ื”ืขื“ื›ื•ืŸ ืฉืืชื ืœื ื™ื›ื•ืœื™ื ืœื”ืจืฉื•ืช ืœืขืฆืžื›ื ืœื“ืœื’ ืขืœื™ื•: ืกื•ืฃ ื”ืชืžื™ื›ื” ื‘-Office 2016 ื•-Office 2019

ืงืจื ืขื›ืฉื™ื•
ืื ื• ืžืฉืชืžืฉื™ื ื‘ื‘ื™ื ื” ืžืœืื›ื•ืชื™ืช ืœืชืจื’ื•ื ื”ืืชืจ, ื•ืขืœ ืืฃ ืฉืื ื• ืฉื•ืืคื™ื ืœื“ื™ื•ืง ืžืจื‘ื™, ื™ื™ืชื›ืŸ ืฉื”ืชืจื’ื•ืžื™ื ืื™ื ื ืžื“ื•ื™ืงื™ื ื‘ืžืืช ื”ืื—ื•ื–ื™ื. ืื ื• ืžื•ื“ื™ื ืœืš ืขืœ ื”ื”ื‘ื ื”.

ื—ื•ืžื•ืช ืืฉ ืื™ื ืŸ ืžืกืคื™ืงื•ืช: 7 ืคื’ื™ืขื•ื™ื•ืช ื•ื—ืฉื™ืคื•ืช ื ืคื•ืฆื•ืช ื”ืžืื™ื™ืžื•ืช ืขืœ ื—ื•ืžื•ืช ืืฉ ืžืกื•ืจืชื™ื•ืช

ืขึทืœ ื™ึฐื“ึตื™ OPSWAT
ืฉืชืฃ ืืช ื”ืคื•ืกื˜ ื”ื–ื”

ื—ื•ืžื•ืช ืืฉ ืžืกื•ืจืชื™ื•ืช ื”ืŸ ื‘ื™ืŸ ืฉื›ื‘ื•ืช ื”ื”ื’ื ื” ื”ื ืคื•ืฆื•ืช ื‘ื™ื•ืชืจ - ื•ื”ื ืกืžื›ื™ื ื‘ื™ื•ืชืจ - ื‘ืืกื˜ืจื˜ื’ื™ื•ืช ืื‘ื˜ื—ืช ืกื™ื™ื‘ืจ ื‘ืจืฉืชื•ืช OT. ืขื ื–ืืช, ื”ืืžื•ื ื” ืฉืขืฆื ืงื™ื•ืžื” ืฉืœ ื—ื•ืžืช ืืฉ ืžื‘ื˜ื™ื—ื” ืื‘ื˜ื—ื” ื”ื™ื ืชืคื™ืกื” ืžื•ื˜ืขื™ืช. ื—ื•ืžื•ืช ืืฉ, ืœืžืจื•ืช ืฉื ื•ืขื“ื• ืœืฉืžืฉ ื›ืฉื•ืžืจื•ืช ืกืฃ, ืื™ื ืŸ ื—ืกื™ื ื•ืช ืžืคื ื™ ืคื’ื™ืขื•ื™ื•ืช. ื‘ื‘ืœื•ื’ ื–ื”, ืื ื• ื“ื ื™ื ื‘ืฉื‘ืขื” ืžืงืจื™ื ืกืคืฆื™ืคื™ื™ื ืฉื‘ื”ื ื ื•ื›ื—ื•ืชื” ืฉืœ ื—ื•ืžืช ืืฉ, ืœืžืจื•ืช ืฉื ืชืคืกื” ื›ื‘ืกื™ืก ืœืืกื˜ืจื˜ื’ื™ื™ืช ืื‘ื˜ื—ื”, ื”ืคื›ื” ื‘ืฉื•ื’ื’ ืœื ืชื™ื‘ ืขื‘ื•ืจ ื’ื•ืจืžื™ ืื™ื•ื ืœืงื‘ืœ ื’ื™ืฉื” ื‘ืœืชื™ ืžื•ืจืฉื™ืช ืœืจืฉืช.

ืžื” ื–ื” CVE?

CVE, ืื• Common Vulnerability and Exposure, ื”ื•ื ืžื–ื”ื” ืกื˜ื ื“ืจื˜ื™ ืœืคื’ื™ืขื•ืช ืื‘ื˜ื—ื” ืื• ื—ื•ืœืฉื” ื‘ืชื•ื›ื ื”, ื—ื•ืžืจื” ืื• ืงื•ืฉื—ื”. CVEs ืžืฉืžืฉื™ื ืœื–ื™ื”ื•ื™ ื•ืžืขืงื‘ ื™ื™ื—ื•ื“ื™ื™ื ืื—ืจ ืคื’ื™ืขื•ื™ื•ืช ืืœื•, ืžื” ืฉืžืงืœ ืขืœ ืืจื’ื•ื ื™ื, ื—ื•ืงืจื™ ืื‘ื˜ื—ื” ื•ืกืคืงื™ื ืœืฉืชืฃ ืžื™ื“ืข ืขืœ ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ื•ืœืชืื ืืช ืžืืžืฆื™ื”ื ืœืฆืžืฆื•ืืŸ.


7 CVEs ื‘ื•ืœื˜ื™ื ืฉื”ืฉืคื™ืขื• ืขืœ ื—ื•ืžื•ืช ืืฉ

CVE-2020-3580

ืชื™ืื•ืจ: ืคื’ื™ืขื•ืช ืฉื–ื•ื”ืชื” ื‘ืžืžืฉืง ืฉื™ืจื•ืชื™ ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ืกื™ืกืงื• Adaptive ืžื›ืฉื™ืจ ืื‘ื˜ื—ื” (ASA) Software ื•ื”ื’ื ื” ืžืคื ื™ ืื™ื•ืžื™ Firepower ืฉืœ ืกื™ืกืงื• (FTD) Software .
ื ื–ืง ืืคืฉืจื™:
ืคื’ื™ืขื•ืช ื–ื• ืขืœื•ืœื” ืœืืคืฉืจ ืœืชื•ืงืฃ ืžืจื•ื—ืง ื•ืœื ืžืื•ืžืช ืœื‘ืฆืข ื”ืชืงืคื•ืช ื—ืฆื™ื™ืช ืกืคืจื™ื•ืช, ืžื” ืฉื™ืืคืฉืจ ืœื• ืœืงืจื•ื ืงื‘ืฆื™ื ืจื’ื™ืฉื™ื ื‘ืžืขืจื›ืช ืžืžื•ืงื“ืช.
ืงื™ืฉื•ืจ:
CVE-2020-3580

CVE-2019-1579

ืชื™ืื•ืจ: ื ืžืฆืื” ืชืงืœื” ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื” PAN-OS ืฉืœ Palo Alto Networks ืœืคื ื™ ื’ืจืกื” 8.1.10 ื•-9.0.0.
ื ื–ืง ืคื•ื˜ื ืฆื™ืืœื™:
ืชื•ืงืคื™ื ืžืจื•ื—ืงื™ื ืขืœื•ืœื™ื ืœื ืฆืœ ืคื’ื™ืขื•ืช ื–ื• ื›ื“ื™ ืœื‘ืฆืข ืคืงื•ื“ื•ืช ืฉืจื™ืจื•ืชื™ื•ืช ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื”, ื•ื‘ื›ืš ืœื”ืฉืชืœื˜ ื‘ืื•ืคืŸ ืคื•ื˜ื ืฆื™ืืœื™ ืขืœ ื”ืžืขืจื›ืช ื”ืžื•ืฉืคืขืช.
ืงื™ืฉื•ืจ:
CVE-2019-1579

CVE-2018-6721ย 

ืชื™ืื•ืจ: ืคื’ื™ืขื•ืช ืฉื”ืชื’ืœืชื” ื‘-SonicOS ืฉืœ SonicWall.
ื ื–ืง ืคื•ื˜ื ืฆื™ืืœื™:
ืชื•ืงืคื™ื ืžืจื•ื—ืงื™ื ืขืœื•ืœื™ื ืœื ืฆืœ ืคื’ื™ืขื•ืช ื–ื• ื›ื“ื™ ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช (DoS) ื‘ืืžืฆืขื•ืช ื—ื‘ื™ืœื•ืช ืžืงื•ื˜ืขื•ืช ืฉื ื•ืฆืจื• ื‘ืžื™ื•ื—ื“, ื“ื‘ืจ ื”ืžืฉืคื™ืข ืขืœ ื–ืžื™ื ื•ืช ื”ืžืขืจื›ืช.
ืงื™ืฉื•ืจ:
CVE-2018-6721

CVE-2017-5638

ืชื™ืื•ืจ: ืคื’ื™ืขื•ืช ื‘ื’ืจืกืื•ืช 2 ืฉืœ Apache Struts ืœืคื ื™ 2.3.32 ื•-2.5.x ืœืคื ื™ 2.5.10.1.
ื ื–ืง ืคื•ื˜ื ืฆื™ืืœื™:
ื”ื“ื‘ืจ ืื™ืคืฉืจ ืœืชื•ืงืคื™ื ืœื‘ืฆืข ื”ืชืงืคื•ืช ืฉืœ ื‘ื™ืฆื•ืข ืคืงื•ื“ื•ืช ืžืจื—ื•ืง ื‘ืืžืฆืขื•ืช ืขืจืš Content-Type ืžืขื•ืฆื‘, ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœืคืจื™ืฆื•ืช ื ืชื•ื ื™ื ืื• ืœื ื™ืฆื•ืœ ื ื•ืกืฃ ืฉืœ ื”ืจืฉืช.
ืงื™ืฉื•ืจ:
CVE-2017-5638

CVE-2016-0801

ืชื™ืื•ืจ: ืคื’ื™ืขื•ืช ืฉื–ื•ื”ืชื” ื‘-Cisco ASA Software ืคื•ืขืœ ืขืœ ื’ื‘ื™ ืžื•ืฆืจื™ื ืžืกื•ื™ืžื™ื ืฉืœ Cisco ASA.
ื ื–ืง ืืคืฉืจื™:
ืชื•ืงืคื™ื ืžืจื•ื—ืงื™ื ืขืœื•ืœื™ื ืœื ืฆืœ ืคื’ื™ืขื•ืช ื–ื• ื›ื“ื™ ืœื‘ืฆืข ืงื•ื“ ืฉืจื™ืจื•ืชื™ ืื• ืœื’ืจื•ื ืœื˜ืขื™ื ื” ืžื—ื“ืฉ ืฉืœ ื”ืžืขืจื›ืช, ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœืคื’ื™ืขื” ื‘ืžืขืจื›ืช ืื• ืœื”ืฉื‘ืชื”.
ืงื™ืฉื•ืจ:
CVE-2016-0801

CVE-2014-0160 (ื”ืืจื˜ื‘ืœื™ื“)

ืชื™ืื•ืจ: ืคื’ื™ืขื•ืช ื—ืžื•ืจื” ื‘ื”ืจื—ื‘ืช Heartbeat ืฉืœ OpenSSL TLS.
ื ื–ืง ืคื•ื˜ื ืฆื™ืืœื™:
ื‘ืื’ Heartbleed ืื™ืคืฉืจ ืœืชื•ืงืคื™ื ืœืงืจื•ื ืืช ื”ื–ื™ื›ืจื•ืŸ ืฉืœ ืžืขืจื›ื•ืช ื”ืžื•ื’ื ื•ืช ืขืœ ื™ื“ื™ ื’ืจืกืื•ืช ืคื’ื™ืขื•ืช ืฉืœ OpenSSL, ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื“ืœื™ืคืช ืžื™ื“ืข ืจื’ื™ืฉ ื›ืžื• ืกื™ืกืžืื•ืช, ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ื•ืขื•ื“.
ืงื™ืฉื•ืจ:
CVE-2014-0160

CVE-2012-4681

ืชื™ืื•ืจ: ืคื’ื™ืขื•ืช ื”ืžืฉืคื™ืขื” ืขืœ Oracle Java 7 ืœืคื ื™ ืขื“ื›ื•ืŸ 7.
ื ื–ืง ืคื•ื˜ื ืฆื™ืืœื™:
ืืคืฉืจ ืœืชื•ืงืคื™ื ืœื‘ืฆืข ืงื•ื“ ืฉืจื™ืจื•ืชื™ ืžืจื—ื•ืง ื‘ืืžืฆืขื•ืช ื•ืงื˜ื•ืจื™ื ื”ืงืฉื•ืจื™ื ืœื”ืฉืชืงืคื•ืช. API , ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœืคื’ื™ืขื” ื‘ืžืขืจื›ืช.
ืงื™ืฉื•ืจ:
CVE-2012-4681

ื‘ืื ืจ ืคืจืกื•ืžื™ ืขื‘ื•ืจ ื ื™ื™ืจ ืขืžื“ื” ืฉื›ื•ืชืจืชื•

ืื‘ื˜ื—ืช ืจืฉืช OT ืœืœื ืคืฉืจื•ืช

ื—ื•ืžื•ืช ืืฉ ืžืกื•ืจืชื™ื•ืช ืžืžืฉื™ื›ื•ืช ืœื”ื™ื•ืช ื›ืœื™ ืžืจื›ื–ื™ ื‘ืขื™ืฆื•ื‘ ืžืกื’ืจืช ืื‘ื˜ื—ืช ื”-OT ืฉืœ ืืจื’ื•ื ื™ื, ื•ื”ื‘ื ื” ื•ื˜ื™ืคื•ืœ ื‘ืคื’ื™ืขื•ื™ื•ืช ื”ื˜ื‘ื•ืขื•ืช ื‘ื”ืŸ ื ื•ืชืจื• ื—ื™ื•ื ื™ื™ื. ืืš ื‘ืจื•ืจ ื›ื™ ื‘ืขื•ื“ ืฉื—ื•ืžื•ืช ืืฉ ืื™ื ืŸ ืžื™ื•ืฉื ื•ืช ื‘ืฉื•ื ืื•ืคืŸ, ื”ืกืชืžื›ื•ืช ืขืœ ื”ื”ื’ื ื” ืฉืœื”ืŸ ื‘ืœื‘ื“ ืื™ื ื” ืžืกืคืงืช ื”ื’ื ื” ืžืกืคืงืช ืžืคื ื™ ืื™ื•ืžื™ื ืžืชืขื•ืจืจื™ื. ื‘ื ื™ื™ืช ืืกื˜ืจื˜ื’ื™ื™ืช ื”ื’ื ื” ืืžื™ืชื™ืช ื•ืžืขืžื™ืงื” ื”ืžืชืžืงื“ืช ื‘... Unidirectional Security Gateway ืื• ื“ื™ื•ื“ืช ื ืชื•ื ื™ื ื‘ืื–ื•ืจ ื”-DMZ ืฉืœื›ื ืžื‘ื˜ื™ื—ื” ืฉื ืชื•ื ื™ื ื™ื•ื›ืœื• ืœืขื‘ื•ืจ ื‘ื›ื™ื•ื•ืŸ ืื—ื“ ื‘ืœื‘ื“. ืื›ื™ืคื” ืคื™ื–ื™ืช ื–ื• ืคื™ืจื•ืฉื” ืฉื ื™ืชืŸ ืœืฉืœื•ื— ื ืชื•ื ื™ื ืœืœื ื›ืœ ืื™ื•ื ืฉืœ ื ืชื•ื ื™ื ื–ื“ื•ื ื™ื™ื ืื• ืคืงื•ื“ื•ืช ืฉื ื›ื ืกื•ืช ื‘ื—ื–ืจื”. ื‘ืžืงืจื” ื–ื”, ื’ื ืื ืงื™ื™ืžืช ืคื’ื™ืขื•ืช ืชื•ื›ื ื”, ื”ืื•ืคื™ ื”ืคื™ื–ื™ ืฉืœ ืฉืขืจื™ ืื‘ื˜ื—ื” ืืœื” ืื•ื›ืฃ ื”ื’ื ื” ืžืคื ื™ ื”ืื™ื•ื, ื•ืžื‘ื•ื“ื“ ืืช ื”ืจืฉืช ืฉืœื›ื ืžื—ืฉื™ืคื”.

ืฆืœื•ืœ ืœืขื•ืžืง: ื“ื™ื•ื“ื•ืช ื ืชื•ื ื™ื ืœืขื•ืžืช ื—ื•ืžื•ืช ืืฉ: ื”ืฉื•ื•ืื” ื‘ื™ืŸ ืื‘ื˜ื—ืช ืจืฉืช, ื–ืจื™ืžืช ื ืชื•ื ื™ื ื•ืชืื™ืžื•ืช

ืชืงืจื™ื‘ ืฉืœ MetaDefender NetWall ื”ืชืงื ื™ ื—ื•ืžืจื” ื”ื›ื•ืœืœื™ื ื™ืฆื™ืื•ืช, ืžื—ื•ื•ื ื™ LED ื•ืชื•ื•ื™ื•ืช

MetaDefender NetWall ืฉืขืจ ืื‘ื˜ื—ื” ื‘ืจืžื” ื”ื‘ืื” ื• Optical Diode

ื‘ื”ืชื—ืฉื‘ ื‘ืกื•ื’ื™ ืคื’ื™ืขื•ื™ื•ืช ื›ืืœื”, OPSWAT ืคื™ืชื—ื” NetWall , ืกื“ืจืช ืฉืขืจื™ ืื‘ื˜ื—ื” ืžืชืงื“ืžื™ื ื•ื“ื™ื•ื“ื•ืช ืื•ืคื˜ื™ื•ืช , ืœื”ื’ื ื” ืขืœ ืกื‘ื™ื‘ื•ืช OT ืงืจื™ื˜ื™ื•ืช ืžืคื ื™ ื ื•ืฃ ื”ืื™ื•ืžื™ื ื”ืžืชืคืชื—. ื–ืžื™ืŸ ื‘ืžื’ื•ื•ืŸ ืชืฆื•ืจื•ืช ื•ื’ื•ืจืžื™ ืฆื•ืจื”, NetWall ื ื•ืขื“ ืœืคืฉื˜ ืืช ืžื•ืจื›ื‘ื•ื™ื•ืช ืื‘ื˜ื—ืช ื”ืจืฉืช ื›ืคืชืจื•ืŸ ืงืœ ืœืฉื™ืžื•ืฉ, ื ื™ืชืŸ ืœื”ืจื—ื‘ื” ื•ืžืื•ื‘ื˜ื—.

ื’ืœื” ืžื“ื•ืข NetWall ืืžื™ืŸ ื‘ืจื—ื‘ื™ ื”ืขื•ืœื ืœื”ื’ืŸ ืขืœ ื›ืžื” ืžื”ืกื‘ื™ื‘ื•ืช ื”ืงืจื™ื˜ื™ื•ืช ื‘ื™ื•ืชืจ ื‘ืขื•ืœื

ืชื’ื™ื•ืช:

ื”ื™ืฉืืจ ืžืขื•ื“ื›ืŸ ืขื OPSWAT !

ื”ื™ืจืฉืžื• ืขื•ื“ ื”ื™ื•ื ื›ื“ื™ ืœืงื‘ืœ ืืช ื”ืขื“ื›ื•ื ื™ื ื”ืื—ืจื•ื ื™ื ืฉืœ ื”ื—ื‘ืจื”, ืกื™ืคื•ืจื™ื, ืžื™ื“ืข ืขืœ ืื™ืจื•ืขื™ื ื•ืขื•ื“.