ื”ืขื“ื›ื•ืŸ ืฉืืชื ืœื ื™ื›ื•ืœื™ื ืœื”ืจืฉื•ืช ืœืขืฆืžื›ื ืœื“ืœื’ ืขืœื™ื•: ืกื•ืฃ ื”ืชืžื™ื›ื” ื‘-Office 2016 ื•-Office 2019

ืงืจื ืขื›ืฉื™ื•
ืื ื• ืžืฉืชืžืฉื™ื ื‘ื‘ื™ื ื” ืžืœืื›ื•ืชื™ืช ืœืชืจื’ื•ื ื”ืืชืจ, ื•ืขืœ ืืฃ ืฉืื ื• ืฉื•ืืคื™ื ืœื“ื™ื•ืง ืžืจื‘ื™, ื™ื™ืชื›ืŸ ืฉื”ืชืจื’ื•ืžื™ื ืื™ื ื ืžื“ื•ื™ืงื™ื ื‘ืžืืช ื”ืื—ื•ื–ื™ื. ืื ื• ืžื•ื“ื™ื ืœืš ืขืœ ื”ื”ื‘ื ื”.

ืื‘ื˜ื—ืช ื‘ืงืจื™ ื‘ืงืจื” ืฉืœ Schneider Modicon M241 - CVE-2025-2875

ืขึทืœ ื™ึฐื“ึตื™ OPSWAT
ืฉืชืฃ ืืช ื”ืคื•ืกื˜ ื”ื–ื”

ื˜ื›ื ื•ืœื•ื’ื™ื” ืชืคืขื•ืœื™ืช (OT) ื›ื•ืœืœืช ืžืขืจื›ื•ืช ื—ื•ืžืจื” ื•ืชื•ื›ื ื” ืฉื ื•ืขื“ื• ืœื ื˜ืจ, ืœืฉืœื•ื˜ ื•ืœื ื”ืœ ืชื”ืœื™ื›ื™ื ืคื™ื–ื™ื™ื, ืžื›ืฉื™ืจื™ื ื•ืชืฉืชื™ื•ืช ื‘ืžื’ื–ืจื™ื ืงืจื™ื˜ื™ื™ื, ื›ื•ืœืœ ื™ื™ืฆื•ืจ, ื™ื™ืฆื•ืจ ืื ืจื’ื™ื”, ืจืฉืชื•ืช ืชื—ื‘ื•ืจื” ื•ืฉื™ืจื•ืชื™ื ืฆื™ื‘ื•ืจื™ื™ื. ื‘ื ื™ื’ื•ื“ ืœื˜ื›ื ื•ืœื•ื’ื™ื™ืช ืžื™ื“ืข (IT), ื”ืžืชืžืงื“ืช ื‘ืขื™ื‘ื•ื“ ื ืชื•ื ื™ื ื•ืชืงืฉื•ืจืช, ื˜ื›ื ื•ืœื•ื’ื™ื” ืชืคืขื•ืœื™ืช (OT) ืžื ื”ืœืช ืชื”ืœื™ื›ื™ื ืคื™ื–ื™ื™ื ื‘ืขื•ืœื ื”ืืžื™ืชื™. ื–ื” ื”ื•ืคืš ืืช ืื‘ื˜ื—ืช OT ืœื—ื™ื•ื ื™ืช ืœื”ื‘ื˜ื—ืช ื‘ื˜ื™ื—ื•ืช, ื”ืžืฉื›ื™ื•ืช ื•ืฉืœืžื•ืช ืฉืœ ืชืฉืชื™ื•ืช ืงืจื™ื˜ื™ื•ืช.

ื‘ืฉื ื™ื ื”ืื—ืจื•ื ื•ืช, ืกื‘ื™ื‘ื•ืช OT ื”ืคื›ื• ื™ื•ืชืจ ื•ื™ื•ืชืจ ืœืžื˜ืจื•ืช ืœืื™ื•ืžื™ ืกื™ื™ื‘ืจ ืžืชื•ื—ื›ืžื™ื. ืื™ื•ืžื™ื ืืœื” ื›ื•ืœืœื™ื ื‘ื“ืจืš ื›ืœืœ ืชื•ื›ื ื•ืช ื›ื•ืคืจ, ื ื™ืกื™ื•ื ื•ืช ื’ื™ืฉื” ื‘ืœืชื™ ืžื•ืจืฉื™ืช, ื—ื‘ืœื” ืžื›ื•ื•ื ืช ื‘ืชืฉืชื™ื•ืช ืงืจื™ื˜ื™ื•ืช ื•ื ื™ืฆื•ืœ ืคื’ื™ืขื•ื™ื•ืช ื‘ืžืขืจื›ื•ืช ื‘ืงืจื” ืชืขืฉื™ื™ืชื™ื•ืช (ICS). ืื™ืจื•ืขื™ื ื‘ื•ืœื˜ื™ื ืื—ืจื•ื ื™ื ืžื“ื’ื™ืฉื™ื ืืช ืื•ืคื™ื™ื ื”ืงืจื™ื˜ื™ ืฉืœ ืื™ื•ืžื™ื ืืœื”, ื›ืคื™ ืฉืžื•ื“ื’ื ื‘ืžืชืงืคืช ื”ื›ื•ืคืจ ืฉืœ Colonial Pipeline ื‘ืฉื ืช 2021, ืฉื’ืจืžื” ืœืฉื™ื‘ื•ืฉื™ื ืžืฉืžืขื•ืชื™ื™ื ื‘ืืกืคืงืช ื”ื“ืœืง ืœืื•ืจืš ื”ื—ื•ืฃ ื”ืžื–ืจื—ื™ ืฉืœ ืืจื”"ื‘, ื•ื‘ืžืชืงืคืช ื”ืกื™ื™ื‘ืจ ืขืœ ืจืฉืชื•ืช ื”ืœื•ื•ื™ื™ืŸ ืฉืœ Viasat ื‘ืฉื ืช 2022, ืฉืคื’ืขื” ืงืฉื•ืช ื‘ืชืฉืชื™ื•ืช ื”ืชืงืฉื•ืจืช ื‘ืจื—ื‘ื™ ืื™ืจื•ืคื” ื‘ืžื”ืœืš ืกื›ืกื•ื›ื™ื ื’ื™ืื•ืคื•ืœื™ื˜ื™ื™ื ืžื—ืžื™ืจื™ื. ื›ื›ืœ ืฉืžืขืจื›ื•ืช OT ื”ื•ืคื›ื•ืช ืžืงื•ืฉืจื•ืช ื•ืžืฉื•ืœื‘ื•ืช ื™ื•ืชืจ ื•ื™ื•ืชืจ ืขื ืชืฉืชื™ื•ืช IT, ื”ืŸ ื ืชืงืœื•ืช ื‘ืื™ื•ืžื™ ืกื™ื™ื‘ืจ ื™ื™ื—ื•ื“ื™ื™ื ืฉื™ื›ื•ืœื™ื ืœื”ื•ื‘ื™ืœ ืœืฉื™ื‘ื•ืฉื™ื ืชืคืขื•ืœื™ื™ื ื—ืžื•ืจื™ื ื•ืœื”ืฉืœื›ื•ืช ื›ืœื›ืœื™ื•ืช ืžื”ื•ืชื™ื•ืช.

ื’ื™ืœื•ื™ ืคื’ื™ืขื•ื™ื•ืช ื‘ืžืขืจื›ืช PLC Schneider Modicon M241 ืขืœ ื™ื“ื™ OPSWAT ื™ื—ื™ื“ื” 515

ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง ื”ื™ื ืžื•ื‘ื™ืœื” ืขื•ืœืžื™ืช ื‘ืชื—ื•ื ื”ืื•ื˜ื•ืžืฆื™ื” ื”ืชืขืฉื™ื™ืชื™ืช ื•ื ื™ื”ื•ืœ ื”ืื ืจื’ื™ื”, ื”ืžืกืคืงืช ืคืชืจื•ื ื•ืช ื—ื“ืฉื ื™ื™ื ื‘ืžื’ื•ื•ืŸ ืชืขืฉื™ื•ืช. ืกื“ืจืช ื”ื‘ืงืจื™ื ื”ืžื•ื“ื™ืงื•ื ื™ื™ื (PLC) ืฉืœ ืžื•ื“ื™ืงื•ืŸ, ื•ื‘ืžื™ื•ื—ื“ ื”-Modicon M241, ืฆื‘ืจื” ืคื•ืคื•ืœืจื™ื•ืช ืจื‘ื” ื‘ื–ื›ื•ืช ื™ื›ื•ืœืชื” ืœื ื”ืœ ืชื”ืœื™ื›ื™ ืื•ื˜ื•ืžืฆื™ื” ืžื•ืจื›ื‘ื™ื ื‘ื™ืขื™ืœื•ืช. ื”ื‘ืงืจ ื”ืžื•ื“ื™ืงื•ื ื™ M241, ื”ืžืฆื•ื™ื“ ื‘ื›ืœื™ ืชื›ื ื•ืช ืื™ื ื˜ื•ืื™ื˜ื™ื‘ื™ื™ื ื•ื™ื›ื•ืœื•ืช ืื™ื ื˜ื’ืจืฆื™ื” ื—ืœืงื•ืช ื‘ืืžืฆืขื•ืช ืคืœื˜ืคื•ืจืžืช EcoStruxure ืฉืœ ืฉื ื™ื™ื“ืจ, ืžื™ื•ืฉื ื‘ืื•ืคืŸ ื ืจื—ื‘ ื‘ืชืขืฉื™ื•ืช ื”ื“ื•ืจืฉื•ืช ื‘ืงืจื•ืช ืื•ื˜ื•ืžืฆื™ื” ืžื“ื•ื™ืงื•ืช ื•ืืžื™ื ื•ืช.

ื‘ื”ืชื—ืฉื‘ ื‘ืื™ืžื•ืฅ ื”ื ืจื—ื‘ ื•ื‘ืชืคืงื™ื“ื• ื”ืงืจื™ื˜ื™ ืฉืœ ื‘ืงืจ ื”-PLC ืฉืœ Schneider Modicon M241 ื‘ืคืขื™ืœื•ืช ืชืขืฉื™ื™ืชื™ืช, ื™ื—ื™ื“ื” 515 ืฉืœื ื•, ื”ื›ื•ืœืœืช ืืช Loc Nguyen, Dat Phung, Thai Do ื•-Minh Pham, ื‘ื™ืฆืขื” ื”ืขืจื›ื” ืžืงื™ืคื” ืฉืœ ืคื’ื™ืขื•ืช ื”ืชืงืŸ ื–ื”. OPSWAT ืžืขื‘ื“ืช ื”ื’ื ื” ืขืœ ืชืฉืชื™ื•ืช ืงืจื™ื˜ื™ื•ืช (CIP). ื”ื ื™ืชื•ื— ืฉืœื ื• ื—ืฉืฃ ืคื’ื™ืขื•ืช ืื‘ื˜ื—ื” ืžืฉืžืขื•ืชื™ืช, ืฉืื ืชื ื•ืฆืœ, ืขืœื•ืœื” ืœืคื’ื•ืข ื‘ืฉืœืžื•ืช ื”ืžืขืจื›ืช ื•ืœื—ืฉื•ืฃ ื ืชื•ื ื™ื ืจื’ื™ืฉื™ื. ื”ืฆื•ื•ืช ืฉืœื ื• ื™ืฆืจ ืงืฉืจ ื™ื–ื•ื ืขื ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง ื•ื“ื™ื•ื•ื— ืขืœ ื”ื‘ืขื™ื” ื›ื“ื™ ืœืกื™ื™ืข ืœื”ื ื‘ืชื”ืœื™ืš ื”ื–ื™ื”ื•ื™ ื•ื”ืชื›ื ื•ืŸ ืœืชื™ืงื•ืŸ, ื‘ืžื˜ืจื” ืœื—ื–ืง ืืช ืžืฆื‘ ื”ืื‘ื˜ื—ื” ื”ื›ื•ืœืœ ืฉืœ ืกื‘ื™ื‘ื•ืช OT .

ื‘ืชื’ื•ื‘ื” ืœื“ื™ื•ื•ื— ืฉืœื ื•, ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง ืคืจืกืžื” ื”ื ื—ื™ื™ืช ืื‘ื˜ื—ื” ื”ืžื›ื™ืจื” ื‘ืคื’ื™ืขื•ืช ื–ื• ื‘ืžืขืจื›ืช ื”-PLC Modicon M241, ื•ื‘ืคืจื˜ CVE-2025-2875. ื”ื ื—ื™ื•ืช ืืœื• ื ื•ืขื“ื• ืœื™ื™ื“ืข ื‘ืขืœื™ ืขื ื™ื™ืŸ ืขืœ ืกื™ื›ื•ื ื™ ืื‘ื˜ื—ื” ืคื•ื˜ื ืฆื™ืืœื™ื™ื ื•ืœืกืคืง ื”ื ื—ื™ื•ืช ื‘ืจื•ืจื•ืช ื›ื™ืฆื“ ืœื™ื™ืฉื ืืžืฆืขื™ ืชื™ืงื•ืŸ ืžืชืื™ืžื™ื.

ื‘ื‘ืœื•ื’ ื–ื”, ืื ื• ืžืกืคืงื™ื ืกื™ื›ื•ื ืžืงื™ืฃ ืฉืœ CVE-2025-2875, ืคื’ื™ืขื•ืช ืื‘ื˜ื—ื” ืฉื–ื•ื”ืชื” ื‘ืžื›ืฉื™ืจ Modicon M241 ืฉืœ ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง. ืžื‘ืœื™ ืœื—ืฉื•ืฃ ืžื™ื“ืข ื˜ื›ื ื™ ืžืคื•ืจื˜ ืฉืขืœื•ืœ ืœื”ืงืœ ืขืœ ืฉื™ืžื•ืฉ ืœืจืขื”, ืื ื• ืžื“ื’ื™ืฉื™ื ืืช ืื•ืคื™ ื”ืคื’ื™ืขื•ืช, ืžืขืจื™ื›ื™ื ืืช ื”ืฉืœื›ื•ืชื™ื” ื”ืคื•ื˜ื ืฆื™ืืœื™ื•ืช ืขืœ ืกื‘ื™ื‘ื•ืช ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ืชืคืขื•ืœื™ื•ืช (OT), ื•ืžืฆื™ืขื™ื ื”ืžืœืฆื•ืช ืžืขืฉื™ื•ืช ืœืฆืžืฆื•ื ื”ืกื™ื›ื•ื ื™ื ื”ื ืœื•ื•ื™ื. ืกืงื™ืจื” ื›ืœืœื™ืช ื–ื• ื ื•ืขื“ื” ืœืชืžื•ืš ื‘ืื ืฉื™ ืžืงืฆื•ืข ื‘ืชื—ื•ื ื”ืื‘ื˜ื—ื” ื•ื‘ื‘ืขืœื™ ื ื›ืกื™ื ื‘ื”ื’ื ื” ืขืœ ืชืฉืชื™ื•ืช ืงืจื™ื˜ื™ื•ืช.

ืžื•ื“ื™ืงื•ืŸ M241 ื•ื”ืื™ื ื˜ืจื ื˜ ื”ืžื•ื˜ืžืข Server

ื”-Modicon M241, ืฉืคื•ืชื— ืขืœ ื™ื“ื™ ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง , ื”ื•ื ื‘ืงืจ ืœื•ื’ื™ืงื” ืžื™ืงืจื•-ืžืชื›ื ืช (PLC) ื‘ืขืœ ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื, ืฉืชื•ื›ื ืŸ ืœืžืฉื™ืžื•ืช ืื•ื˜ื•ืžืฆื™ื” ืชื•ื‘ืขื ื™ื•ืช ืฉืœ ืžื›ื•ื ื•ืช. ื”ื•ื ืžืชืื™ื ื‘ืžื™ื•ื—ื“ ืœืืจื›ื™ื˜ืงื˜ื•ืจืช ืžื›ื•ื ื•ืช ืžื•ื“ื•ืœืจื™ืช ื•ืžื•ืจื›ื‘ืช, ื•ืžืฆื™ืข ืœื™ื‘ืช ืขื™ื‘ื•ื“ ืขื•ืฆืžืชื™ืช, ืžืžืฉืงื™ ืชืงืฉื•ืจืช ื’ืžื™ืฉื™ื ื•ืืคืฉืจื•ื™ื•ืช ืชืฆื•ืจื” ื ื™ืชื ื•ืช ืœื”ืจื—ื‘ื” ื›ื“ื™ ืœืขื ื•ืช ืขืœ ืžื’ื•ื•ืŸ ืจื—ื‘ ืฉืœ ื“ืจื™ืฉื•ืช ืชืขืฉื™ื™ืชื™ื•ืช.

ื™ื›ื•ืœืช ื‘ื•ืœื˜ืช ืื—ืช ืฉืœ ื”-Modicon M241 ื”ื™ื ืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ื”ืžื•ื˜ืžืข ืฉืœื•, ื”ืžืฆื™ืข ืžืžืฉืง ืžื•ื›ืŸ ืœืฉื™ืžื•ืฉ ืฉื ื™ืชืŸ ืœื’ืฉืช ืืœื™ื• ื™ืฉื™ืจื•ืช ื“ืจืš ื›ืœ ื“ืคื“ืคืŸ ืื™ื ื˜ืจื ื˜ ืกื˜ื ื“ืจื˜ื™. ืชื›ื•ื ื” ื–ื• ืžืืคืฉืจืช ืœืžืฉืชืžืฉื™ื ืœื ื˜ืจ, ืœื”ื’ื“ื™ืจ ื•ืœืงื™ื™ื ืื™ื ื˜ืจืืงืฆื™ื” ืขื ื”ื‘ืงืจ ืžืจื—ื•ืง, ืœืœื ืฆื•ืจืš ื‘ืชื•ื›ื ื” ื ื•ืกืคืช ืื• ื‘ื”ื’ื“ืจื•ืช ืžื•ืจื›ื‘ื•ืช.

ืžื‘ื˜ ืงื“ืžื™ ืขืœ ื‘ืงืจ PLC Schneider Modicon M241 ื”ืžืฆื™ื’ ื™ืฆื™ืื•ืช, ืžื—ื•ื•ื ื™ื ื•ื—ื™ื‘ื•ืจ Ethernet

ื‘ืขื•ื“ ืฉืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ื”ืžื•ื˜ืžืข ืžืฉืคืจ ืžืื•ื“ ืืช ื”ืฉื™ืžื•ืฉื™ื•ืช, ื‘ืžื™ื•ื—ื“ ื‘ืคืขื•ืœื•ืช ืžืจื—ื•ืง, ื”ื•ื ื’ื ืžืฆื™ื’ ืกื™ื›ื•ื ื™ ืกื™ื™ื‘ืจ ืคื•ื˜ื ืฆื™ืืœื™ื™ื ืื ืื™ื ื• ืžืื•ื‘ื˜ื— ื›ืจืื•ื™. ืื™ืžื•ืช ืงืœื˜ ืœื ืชืงื™ืŸ ืื• ื”ื™ืขื“ืจ ื‘ืงืจื•ืช ืื™ืžื•ืช ืขืœื•ืœื™ื ืœื—ืฉื•ืฃ ืืช ื”ืžืขืจื›ืช ืœื’ื™ืฉื” ืื• ืžื ื™ืคื•ืœืฆื™ื” ืœื ืžื•ืจืฉื™ืช.

ืžืชื•ืš ื”ื›ืจื” ื‘ื—ืฉืฉื•ืช ื”ืื‘ื˜ื—ื” ื”ืคื•ื˜ื ืฆื™ืืœื™ื™ื ื”ืœืœื•, ื™ื—ื™ื“ื” 515 ืฉืœื ื• ืขืจื›ื” ื”ืขืจื›ื” ื™ืกื•ื“ื™ืช ืฉืœ ืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ื”ืžื•ื˜ืžืข ืฉืœ ื”-Modicon M241. ื”ืžื˜ืจื” ื”ื™ื™ืชื” ืœืงื‘ื•ืข ื”ืื ืงื™ื™ืžื•ืช ืคื’ื™ืขื•ื™ื•ืช ื”ื ื™ืชื ื•ืช ืœื ื™ืฆื•ืœ ื‘ืจื›ื™ื‘ ื–ื” ืฉืขืœื•ืœื•ืช ืœืคื’ื•ืข ื‘ืฉืœืžื•ืช, ื‘ื–ืžื™ื ื•ืช ืื• ื‘ืกื•ื“ื™ื•ืช ื”ืžืขืจื›ืช.

CVE-2025-2875: ื”ืคื ื™ื” ืžื‘ื•ืงืจืช ื—ื™ืฆื•ื ื™ืช ืœืžืฉืื‘ ื‘ืกืคื™ืจื” ืื—ืจืช

ื‘ื”ืชืื ืœืžื˜ืจื” ื–ื•, ื™ื—ื™ื“ื” 515 ื‘ื™ืฆืขื” ื ื™ืชื•ื— ืžืขืžื™ืง ืฉืœ ืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ื”ืžื•ื˜ืžืข Modicon M241. ื ื™ืชื•ื— ื–ื” ื—ืฉืฃ ืชืจื—ื™ืฉื™ื ืกืคืฆื™ืคื™ื™ื ืฉื‘ื”ื ืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ื”ืžื•ื˜ืžืข ื™ืงื‘ืœ ื‘ืงืฉื•ืช ื’ื™ืฉื” ืœืงื‘ืฆื™ื ืฉื ื•ืฆืจื• ื‘ืžื›ื•ื•ืŸ, ื•ื‘ื›ืš ื™ืขืงื•ืฃ ืืช ืžื’ื‘ืœื•ืช ื”ืื‘ื˜ื—ื” ืฉื ื•ืขื“ื•. ื‘ื ื•ืกืฃ, ื‘ื“ื™ืงื” ืžืงื™ืคื” ืฉืœ ื”ืžื›ืฉื™ืจ ืืคืฉืจื” ื–ื™ื”ื•ื™ ืฉืœ ื ืชื™ื‘ื™ ืงื‘ืฆื™ื ืคื ื™ืžื™ื™ื ื‘ืชื•ืš ื”-PLC. ื ื™ืฆื•ืœ ืคื’ื™ืขื•ืช ื–ื• ืขืœื•ืœ ืœืืคืฉืจ ืœืชื•ืงืฃ ืœื ืžืื•ืžืช ื’ื™ืฉื” ืœืงื‘ืฆื™ื ืคื ื™ืžื™ื™ื ืจื’ื™ืฉื™ื ื‘ืžื›ืฉื™ืจ, ื“ื‘ืจ ืฉื™ืคื’ืข ื‘ืื•ืคืŸ ืžืฉืžืขื•ืชื™ ื‘ืกื•ื“ื™ื•ืช ื”ืžืขืจื›ืช.

ื”ืคื’ื™ืขื•ืช ื ื—ืฉืคื” ื‘ืคื ื™ ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง ื‘ืืžืฆืขื•ืช ืชื”ืœื™ืš ื’ื™ืœื•ื™ ืื—ืจืื™, ื•ืžืื– ื”ื•ืขืžื“ื• ืœืจืฉื•ืช ืืžืฆืขื™ ื”ืคื—ืชื” ื•ืชื™ืงื•ื ื™ื ืžืชืื™ืžื™ื. ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ืœืงื•ื—ื•ืช ืฉื ื™ื™ื“ืจ ื•ืœืžื ื•ืข ืฉื™ืžื•ืฉ ืœืจืขื” ืืคืฉืจื™, OPSWAT ื”ืกืชื™ืจื” ื‘ืžื›ื•ื•ืŸ ืžื™ื“ืข ื˜ื›ื ื™ ืžืคื•ืจื˜ ื”ืงืฉื•ืจ ืœืคื’ื™ืขื•ืช ื–ื•.

ืคืจื˜ื™ ืคื’ื™ืขื•ืช CVE-2025-2875 ืขื‘ื•ืจ ืžืขืจื›ืช PLC Schneider Modicon M241 ืขื ื“ื™ืจื•ื’ ื—ื•ืžืจื” ื’ื‘ื•ื” ืฉืœ CVSS 8.7

ืฆื™ืจ ื–ืžืŸ ืฉืœ CVE-2025-2875

ื‘ื”ืชืื ืœื ื”ืœื™ ื’ื™ืœื•ื™ ืื—ืจืื™ ื• OPSWAT ืžืชื•ืš ืžื—ื•ื™ื‘ื•ืช ืฉืœ ื—ื‘ืจืช ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง ืœื”ื’ื ื” ืขืœ ืชืฉืชื™ื•ืช ืงืจื™ื˜ื™ื•ืช, ื™ื—ื™ื“ื” 515 ื“ื™ื•ื•ื—ื” ืžื™ื“ ืขืœ ื”ืคื’ื™ืขื•ืช ืœื—ื‘ืจืช ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง ื“ืจืš ืขืจื•ืฅ ื”ืงืฉืจ ื”ืจืฉืžื™ ืฉืœื” ื‘ืชื—ื•ื ื”ืื‘ื˜ื—ื”, ื›ื“ื™ ืœืกื™ื™ืข ื‘ื—ืงื™ืจื” ื•ื‘ืชื›ื ื•ืŸ ื”ืชื™ืงื•ืŸ:

  • 20 ื‘ืคื‘ืจื•ืืจ 2025: ื™ื—ื™ื“ื” 515 ื”ื’ื™ืฉื” ื“ื•ื— ืคื’ื™ืขื•ืช ืœื—ื‘ืจืช ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง ื•ื‘ื• ืคื™ืจื˜ ืืช ื”ืคื’ื™ืขื•ืช ื‘ืžื›ืฉื™ืจ ืžื•ื“ื™ืงื•ืŸ M241.
  • 21 ื‘ืคื‘ืจื•ืืจ 2025: ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง ืื™ืฉืจื” ืงื‘ืœืช ื”ื“ื•ื— ื•ืคืชื—ื” ื‘ื—ืงื™ืจื” ืคื ื™ืžื™ืช. ื”ื•ืงืฆื” ืžื–ื”ื” ืžืขืงื‘ ืชื™ืง ืœืฆื•ืจืš ืชื™ืื•ื ืžืขืงื‘.
  • 20 ื‘ืžืจืฅ, 2025: ืœืื—ืจ ื ื™ืชื•ื— ืžืคื•ืจื˜, ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง ืื™ืฉืจื” ืืช ืชืงืคื•ืช ื”ืคื’ื™ืขื•ืช ื•ื”ื—ืœื” ืœืคืชื— ืชื•ื›ื ื™ืช ืชื™ืงื•ืŸ.
  • 13 ื‘ืžืื™ 2025: ืฉื ื™ื™ื“ืจ ืืœืงื˜ืจื™ืง ืคืจืกืžื” ื”ื•ื“ืขืช ื™ื™ืขื•ืฅ ืœืฆื™ื‘ื•ืจ ื™ื—ื“ ืขื ื”ื ื—ื™ื•ืช ืœืชื™ืงื•ืŸ ื”ื‘ืขื™ื” ืฉื–ื•ื”ืชื”. ืœืคื’ื™ืขื•ืช ื–ื• ื”ื•ืงืฆื” ืžื–ื”ื” CVE, CVE-2025-2875.

ืชื™ืงื•ืŸ

ืื ื• ืžืžืœื™ืฆื™ื ื‘ื—ื•ื ืฉืืจื’ื•ื ื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืžื›ืฉื™ืจื™ PLC ืžื“ื’ื Modicon M241 ืฉืœ Schneider Electric ื™ืคืขืœื• ืœืคื™ ื”ื”ื ื—ื™ื•ืช ื”ืจืฉืžื™ื•ืช ืฉืœ Schneider Electric ืœืชื™ืงื•ืŸ ืคื’ื™ืขื•ืช ื–ื•, ื”ื–ืžื™ื ื•ืช ื›ืืŸ: ืžืกืžืš ื™ื™ืขื•ืฅ ืื‘ื˜ื—ื” ืฉืœ Schneider .

ื›ื“ื™ ืœืฆืžืฆื ื‘ื™ืขื™ืœื•ืช ืคื’ื™ืขื•ื™ื•ืช ื›ืžื• CVE-2025-2875, ืืจื’ื•ื ื™ื ืฆืจื™ื›ื™ื ืœืืžืฅ ืืกื˜ืจื˜ื’ื™ื™ืช ื”ื’ื ื” ืžืงื™ืคื” ืœืขื•ืžืง, ื”ื›ื•ืœืœืช:

  1. Vulnerability detection ื‘ืืžืฆืขื•ืช ืกืจื™ืงืช CVE ืจืฆื™ืคื”: ืกืจื™ืงื” ืงื‘ื•ืขื” ืฉืœ ืจืฉืชื•ืช ืื—ืจ ืคื’ื™ืขื•ื™ื•ืช ื›ืžื• CVE-2025-2875
  2. ื ื™ื˜ื•ืจ ื”ืชื ื”ื’ื•ื™ื•ืช ื—ืจื™ื’ื•ืช: ืกื™ืžื•ืŸ ืขืœื™ื•ืช ื—ืจื™ื’ื•ืช ื‘ืชื“ื™ืจื•ืช ื”ืชืงืฉื•ืจืช ืขื ื‘ืงืจ ื”-PLC Schneider Modion M241, ื“ื‘ืจ ืฉื™ื›ื•ืœ ืœื”ืฆื‘ื™ืข ืขืœ ื ื™ืกื™ื•ืŸ ื“ืœื™ืคืช ื ืชื•ื ื™ื ืœื ืžื•ืจืฉื” ืžืชืžืฉืš.
  3. ื–ื™ื”ื•ื™ ื—ื™ื‘ื•ืจื™ ื”ืชืงื ื™ื ืœื ืžื•ืจืฉื™ื: ื”ืžืขืจื›ืช ืืžื•ืจื” ืœื–ื”ื•ืช ืžืชื™ ื”ืชืงืŸ ืกื•ืจืจ/ืœื ืžื•ืจืฉื” ืžืชื—ื‘ืจ ืœ-PLC
  4. ืคื™ืœื•ื— ืจืฉืช: ื‘ื™ื“ื•ื“ ืžื›ืฉื™ืจื™ื ืžื•ืฉืคืขื™ื ื™ื›ื•ืœ ืœืกื™ื™ืข ื‘ืžื ื™ืขืช ื”ืชืคืฉื˜ื•ืช ืจื•ื—ื‘ื™ืช ืฉืœ ื”ืชืงืคื•ืช, ื•ื‘ื›ืš ืœืžื–ืขืจ ืืช ื”ื”ืฉืคืขื”.
  5. ืžื ื™ืขืช ื—ื“ื™ืจื•ืช: ื–ื™ื”ื•ื™ ื•ื—ืกื™ืžื” ืžื™ื™ื“ื™ืช ืฉืœ ืคืงื•ื“ื•ืช ื–ื“ื•ื ื™ื•ืช/ืœื ืžืื•ืฉืจื•ืช ืœืžืขืจื›ืช ื”ื‘ืงืจื” ื”ืžืžืฉืœืชื™ืช (PLC), ื•ืœืื—ืจ ืžื›ืŸ ื”ื’ื ื” ื™ืขื™ืœื” ืขืœ ืคืขื•ืœื•ืช ืชืงื™ื ื•ืช ืฉืœ ื”ืžืขืจื›ืช.

OPSWAT OT Security ืฉืœ MetaDefender ืขื•ื ื” ืขืœ ืฆืจื›ื™ื ืืœื” ืขืœ ื™ื“ื™ ื–ื™ื”ื•ื™ CVEs, ื ื™ื˜ื•ืจ ืจืฆื™ืฃ ืฉืœ ื”ืจืฉืช ืœืื™ืชื•ืจ ื”ืชื ื”ื’ื•ื™ื•ืช ื—ืจื™ื’ื•ืช ื•ื–ื™ื”ื•ื™ ื—ื™ื‘ื•ืจื™ื ืœื ืžื•ืจืฉื™ื. ื‘ืืžืฆืขื•ืช ื‘ื™ื ื” ืžืœืื›ื•ืชื™ืช, ื”ื™ื ืœื•ืžื“ืช ื“ืคื•ืกื™ ืชื ื•ืขื” ืจื’ื™ืœื™ื, ืงื•ื‘ืขืช ื”ืชื ื”ื’ื•ืช ื‘ืกื™ืกื™ืช ื•ืžื™ื™ืฉืžืช ืžื“ื™ื ื™ื•ืช ืœื”ืชืจืขื” ืขืœ ืื ื•ืžืœื™ื•ืช. ื–ื” ืžืืคืฉืจ ืชื’ื•ื‘ื•ืช ืžื™ื™ื“ื™ื•ืช ื•ืžื•ืฉื›ืœื•ืช ืœืื™ื•ืžื™ื ืคื•ื˜ื ืฆื™ืืœื™ื™ื.

ื‘ืžืงืจื” ืฉืœ ืžืชืงืคื” ื”ืžื ืฆืœืช ืืช CVE-2025-2875, MetaDefender OT Security ืžืฉืชืœื‘ ืขื Firewall Industrial MetaDefender ื›ื“ื™ ืœื–ื”ื•ืช, ืœื”ืชืจื™ืข ื•ืœื—ืกื•ื ืชืงืฉื•ืจืช ื—ืฉื•ื“ื” ืขืœ ืกืžืš ื›ืœืœื™ื ืงื‘ื•ืขื™ื. Firewall Industrial MetaDefender ืžืฉืชืžืฉืช ื‘ื‘ื™ื ื” ืžืœืื›ื•ืชื™ืช ื›ื“ื™ ืœืœืžื•ื“ ื“ืคื•ืกื™ ืชื ื•ืขื” ืงื‘ื•ืขื™ื ื•ืœืื›ื•ืฃ ืžื“ื™ื ื™ื•ืช ืœืžื ื™ืขืช ื—ื™ื‘ื•ืจื™ื ืœื ืžื•ืจืฉื™ื.

ื”ืกืจื˜ื•ืŸ ื”ื‘ื ืžืžื—ื™ืฉ ื›ื™ืฆื“ OPSWAT OT Security MetaDefender ื•ื—ื•ืžืช Firewall Industrial ืฉืœ MetaDefender ืฉืœ MetaDefender ืžืฆืžืฆืžื•ืช ื‘ืื•ืคืŸ ื™ื–ื•ื ืืช ื”ืคื’ื™ืขื•ืช ื”ื–ื• ื•ืžื•ื ืขื•ืช ื’ื™ืฉื” ื‘ืœืชื™ ืžื•ืจืฉื™ืช ื‘ืชื•ืš ืกื‘ื™ื‘ืช ื”-OT:

ืžืขื‘ืจ ืœืžื ื™ืขื”, OPSWAT OT Security ืฉืœ MetaDefender ืžืืคืฉืจืช ืœืืจื’ื•ื ื™ื ืœื ื˜ืจ ืกื™ืžื ื™ ื ื™ืฆื•ืœ ื‘ื–ืžืŸ ืืžืช ื‘ืืžืฆืขื•ืช ื ืจืื•ืช ืžืชืžืฉื›ืช ืฉืœ ื ื›ืกื™ื ื•ื”ืขืจื›ืช ืคื’ื™ืขื•ื™ื•ืช. ืขืœ ื™ื“ื™ ืžื™ื ื•ืฃ ื™ื›ื•ืœื•ืช ืžืชืงื“ืžื•ืช ืฉืœ ืžืขืงื‘ ืื—ืจ ืžืœืื™ ื ื›ืกื™ื ื•ื”ืขืจื›ืช ืคื’ื™ืขื•ื™ื•ืช, ื”ืคืœื˜ืคื•ืจืžื” ืฉืœื ื• ืžืกืคืงืช ื–ื™ื”ื•ื™ ืื™ื•ืžื™ื ืคืจื•ืืงื˜ื™ื‘ื™ ื•ืžืืคืฉืจืช ืคืขื•ืœื•ืช ืชื™ืงื•ืŸ ืžื”ื™ืจื•ืช ื•ื™ืขื™ืœื•ืช.

ื”ืกืจื˜ื•ืŸ ื”ื‘ื ืžื“ื’ื™ื ื›ื™ืฆื“ MetaDefender OT Security ืžื–ื”ื” ื‘ื™ืขื™ืœื•ืช ืžื›ืฉื™ืจื™ื ืคื’ื™ืขื™ื ื•ืžืกืคืง ืคืชืจื•ืŸ ืžื”ื™ืจ ืœืคื’ื™ืขื•ื™ื•ืช ืฉื–ื•ื”ื•:

ื”ื™ืฉืืจ ืžืขื•ื“ื›ืŸ ืขื OPSWAT !

ื”ื™ืจืฉืžื• ืขื•ื“ ื”ื™ื•ื ื›ื“ื™ ืœืงื‘ืœ ืืช ื”ืขื“ื›ื•ื ื™ื ื”ืื—ืจื•ื ื™ื ืฉืœ ื”ื—ื‘ืจื”, ืกื™ืคื•ืจื™ื, ืžื™ื“ืข ืขืœ ืื™ืจื•ืขื™ื ื•ืขื•ื“.