‚é€™å°‡å°Žč‡´äģĨį›Žå‰ Spark åŸˇčĄŒäŊŋį”¨č€…įš„čēĢäģŊåŸˇčĄŒäģģæ„įš„ Shell 指äģ¤

Detection

2022 åš´ 7 月 19 æ—Ĩ 上午 10:06

Opt-in Protection

2022 åš´ 7 月 19 æ—Ĩ 下午 7:25

Global Protection

2022 åš´ 7 月 20 æ—Ĩ 下午 5:23

Name

垎č쟿”¯æ´č¨ēæ–ˇåˇĨ兎遠į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2022-30190

Severity Score

7.8 (High)

Detect to Protect

1夊 īŧ˜å°æ™‚ 17分鐘

Description

垎čģŸ Windows 支援č¨ēæ–ˇåˇĨå…ˇ (MSDT) 遠į̝ፋåŧįĸŧåŸˇčĄŒæŧæ´žã€‚

Detection

2022 åš´ 5 月 31 æ—Ĩ 上午 8:43

Opt-in Protection

2022 åš´ 5 月 31 æ—Ĩ 下午 10:06

Global Protection

2022 åš´ 6 月 1 æ—Ĩ 下午 5:00

Name

VMware Tanzu Spring Cloud Function 遠į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2022-22963

Severity Score

9.8 (Critical)

Detect to Protect

2夊 1小時 54分鐘

Description

在 Spring Cloud Function į‰ˆæœŦ 3.1.6、3.2.2 及čŧƒčˆŠįš„æœĒæ”¯æ´į‰ˆæœŦ中īŧŒį•ļäŊŋį”¨čˇ¯į”ąåŠŸčƒŊ時īŧŒæ”ģæ“Šč€…可äģĨæäž›į‰ščŖŊįš„ SpEL äŊœį‚ēčˇ¯į”ąčĄ¨é”åŧīŧŒé€™å¯čƒŊå°Žč‡´é į̝ፋåŧįĸŧåŸˇčĄŒä¸Ļ存取æœŦåœ°čŗ‡æē

Detection

2022 åš´ 3 月 30 æ—Ĩ 下午 6:00

Opt-in Protection

2022 åš´ 3 月 30 æ—Ĩ 下午 11:09

Global Protection

2022 åš´ 4 月 1 æ—Ĩ 下午 7:54

Name

Log4shell

CVE

CVE-2021-44228

Severity Score

10.0 (Critical)

Detect to Protect

17 hours, 2 minutes

Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled

Detection

Dec 10th, 2021 at 8:45 PM

Opt-in Protection

December 11, 2021 at 3:16 AM

Global Protection

December 11, 2021 at 1:47 PM

Name

Apache HTTP Server Path Traversal

CVE

CVE-2021-41773

Severity Score

7.5 (High)

Detect to Protect

1 day, 16 hours, 46 minutes

Description

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution

Detection

Oct 6th, 2021 at 7:19 AM

Opt-in Protection

October 7, 2021 at 2:01 PM

Global Protection

October 8, 2021 at 12:05 AM

Name

Exchange Autodiscover Password

CVE

Severity Score

(Critical)

Detect to Protect

5 days, 5 hours, 30 minutes

Description

Detection

Sep 30th, 2021 at 2:33 PM

Opt-in Protection

September 30, 2021 at 5:40 PM

Global Protection

October 5, 2021 at 8:03 PM

Name

VMware vCenter RCE (II)

CVE

CVE-2021-22005

Severity Score

9.8 (Critical)

Detect to Protect

3 days, 10 hours, 1 minute

Description

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file

Detection

Sep 23rd, 2021 at 8:36 AM

Opt-in Protection

September 23, 2021 at 6:23 PM

Global Protection

September 26, 2021 at 6:37 PM

Name

PrintNightmare Spooler RCE Vulnerability

CVE

CVE-2021-1675

Severity Score

8.8 (High)

Detect to Protect

6 days, 6 hours, 28 minutes

Description

Windows Print Spooler Elevation of Privilege Vulnerability

Detection

Jul 5th, 2021 at 12:16 PM

Opt-in Protection

July 11, 2021 at 10:52 AM

Global Protection

July 11, 2021 at 6:44 PM

Name

Sphere Client (HTML5) Remote Code Execution

CVE

CVE-2021-21985

Severity Score

9.8 (Critical)

Detect to Protect

3 days, 11 hours, 29 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server

Detection

May 31, 2021 at 10:55 AM

Opt-in Protection

June 1, 2021 at 9:47 PM

Global Protection

June 3, 2021 at 10:24 PM

Name

F5 Vulnerability

CVE

CVE-2021-22986

Severity Score

9.8 (Critical)

Detect to Protect

2 days, 19 hours, 38 minutes

Description

On specific versions of BIG-IP and BIG-IQ , the iControl REST interface has an unauthenticated remote command execution vulnerability

Detection

Mar 20th, 2021 at 11:43 PM

Opt-in Protection

Mar 23rd, 2021 at 12:12 PM

Global Protection

March 23, 2021 at 7:21 PM

Name

MS Exchange SSRF

CVE

CVE-2021-26855

Severity Score

9.8 (Critical)

Detect to Protect

4 days, 2 hours, 23 minutes

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Detection

March 3, 2021 at 11:03 AM

Opt-in Protection

March 4, 2021 at 10:48 PM

Global Protection

March 7, 2021 at 1:26 PM

Name

VMWare VCenter RCE

CVE

CVE-2021-21972

Severity Score

9.8 (Critical)

Detect to Protect

1 day, 1 hour, 57 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

Detection

February 25, 2021 at 10:06 AM

Opt-in Protection

February 25, 2021 at 7:16 PM

Global Protection

February 26, 2021 at 12:03 PM

Name

æœĒįļ“čĒč­‰įš„é įĢ¯æŒ‡ä줿ŗ¨å…Ĩæŧæ´ž

CVE

CVE-2024-9474

Severity Score

7.2

Detect to Protect

0 夊

Description

CVE-2024-9474 是 PAN-OS čŖįŊŽįŽĄį†įļ˛é äģ‹éĸä¸­įš„æŦŠé™æå‡æŧæ´žã€‚æœĒįļ“čēĢäģŊéŠ—č­‰įš„é į̝æ”ģæ“Šč€…īŧŒå¯äģĨ將 CVE-2024-0012 和 CVE-2024-9474 æŧæ´žä¸˛č¯čĩˇäž†īŧŒåžžč€Œåœ¨æ˜“受æ”ģæ“Šįš„ PAN-OS čŖįŊŽä¸Šį˛åž— root æŦŠé™ä¸ĻåŸˇčĄŒæŒ‡äģ¤ã€‚

Detection

2024 åš´ 11 月 18 æ—Ĩ

Opt-in Protection

0 * į”ąæ–ŧé€šį”¨į°Ŋ名

Global Protection

0 * į”ąæ–ŧé€šį”¨į°Ŋ名

Name

SolarWinds SERV-U į›ŽéŒ„éæ­ˇ

CVE

CVE-2024-28995

Severity Score

10

Detect to Protect

0 * į”ąæ–ŧé€šį”¨į°Ŋ名

Description

SolarWinds SERV-U į›ŽéŒ„éæ­ˇå…č¨ąå­˜å–ä¸ĻčŽ€å–ä¸ģæŠŸä¸Šįš„æ•æ„ŸæĒ”æĄˆã€‚

Detection

2024 åš´ 6 月 7 æ—Ĩ 下午 11:00

Opt-in Protection

0 * į”ąæ–ŧé€šį”¨į°Ŋ名

Global Protection

0 * į”ąæ–ŧé€šį”¨į°Ŋ名

Name

ConnectWise ScreenConnect čĒč­‰įšžéŽ

CVE

CVE-2024-1709

Severity Score

10

Detect to Protect

4 夊

Description

ConnectWise ScreenConnect 23.9.7 åŠäš‹å‰įš„į‰ˆæœŦ存在一個čĒč­‰įšžéŽæŧæ´žīŧŒæ”ģæ“Šč€…可äģĨ透過æ›ŋäģŖčˇ¯åž‘æˆ–é€šé“įšžéŽčĒč­‰īŧŒé€˛č€Œį›´æŽĨå­˜å–æŠŸå¯†čŗ‡č¨Šæˆ–é—œéĩįŗģįĩąã€‚

Detection

2024 åš´ 2 月 21 æ—Ĩ

Opt-in Protection

2024 åš´ 2 月 23 æ—Ĩ 上午 10:45 UTC

Global Protection

2024 åš´ 2 月 25 æ—Ĩ 上午 9:00 UTC

Name

Jenkins äģģæ„æĒ”æĄˆčŽ€å–

CVE

CVE-2024-23897

Severity Score

9.8

Detect to Protect

2 夊

Description

Jenkins 2.441 åŠäš‹å‰į‰ˆæœŦīŧŒäģĨ及 LTS 2.426.2 åŠäš‹å‰į‰ˆæœŦīŧŒæœĒįρᔍå…ļ CLI å‘Ŋäģ¤č§Ŗæžå™¨ä¸­įš„一個功čƒŊīŧŒčО功čƒŊæœƒå°‡åƒæ•¸ä¸­įš„ '@' 字įŦĻ及å…ļåžŒįš„æĒ”æĄˆčˇ¯åž‘æ›ŋ換į‚ēæĒ”æĄˆįš„å…§åŽšīŧŒäŊŋæœĒįļ“čĒč­‰įš„æ”ģæ“Šč€…čƒŊå¤ čŽ€å– Jenkins äŧ翜å™¨æĒ”æĄˆįŗģįĩąä¸­įš„äģģæ„æĒ”æĄˆã€‚

Detection

2024 åš´ 1 月 27 æ—Ĩ

Opt-in Protection

2024 åš´ 1 月 28 æ—Ĩ 下午 9:50

Global Protection

2024 åš´ 1 月 29 æ—Ĩ 下午 5:30

Name

Atlassian Confluence Data Center 與äŧ翜å™¨é į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2023-22527

Severity Score

10

Detect to Protect

1 夊

Description

Atlassian Confluence äŧ翜å™¨čˆ‡čŗ‡æ–™ä¸­åŋƒå­˜åœ¨ä¸€å€‹é į̝ፋåŧįĸŧåŸˇčĄŒæŧæ´žīŧŒæœĒįļ“čēĢäģŊéŠ—č­‰įš„æ”ģæ“Šč€…å¯é€éŽæ¨Ąæŋæŗ¨å…Ĩį˛åž—é į̝ፋåŧįĸŧåŸˇčĄŒįš„æŦŠé™ã€‚

Detection

2024 åš´ 1 月 22 æ—Ĩ

Opt-in Protection

2024 åš´ 1 月 22 æ—Ĩ 下午 7:00 UTC

Global Protection

2024 åš´ 1 月 23 æ—Ĩ 下午 11:00 UTC

Name

Apache Struts 2 æĒ”æĄˆä¸Šå‚ŗé į̝ፋåŧįĸŧåŸˇčĄŒæŧæ´ž

CVE

CVE-2023-50164

Severity Score

9.8

Detect to Protect

1 夊

Description

透過 Apache Struts 2 įļ˛é æĄ†æžļä¸­įš„æĒ”æĄˆä¸Šå‚ŗé‚čŧ¯æŧæ´žīŧŒæ”ģæ“Šč€…å¯é€˛čĄŒäģģæ„æĒ”æĄˆä¸Šå‚ŗä¸ĻåŸˇčĄŒį¨‹åŧįĸŧ

Detection

POC å¯į”¨ – 2023 åš´ 12 月 12 æ—Ĩ

Opt-in Protection

2023 åš´ 12 月 12 æ—Ĩ

Global Protection

2023 åš´ 12 月 13 æ—Ĩ

Name

æ€į§‘ IOS XE įļ˛é äģ‹éĸæŦŠé™æå‡æŧæ´ž

CVE

CVE-2023-20198

Severity Score

10

Detect to Protect

2 夊

Description

針對įļ˛éš›įļ˛čˇ¯įš„æ€į§‘荭備䏭īŧŒč‹Ĩ運行 IOS XE ä¸”å•Ÿį”¨äē† HTTP įļ˛é äģ‹éĸ功čƒŊīŧŒå‰‡å¯čƒŊį™ŧį”ŸæŦŠé™æå‡æŧæ´ž

Detection

POC å¯į”¨ – 2023 åš´ 10 月 30 æ—Ĩ 20:30 UTC

Opt-in Protection

2023 åš´ 10 月 31 æ—Ĩ 20:00 UTC

Global Protection

2023 åš´ 11 月 1 æ—Ĩ 20:00 UTC

Name

cURL SOCKS5 äģŖį†å †į–ŠįˇŠčĄå€æēĸäŊ

CVE

CVE-2023-38545

Severity Score

7.5

Detect to Protect

1 夊 3 小時

Description

在 SOCKS5 äģŖį†äŧ翜å™¨é€Ŗįˇšå”å•†éŽį¨‹ä¸­īŧŒä¸ģæŠŸåį¨ąč§Ŗæžįš„å †į–ŠįˇŠčĄå€æēĸäŊæŧæ´žå¯čƒŊå°Žč‡´åœ¨æ˜“å—æ”ģæ“Šįš„ libcurl å¯ĻäŊœä¸­åŸˇčĄŒæƒĄæ„į¨‹åŧįĸŧ

Detection

2023 åš´ 10 月 11 æ—Ĩ 6:30 UTC

Opt-in Protection

2023 åš´ 10 月 11 æ—Ĩ 20:00 UTC

Global Protection

2023 åš´ 10 月 12 æ—Ĩ 9:30 UTC

Name

Atlassian Confluence Data Center 與 Server æŦŠé™æå‡æŧæ´ž

CVE

CVE-2023-22515

Severity Score

10

Detect to Protect

1 夊 23 小時

Description

Atlassian Confluence Server 與 Data Center æœŦåœ°į‰ˆæœŦįš„æŦŠé™æå‡æŧæ´žīŧŒæ”ģæ“Šč€…可äģĨåˆŠį”¨æ˜“å—æ”ģæ“Šįš„įĩ‚įĢ¯čŖįŊŽīŧŒå‰ĩåģ翜ĒįŽˆæŦŠįš„įŽĄį†å“Ąå¸ŗæˆļä¸Ļį˛å–äŧ翜å™¨å­˜å–æŦŠé™

Detection

2023 åš´ 10 月 4 æ—Ĩ 13:00 UTC

Opt-in Protection

2023 åš´ 10 月 5 æ—Ĩ 11:00 UTC

Global Protection

2023 åš´ 10 月 6 æ—Ĩ 12:00 UTC

Name

MOVEit Transfer SQL

CVE

CVE-2023-34362

Severity Score

10

Detect to Protect

3 夊 6 小時

Description

InProgress įš„įŽĄį†æĒ”æĄˆå‚ŗčŧ¸ (MFT) č§Ŗæąēæ–šæĄˆ MOVEit Transfer 存在 SQL æŗ¨å…Ĩæŧæ´žīŧŒæ”ģæ“Šč€…å¯åŸˇčĄŒ SQL å‘Ŋäģ¤īŧŒä¸Ļ可čƒŊå°Žč‡´åŽ‰čŖå°ˆį”¨åžŒé–€īŧŒé€˛č€Œå¯Ļįžé į̝ፋåŧįĸŧåŸˇčĄŒã€‚

Detection

2023 åš´ 6 月 6 æ—Ĩ 上午 8:00

Opt-in Protection

2023 åš´ 6 月 8 æ—Ĩ 下午 4:30

Global Protection

2023 åš´ 6 月 9 æ—Ĩ 下午 2:00

Name

Microsoft Outlook 遠įĢ¯å“ˆå¸Œæŧæ´ž

CVE

CVE-2023-23397

Severity Score

9.8

Detect to Protect

0*

Description

Microsoft Outlook 提升æŦŠé™æŧæ´ž * 在é›ļ時éģžīŧšCato įš„é˜˛įĢį‰†é č¨­æœƒå°éŽ–å¤–éƒ¨įš„ SMB æĩé‡

Detection

2023 åš´ 3 月 3 æ—Ĩ 上午 8:02

Opt-in Protection

2023 åš´ 3 月 3 æ—Ĩ 上午 8:02

Global Protection

2023 åš´ 3 月 3 æ—Ĩ 上午 8:02

Name

OWASSRFīŧŒMS Exchange RCE

CVE

CVE-2022-41082

Severity Score

8.8

Detect to Protect

23 小時 45 分鐘

Description

äŊœį‚ē ProxyNotShell æ”ģæ“Šéˆįš„一部分īŧŒæŸäē›į‰ˆæœŦįš„ MS Exchange 存在 RCEīŧˆé į̝ፋåŧįĸŧåŸˇčĄŒīŧ‰

Detection

2022 åš´ 12 月 21 æ—Ĩ 下午 5:00

Opt-in Protection

2022 åš´ 12 月 21 æ—Ĩ 下午 11:29

Global Protection

2022 åš´ 12 月 22 æ—Ĩ 下午 4:45

Name

Microsoft Exchange 遠į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2022-41040, CVE-2022-41082

Severity Score

8.8

Detect to Protect

2夊 10小時 6分鐘

Description

Microsoft Outlook 提升æŦŠé™æŧæ´ž

Detection

2022 åš´ 9 月 30 æ—Ĩ 下午 1:19

Opt-in Protection

2022 åš´ 9 月 30 æ—Ĩ 下午 11:25

Global Protection

2022 åš´ 10 月 2 æ—Ĩ 下午 12:40

Name

DogWalk – 垎čģŸ Windows 支援č¨ēæ–ˇåˇĨ兎遠į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2022-34713

Severity Score

7.8

Detect to Protect

2夊 4小時 54分鐘

Description

垎čģŸ Windows 支援č¨ēæ–ˇåˇĨå…ˇ (MSDT) 遠į̝ፋåŧįĸŧåŸˇčĄŒæŧæ´ž

Detection

2022 åš´ 8 月 10 æ—Ĩ 上午 11:22

Opt-in Protection

2022 åš´ 8 月 11 æ—Ĩ 下午 6:38

Global Protection

2022 åš´ 8 月 12 æ—Ĩ 下午 4:16

Name

Apache Spark 遠į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2022-33891

Severity Score

8.8

Detect to Protect

1夊 7小時 17分鐘

Description

Apache Spark äŊŋᔍ者äģ‹éĸ提䞛äē†é€éŽč¨­åŽšé¸é … spark.acls.enable å•Ÿį”¨ ACLs įš„åŠŸčƒŊã€‚é€éŽéŠ—č­‰į¯Šé¸å™¨īŧŒįŗģįĩ࿜ƒæĒĸæŸĨᔍæˆļ是åĻ兎備æŸĨįœ‹æˆ–äŋŽæ”𿇉ᔍፋåŧįš„存取æŦŠé™ã€‚åĻ‚æžœå•Ÿį”¨äē† ACLs 則 HttpSecurityFilter ä¸­įš„æŸäē›į¨‹åŧįĸŧčˇ¯åž‘å¯čƒŊæœƒčŽ“æ”ģæ“Šč€…透過提䞛äģģæ„įš„äŊŋį”¨č€…åį¨ąé€˛čĄŒå†’å……ã€‚æƒĄæ„į”¨æˆļ可čƒŊæœƒåˆŠį”¨æ­¤æŧæ´žīŧŒé€˛č€Œč§¸į™ŧ一個æŦŠé™æĒĸæŸĨ功čƒŊīŧŒčО功čƒŊ最įĩ‚æœƒæ šæ“šį”¨æˆļįš„čŧ¸å…Ĩåģēį̋䏀æĸ Unix Shell 指äģ¤ä¸ĻåŸˇčĄŒã€‚é€™å°‡å°Žč‡´äģĨį›Žå‰ Spark åŸˇčĄŒäŊŋį”¨č€…įš„čēĢäģŊåŸˇčĄŒäģģæ„įš„ Shell 指äģ¤

Detection

2022 åš´ 7 月 19 æ—Ĩ 上午 10:06

Opt-in Protection

2022 åš´ 7 月 19 æ—Ĩ 下午 7:25

Global Protection

2022 åš´ 7 月 20 æ—Ĩ 下午 5:23

Name

垎č쟿”¯æ´č¨ēæ–ˇåˇĨ兎遠į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2022-30190

Severity Score

7.8

Detect to Protect

1夊 īŧ˜å°æ™‚ 17分鐘

Description

垎čģŸ Windows 支援č¨ēæ–ˇåˇĨå…ˇ (MSDT) 遠į̝ፋåŧįĸŧåŸˇčĄŒæŧæ´žã€‚

Detection

2022 åš´ 5 月 31 æ—Ĩ 上午 8:43

Opt-in Protection

2022 åš´ 5 月 31 æ—Ĩ 下午 10:06

Global Protection

2022 åš´ 6 月 1 æ—Ĩ 下午 5:00

Name

VMware Tanzu Spring Cloud Function 遠į̝ፋåŧįĸŧåŸˇčĄŒ

CVE

CVE-2022-22963

Severity Score

9.8

Detect to Protect

2夊 1小時 54分鐘

Description

在 Spring Cloud Function į‰ˆæœŦ 3.1.6、3.2.2 及čŧƒčˆŠįš„æœĒæ”¯æ´į‰ˆæœŦ中īŧŒį•ļäŊŋį”¨čˇ¯į”ąåŠŸčƒŊ時īŧŒæ”ģæ“Šč€…可äģĨæäž›į‰ščŖŊįš„ SpEL äŊœį‚ēčˇ¯į”ąčĄ¨é”åŧīŧŒé€™å¯čƒŊå°Žč‡´é į̝ፋåŧįĸŧåŸˇčĄŒä¸Ļ存取æœŦåœ°čŗ‡æē

Detection

2022 åš´ 3 月 30 æ—Ĩ 下午 6:00

Opt-in Protection

2022 åš´ 3 月 30 æ—Ĩ 下午 11:09

Global Protection

2022 åš´ 4 月 1 æ—Ĩ 下午 7:54

Name

Log4shell

CVE

CVE-2021-44228

Severity Score

10.0

Detect to Protect

17 hours, 2 minutes

Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled

Detection

Dec 10th, 2021 at 8:45 PM

Opt-in Protection

December 11, 2021 at 3:16 AM

Global Protection

December 11, 2021 at 1:47 PM

Name

Apache HTTP Server Path Traversal

CVE

CVE-2021-41773

Severity Score

7.5

Detect to Protect

1 day, 16 hours, 46 minutes

Description

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution

Detection

Oct 6th, 2021 at 7:19 AM

Opt-in Protection

October 7, 2021 at 2:01 PM

Global Protection

October 8, 2021 at 12:05 AM

Name

Exchange Autodiscover Password

CVE

Severity Score

Detect to Protect

5 days, 5 hours, 30 minutes

Description

Detection

Sep 30th, 2021 at 2:33 PM

Opt-in Protection

September 30, 2021 at 5:40 PM

Global Protection

October 5, 2021 at 8:03 PM

Name

VMware vCenter RCE (II)

CVE

CVE-2021-22005

Severity Score

9.8

Detect to Protect

3 days, 10 hours, 1 minute

Description

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file

Detection

Sep 23rd, 2021 at 8:36 AM

Opt-in Protection

September 23, 2021 at 6:23 PM

Global Protection

September 26, 2021 at 6:37 PM

Name

PrintNightmare Spooler RCE Vulnerability

CVE

CVE-2021-1675

Severity Score

8.8

Detect to Protect

6 days, 6 hours, 28 minutes

Description

Windows Print Spooler Elevation of Privilege Vulnerability

Detection

Jul 5th, 2021 at 12:16 PM

Opt-in Protection

July 11, 2021 at 10:52 AM

Global Protection

July 11, 2021 at 6:44 PM

Name

Sphere Client (HTML5) Remote Code Execution

CVE

CVE-2021-21985

Severity Score

9.8

Detect to Protect

3 days, 11 hours, 29 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server

Detection

May 31, 2021 at 10:55 AM

Opt-in Protection

June 1, 2021 at 9:47 PM

Global Protection

June 3, 2021 at 10:24 PM

Name

F5 Vulnerability

CVE

CVE-2021-22986

Severity Score

9.8

Detect to Protect

2 days, 19 hours, 38 minutes

Description

On specific versions of BIG-IP and BIG-IQ , the iControl REST interface has an unauthenticated remote command execution vulnerability

Detection

Mar 20th, 2021 at 11:43 PM

Opt-in Protection

Mar 23rd, 2021 at 12:12 PM

Global Protection

March 23, 2021 at 7:21 PM

Name

MS Exchange SSRF

CVE

CVE-2021-26855

Severity Score

9.8

Detect to Protect

4 days, 2 hours, 23 minutes

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Detection

March 3, 2021 at 11:03 AM

Opt-in Protection

March 4, 2021 at 10:48 PM

Global Protection

March 7, 2021 at 1:26 PM

Name

VMWare VCenter RCE

CVE

CVE-2021-21972

Severity Score

9.8

Detect to Protect

1 day, 1 hour, 57 minutes

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

Detection

February 25, 2021 at 10:06 AM

Opt-in Protection

February 25, 2021 at 7:16 PM

Global Protection

February 26, 2021 at 12:03 PM

į‚ēäģ€éēŧ CVE įš„įˇŠč§ŖåĻ‚æ­¤å…ˇæŒ‘æˆ°æ€§īŧŸ

åŽĸæˆļįļ“常在äŋč­ˇįļ˛įĩĄå…å—æ–°čˆˆ CVE å¨č„…æ™‚īŧŒåœ¨éŽį¨‹ã€čŗ‡æēå’Œæ™‚é–“ä¸Šé‡åˆ°å›°é›Ŗã€‚åŽŸå› åς䏋īŧš

䞛應商åŋ…須針對čО CVE é€˛čĄŒį ”įŠļä¸Ļ開į™ŧį›¸æ‡‰įš„į‰šåžĩįĸŧ

åŽĸæˆļ需čρ圍įļ­č­ˇįĒ—åŖå…§æ¸ŦčŠĻčŠ˛į‰šåžĩįĸŧ

åŽĸæˆļæ¸ŦčŠĻåŋ…é ˆįĸēäŋčŠ˛į‰šåžĩįĸŧä¸æœƒä¸­æ–ˇæĩé‡ã€é™äŊŽæĒĸæ¸Ŧ效čƒŊ或åŊąéŸŋᔍæˆļéĢ”éŠ—

į‰šåžĩįĸŧåĒ有在æ¸ŦčŠĻ成功垌才čƒŊå•Ÿį”¨

這項é̘åēĻ耗č˛ģčŗ‡æēįš„éŽį¨‹īŧŒäŊŋč¨ąå¤šåŽĸæˆļ不垗不將å…Ĩäžĩ防įĻĻįŗģįĩą (IPS) åˆ‡æ›č‡ŗåĩæ¸Ŧæ¨ĄåŧīŧŒæˆ–雪äģĨįļ­æŒæœ€äŊŗįš„åŽ‰å…¨é˜˛č­ˇį‹€æ…‹ã€‚é€™æé̘äē†čĸĢå…Ĩäžĩįš„éĸ¨éšĒīŧŒå› į‚翔쿓Šč€…會čŠĻåœ–åˆŠį”¨æœĒäŋŽčŖœįš„ CVEīŧŒį”šč‡ŗæ˜¯éŽåŽģįš„æŧæ´žã€‚

Cato Networks æäž›æ–°čˆˆ CVE įš„å…¨č‡Ēå‹•č™›æ“ŦäŋŽčŖœæ–šæĄˆ

Cato įš„č™›æ“ŦäŋŽčŖœæĩį¨‹åŒ…åĢ四個æ­Ĩ驟īŧŒå…¨éƒ¨į”ą Cato åŽ‰å…¨åœ˜éšŠč˛ č˛ŦåŸˇčĄŒīŧš

評äŧ°

評äŧ° CVE įš„ åŊąéŸŋį¯„åœä¸Ļį ”įŠļ į›¸é—œæŧæ´žã€‚į‰šåˆĨ是針對 å¯Ļéš›ä¸­åˆŠį”¨æ­¤ CVE į™ŧ動æ”ģæ“Šįš„æƒ…æŗé€˛čĄŒåˆ†æžã€‚

äē†č§Ŗå—åŊąéŸŋįš„ įŗģįĩąéĄžåž‹äģĨåŠå¨č„…čĄŒį‚ē者 åĻ‚äŊ•åŸˇčĄŒæ”ģ擊

開į™ŧ

åģēįĢ‹æ–°įš„å…Ĩäžĩ防įĻĻįŗģįĩąčĻå‰‡ 來虛æ“ŦäŋŽčŖœæ­¤æŧæ´ž

透過回æ¸Ŧ æĩé‡å…ƒčŗ‡æ–™ 來æļˆé™¤čĒ¤å ą

選擇性äŋč­ˇ

åœ¨ã€Œæ¨Ąæ“Ŧæ¨Ąåŧã€ä¸‹ 選擇性部įŊ˛č™›æ“Ŧ誜䏁

į‚ēį‰šåŽšåŽĸæˆļ å•Ÿį”¨é¸æ“‡æ€§é˜˛č­ˇ

å…¨įƒé˜˛č­ˇ

將虛æ“Ŧ誜䏁 切換į‚ēé˜˛č­ˇæ¨Ąåŧ

在所有åŽĸæˆļ和所有æĩé‡ä¸­åŧˇåˆļå•Ÿį”¨č™›æ“Ŧ誜䏁

æ­¤æĩį¨‹åŽŒå…¨ä¸éœ€čρåŽĸæˆļčŗ‡æēįš„åƒčˆ‡īŧŒäšŸä¸æœƒå°åŽĸæˆļįš„æĨ­å‹™é‹äŊœé€ æˆäģģäŊ•éĸ¨éšĒ。

Request a Demo