{"id":132058,"date":"2024-01-16T17:52:59","date_gmt":"2024-01-17T01:52:59","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=132058"},"modified":"2024-06-24T05:12:00","modified_gmt":"2024-06-24T12:12:00","slug":"threat-brief-ivanti-cve-2023-46805-cve-2024-21887","status":"publish","type":"post","link":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/","title":{"rendered":"[2024-03-01 JST \u66f4\u65b0] \u8105\u5a01\u306b\u95a2\u3059\u308b\u60c5\u5831: Ivanti Connect Secure\u3001Ivanti Policy Secure \u306b\u304a\u3051\u308b\u8106\u5f31\u6027 (CVE-2023-46805\u3001CVE-2024-21887\u3001CVE-2024-21888\u3001CVE-2024-21893\u3001CVE-2024-22024)"},"content":{"rendered":"<h2><b>3 \u6708 1 \u65e5 JST \u66f4\u65b0<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">\u7c73\u56fd\u653f\u5e9c\u306f\u56fd\u969b\u7684\u306a\u653f\u5e9c\u306e\u540c\u76df\u56fd\u3068\u5354\u529b\u3057\u3001\u540c\u30b0\u30eb\u30fc\u30d7\u306e\u6d3b\u52d5\u306b\u95a2\u3059\u308b<\/span><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa24-060b\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">\u5408\u540c\u30b5\u30a4\u30d0\u30fc\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u52e7\u544a (CSA) <\/span><\/a><span style=\"font-weight: 400;\">\u3092\u767a\u8868\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u52e7\u544a\u306b\u306f\u3001Ivanti \u88fd\u54c1\u306e\u8106\u5f31\u6027\u60aa\u7528\u306b\u95a2\u3059\u308b\u6700\u8fd1\u306e\u8abf\u67fb\u7d50\u679c\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u52e7\u544a\u306e\u57f7\u7b46\u3092\u62c5\u5f53\u3057\u305f\u8907\u6570\u306e\u7d44\u7e54\u304c\u300c\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3089\u306f Ivanti \u306e\u5185\u90e8\u304a\u3088\u3073\u5916\u90e8\u306e\u30a4\u30f3\u30c6\u30b0\u30ea\u30c6\u30a3 \u30c1\u30a7\u30c3\u30ab\u30fc \u30c4\u30fc\u30eb (ICT) \u3092\u6b3a\u304f\u3053\u3068\u304c\u3067\u304d\u3001\u305d\u306e\u7d50\u679c\u3001\u4fb5\u5bb3\u3092\u691c\u77e5\u3067\u304d\u306a\u3044\u300d\u3068\u8ff0\u3079\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3053\u308c\u3089\u306e\u7d44\u7e54\u306f\u300c\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3089\u306f\u5de5\u5834\u51fa\u8377\u6642\u8a2d\u5b9a\u3078\u306e\u30ea\u30bb\u30c3\u30c8\u3092\u884c\u3063\u305f\u5f8c\u3082\u30eb\u30fc\u30c8\u30ec\u30d9\u30eb\u306e\u6301\u7d9a\u6027\u3092\u7dad\u6301\u3067\u304d\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u300d\u3068\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u3053\u306e CSA \u306b\u306f\u3001\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u306e\u624b\u9806\u306b\u95a2\u3059\u308b\u30ac\u30a4\u30c0\u30f3\u30b9\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u4e0a\u8a18\u306e\u7d44\u7e54\u306f\u307e\u305f\u3001\u9632\u5fa1\u5074\u306b\u5bfe\u3057\u3001\u6f0f\u51fa\u3057\u305f\u3059\u3079\u3066\u306e\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb (\u8a8d\u8a3c\u60c5\u5831) \u3092\u30ea\u30bb\u30c3\u30c8\u3057\u3001Active Directory \u306e\u30a2\u30af\u30bb\u30b9\u3092\u3082\u3064 Ivanti \u30db\u30b9\u30c8\u3092\u7279\u5b9a\u3057\u3001\u307b\u304b\u306b\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u304c\u898b\u3089\u308c\u306a\u3044\u304b\u3092\u63a2\u3059\u305f\u3081\u306e\u65bd\u7b56\u3092\u53d6\u308b\u3088\u3046\u52e7\u544a\u3057\u3066\u3044\u307e\u3059\u3002\u305d\u306e\u7406\u7531\u306f\u3001\u305f\u3068\u3048\u60aa\u610f\u306e\u3042\u308b\u7ba1\u7406\u8005\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u524a\u9664\u3057\u3066\u3082\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u307b\u304b\u306e\u6c38\u7d9a\u6027\u7dad\u6301\u306e\u30e1\u30ab\u30cb\u30ba\u30e0\u3092\u78ba\u7acb\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304b\u3089\u3001\u8105\u5a01\u3092\u7de9\u548c\u3067\u304d\u306a\u3044\u53ef\u80fd\u6027\u304c\u3042\u308b\u305f\u3081\u3067\u3059\u3002\u3055\u3089\u306b\u3001\u300c\u4f01\u696d\u74b0\u5883\u306b\u304a\u3044\u3066 Ivanti Connect Secure \u304a\u3088\u3073 Ivanti Policy Secure \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u30c7\u30d0\u30a4\u30b9\u306e\u904b\u7528\u7d99\u7d9a\u306e\u53ef\u5426\u3092\u6c7a\u5b9a\u3059\u308b\u3055\u3044\u306f\u3001\u3053\u308c\u3089\u306e\u30c7\u30d0\u30a4\u30b9\u306b\u5bfe\u3059\u308b\u653b\u6483\u8005\u306e\u30a2\u30af\u30bb\u30b9\u304a\u3088\u3073\u6c38\u7d9a\u6027\u7dad\u6301\u3068\u3044\u3046\u91cd\u5927\u30ea\u30b9\u30af\u3092\u8003\u616e\u3059\u308b\u3088\u3046\u3001\u3059\u3079\u3066\u306e\u7d44\u7e54\u306b\u5f37\u304f\u4fc3\u3059\u300d\u3068\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<h2>2 \u6708 9 \u65e5 JST \u66f4\u65b0<\/h2>\n<p><span style=\"font-weight: 400;\">Ivanti \u306f\u3001CVE-2024-22024 \u3068\u3044\u3046\u65b0\u3057\u3044\u8106\u5f31\u6027\u3092\u5831\u544a\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u8106\u5f31\u6027\u306f\u3001\u540c\u793e\u306e Connect Secure\u3001Policy Secure\u3001ZTA \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u88fd\u54c1\u306b\u5f71\u97ff\u3057\u307e\u3059\u3002<\/span><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">\u5f71\u97ff\u3092\u53d7\u3051\u308b\u88fd\u54c1\u30d0\u30fc\u30b8\u30e7\u30f3\u306e\u4e00\u90e8<\/span><\/a><span style=\"font-weight: 400;\">\u306b\u3064\u3044\u3066\u306f\u30d1\u30c3\u30c1\u3092\u5229\u7528\u3067\u304d\u307e\u3059\u3002Ivanti \u304c 1 \u6708 31 \u65e5\u306b\u63d0\u4f9b\u3057\u305f\u56de\u907f\u7b56\u306f\u3001\u3053\u306e\u65b0\u305f\u306a\u8106\u5f31\u6027\u306e\u30d6\u30ed\u30c3\u30af\u306b\u6709\u52b9\u3068\u5831\u544a\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/p>\n<p><span style=\"font-weight: 400;\">CVE-2024-22024 \u306f\u3001Ivanti Connect Secure (9.x, 22.x)\u3001Ivanti Policy Secure (9.x, 22.x)\u3001ZTA \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u88fd\u54c1\u306e SAML \u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306b\u5b58\u5728\u3059\u308b XML \u5916\u90e8\u5b9f\u4f53\u53c2\u7167 (XML eXternal Entity: XXE) \u306e\u8106\u5f31\u6027\u3067\u3001\u653b\u6483\u8005\u306f\u8a8d\u8a3c\u306a\u3057\u3067\u7279\u5b9a\u306e\u5236\u9650\u3055\u308c\u305f\u30ea\u30bd\u30fc\u30b9\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Ivanti \u306f\u3053\u308c\u307e\u3067\u3053\u306e\u65b0\u305f\u306a\u8106\u5f31\u6027\u304c\u91ce\u751f\u3067\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3055\u308c\u3066\u3044\u308b\u8a3c\u62e0\u306f\u78ba\u8a8d\u3057\u3066\u3044\u307e\u305b\u3093\u3002\u305f\u3060\u3057\u3001Ivanti \u306e\u6700\u65b0\u306e\u30a2\u30c9\u30d0\u30a4\u30b6\u30ea\u30fc\u306f\u3001\u4fdd\u8b77\u3092\u5b8c\u5168\u306a\u3082\u306e\u3068\u3059\u308b\u305f\u3081\u3001\u305f\u3060\u3061\u306b\u63aa\u7f6e\u3092\u8b1b\u3058\u308b\u3053\u3068\u304c\u91cd\u8981\u3068\u3057\u3066\u3044\u307e\u3059\u3002\u72b6\u6cc1\u306f\u6d41\u52d5\u7684\u306a\u305f\u3081 Ivanti \u30b5\u30a4\u30c8\u3092\u983b\u7e41\u306b\u78ba\u8a8d\u3057\u3001\u6700\u65b0\u60c5\u5831\u3092\u5f97\u308b\u3088\u3046\u306b\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/span><\/p>\n<h2><span style=\"font-weight: 400;\"><strong>2 \u6708 3 \u65e5 JST \u66f4\u65b0<\/strong><\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Ivanti \u306f\u3001CVE-2024-21888 \u304a\u3088\u3073 CVE-2024-21893 \u3068\u3044\u3046 2 \u3064\u306e\u65b0\u3057\u3044\u8106\u5f31\u6027\u3092\u958b\u793a\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306f\u3044\u305a\u308c\u3082\u540c\u793e\u306e Connect Secure (9.x\u300122.x) \u304a\u3088\u3073 Policy Secure (9.x\u300122.x) \u88fd\u54c1\u306b\u5f71\u97ff\u3057\u307e\u3059\u3002CVE-2024-21893 \u306f Ivanti Neurons for ZTA \u306b\u3082\u5f71\u97ff\u3057\u307e\u3059\u3002Ivanti \u306f 2024 \u5e74 1 \u6708\u521d\u65ec\u4ee5\u964d\u3001\u5408\u8a08\u3067 4 \u4ef6\u3001\u6df1\u523b\u5ea6\u304c\u300c\u9ad8\u300d\u307e\u305f\u306f\u300c\u7dca\u6025\u300d\u306e\u8106\u5f31\u6027\u3092\u958b\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">2024\u5e74 1 \u6708 31 \u65e5\u3001\u7c73\u30b5\u30a4\u30d0\u30fc\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30a4\u30f3\u30d5\u30e9\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5c40 (CISA) \u306f\u3059\u3079\u3066\u306e\u7c73\u56fd\u9023\u90a6\u653f\u5e9c\u6a5f\u95a2\u306b\u5bfe\u3057<\/span>\u300c<span style=\"font-weight: 400;\">\u53ef\u53ca\u7684\u901f\u3084\u304b\u306b\u9045\u304f\u3068\u3082 2024 \u5e74 2 \u6708 2 \u65e5 (\u91d1) \u5348\u5f8c 11 \u6642 59 \u5206\u307e\u3067\u306b Ivanti Connect Secure \u304a\u3088\u3073 Ivanti Policy Secure \u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u88fd\u54c1\u306e\u5168\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u6a5f\u95a2\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u304b\u3089\u5207\u308a\u96e2\u3059\u3053\u3068<\/span>\u300d\u3068\u3044\u3046<a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">\u88dc\u8db3\u6307\u793a<\/span><\/a>\u3092\u51fa\u3057\u307e\u3057\u305f\u3002<\/p>\n<p><span style=\"font-weight: 400;\">Unit 42 \u306f\u5f15\u304d\u7d9a\u304d\u72b6\u6cc1\u3092\u76e3\u8996\u3057\u3066\u3044\u307e\u3059\u3002\u8ffd\u52a0\u306e\u60c5\u5831\u304c\u5165\u308a\u6b21\u7b2c\u3001\u672c\u8105\u5a01\u6982\u8981\u306f\u66f4\u65b0\u3055\u308c\u307e\u3059\u3002<\/span><\/p>\n<h2><a id=\"post-132058-_4lt92rr5muov\"><\/a>Ivanti \u6982\u8981<\/h2>\n<p>2024 \u5e74 1 \u6708 10 \u65e5\u3001<a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US\" target=\"_blank\" rel=\"noopener\">Ivanti<\/a> \u306f Ivanti Connect Secure (ICS) \u3068 Ivanti Policy Secure \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u88fd\u54c1\u306b\u5b58\u5728\u3059\u308b 2 \u3064\u306e\u65b0\u305f\u306a\u8106\u5f31\u6027\u3001<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-46805\" target=\"_blank\" rel=\"noopener\">CVE-2023-46805<\/a> \u3068 <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-21887\" target=\"_blank\" rel=\"noopener\">CVE-2024-21887<\/a> \u3068\u3092<a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US\" target=\"_blank\" rel=\"noopener\">\u958b\u793a<\/a>\u3057\u307e\u3057\u305f\u30021 \u3064\u3081\u306e CVE \u306f\u6df1\u523b\u5ea6\u304c\u300c\u9ad8 (High)\u300d\u306e\u8a8d\u8a3c\u30d0\u30a4\u30d1\u30b9\u306e\u8106\u5f31\u6027\u3067\u30012 \u3064\u3081\u306e CVE \u306f\u6df1\u523b\u5ea6\u304c\u300c\u7dca\u6025 (Critical)\u300d\u306e\u30b3\u30de\u30f3\u30c9 \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u306e\u8106\u5f31\u6027\u3067\u3059\u3002\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306f\u3001\u30b5\u30dd\u30fc\u30c8\u3055\u308c\u3066\u3044\u308b\u3059\u3079\u3066\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306e\u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u88fd\u54c1\u306b\u5f71\u97ff\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-weight: 400;\">Ivanti \u306f 2024 \u5e74 1 \u6708 31 \u65e5\u3001\u3055\u3089\u306b 2 \u4ef6\u306e\u8106\u5f31\u6027\u3001 <\/span><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-21888\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">CVE-2024-21888<\/span><\/a><span style=\"font-weight: 400;\"> \u304a\u3088\u3073 <\/span><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-21893\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">CVE-2024-21893<\/span><\/a><span style=\"font-weight: 400;\"> \u3092\u958b\u793a\u3057\u307e\u3057\u305f\u3002CVE-2024-21888 \u306f\u6df1\u523b\u5ea6\u304c\u300c\u9ad8 (High)\u300d\u306e\u7279\u6a29\u6607\u683c\u306e\u8106\u5f31\u6027\u3067\u3059\u3002CVE-2024-21893 \u306f\u6df1\u523b\u5ea6\u304c\u300c\u9ad8 (High)\u300d\u306e\u30b5\u30fc\u30d0\u30fc\u30b5\u30a4\u30c9 \u30ea\u30af\u30a8\u30b9\u30c8 \u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u306e\u8106\u5f31\u6027\u3067\u3001Ivanti Connect Secure \u306e SAML \u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306b\u5f71\u97ff\u3057\u307e\u3059\u3002\u5f8c\u8005\u306e\u8106\u5f31\u6027\u306f\u3001CVE-2023-46805 \u3068 CVE-2024-21887 \u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u7de9\u548c\u7b56\u3092\u30d0\u30a4\u30d1\u30b9\u3059\u308b\u306e\u306b\u5229\u7528\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">2024 \u5e74 2 \u6708 8 \u65e5 (PST)\u3001Ivanti \u306f 5 \u3064\u3081\u306e\u8106\u5f31\u6027\u3092\u516c\u958b\u3057\u307e\u3057\u305f\u3002CVE-2024-22024 \u306f\u6df1\u523b\u5ea6\u300cHigh (\u9ad8)\u300d\u306e\u8106\u5f31\u6027\u3067\u3059\u3002\u672c\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u3053\u3068\u306b\u3088\u308a\u3001\u653b\u6483\u8005\u306f\u8a8d\u8a3c\u306a\u3057\u3067\u7279\u5b9a\u306e\u5236\u9650\u3055\u308c\u305f\u30ea\u30bd\u30fc\u30b9\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">CVE-2024-21887 \u3068 CVE-2024-21893 \u3092\u9023\u9396\u3055\u305b\u3066\u4f7f\u3063\u305f\u5834\u5408\u3001\u653b\u6483\u8005\u306f\u3053\u308c\u3089\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3057\u3066\u3001\u5371\u6b86\u5316\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u4e0a\u3067\u3001\u8a8d\u8a3c\u306a\u3057\u3067\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002\u4e21\u8106\u5f31\u6027\u306f\u3069\u3061\u3089\u3082\u6982\u5ff5\u5b9f\u8a3c\u30b3\u30fc\u30c9 (PoC) \u304c\u516c\u958b\u3055\u308c\u3066\u304a\u308a\u3001\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u304c\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306b\u4f7f\u308f\u308c\u308b\u30ea\u30b9\u30af\u304c\u5897\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u3053\u308c\u3089 2 \u3064\u306e\u8ffd\u52a0 CVE \u306e\u958b\u793a\u3092\u53d7\u3051\u3001CISA \u306f\u3059\u3079\u3066\u306e\u7c73\u56fd\u9023\u90a6\u653f\u5e9c\u6a5f\u95a2\u306b\u5bfe\u3057<\/span>\u300c<span style=\"font-weight: 400;\">\u53ef\u53ca\u7684\u901f\u3084\u304b\u306b\u9045\u304f\u3068\u3082 2024 \u5e74 2 \u6708 2 \u65e5 (\u91d1) \u5348\u5f8c 11 \u6642 59 \u5206\u307e\u3067\u306b Ivanti Connect Secure \u304a\u3088\u3073 Ivanti Policy Secure \u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u88fd\u54c1\u306e\u5168\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u6a5f\u95a2\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u304b\u3089\u5207\u308a\u96e2\u3059\u3053\u3068<\/span>\u300d\u3068\u3044\u3046<a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">\u88dc\u8db3\u6307\u793a<\/span><\/a>\u3092\u51fa\u3057\u307e\u3057\u305f\u3002<\/p>\n<p><span style=\"font-weight: 400;\">Ivanti \u306f\u30015 \u3064\u306e CVE \u3059\u3079\u3066\u306b\u5bfe\u5fdc\u3059\u308b\u30d1\u30c3\u30c1\u306e\u516c\u958b\u3092\u958b\u59cb\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e CVE \u306b\u5bfe\u3059\u308b\u30d1\u30c3\u30c1\u304c\u307e\u3060\u63d0\u4f9b\u3055\u308c\u3066\u3044\u306a\u3044\u88fd\u54c1\u306b\u3064\u3044\u3066\u306f\u3001Ivanti \u306f\u30d1\u30c3\u30c1\u306e\u63d0\u4f9b\u304c\u3055\u308c\u308b\u307e\u3067\u306e\u9593\u3001<\/span><a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">\u56de\u907f\u7b56<\/span><\/a><span style=\"font-weight: 400;\">\u3092\u5b9f\u65bd\u3059\u308b\u3053\u3068\u3092\u63a8\u5968\u3057\u3066\u3044\u307e\u3059\u3002Ivanti \u306f<\/span><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Recovery-Steps-Related-to-CVE-2023-46805-and-CVE-2024-21887?language=en_US\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306b\u95a2\u9023\u3059\u308b\u5fa9\u65e7\u624b\u9806\u306e\u30ca\u30ec\u30c3\u30b8\u30d9\u30fc\u30b9\u8a18\u4e8b<\/span><\/a><span style=\"font-weight: 400;\">\u3082\u7528\u610f\u3057\u3066\u304a\u308a\u3001\u305d\u306e\u306a\u304b\u3067\u3001\u540c\u793e\u306e Integrity Checker Tool \u306e\u30b9\u30ad\u30e3\u30f3\u7d50\u679c\u306b\u3082\u3068\u3065\u3044\u3066\u76e3\u8996\u3059\u3079\u304d\u30a2\u30fc\u30c6\u30a3\u30d5\u30a1\u30af\u30c8 (\u4fb5\u5bb3\u6307\u6a19\u3001\u75d5\u8de1) \u3092\u5927\u304d\u304f\u53d6\u308a\u4e0a\u3052\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3089\u304c\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u3092\u7a4d\u6975\u7684\u306b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3057\u3066\u3044\u308b\u3053\u3068\u304b\u3089\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u306e\u958b\u767a\u306b\u5f79\u7acb\u3066\u308b\u305f\u3081\u3001\u30c7\u30d0\u30a4\u30b9\u306e\u9732\u51fa (\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u306b\u76f4\u63a5\u516c\u958b\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3001\u30a8\u30af\u30b9\u30dd\u30fc\u30b8\u30e3\u30fc) \u306a\u3089\u3073\u306b\u95a2\u9023\u304c\u7591\u308f\u308c\u308b\u8105\u5a01\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u95a2\u3059\u308b\u79c1\u305f\u3061\u306e\u89b3\u6e2c\u5185\u5bb9\u3092\u672c\u7a3f\u306b\u3066\u5171\u6709\u3057\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u6700\u521d\u306b\u958b\u793a\u3055\u308c\u305f 2 \u3064\u306e\u8106\u5f31\u6027\u3001CVE-2023-46805 \u3068 CVE-2024-21887 \u306f\u3001\u5c11\u306a\u304f\u3068\u3082 2023 \u5e74 12 \u6708\u521d\u65ec\u4ee5\u964d\u3001\u56fd\u5bb6\u30ec\u30d9\u30eb\u306e\u8105\u5a01\u304b\u3089\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u307e\u3067\u3001\u3055\u307e\u3056\u307e\u306a\u30ec\u30d9\u30eb\u306e\u8105\u5a01\u8005\u306b\u3088\u3063\u3066\u7a4d\u6975\u7684\u306b\u60aa\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u9ad8\u3044\u30ec\u30d9\u30eb\u3067\u306f\u3001\u89b3\u6e2c\u3055\u308c\u305f\u6226\u8853\u30fb\u6280\u8853\u30fb\u624b\u9806 (TTP) \u304c Unit 42 \u304c\u8abf\u67fb\u3057\u3066\u304d\u305f\u904e\u53bb\u306e\u4e2d\u56fd\u3068\u95a2\u9023\u3059\u308b APT \u4e8b\u4f8b\u3068\u4e00\u81f4\u3057\u3066\u304a\u308a\u3001<\/span><span style=\"font-weight: 400;\">\u89b3\u6e2c\u3055\u308c\u305f\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u304c\u4e2d\u56fd\u306e\u56fd\u5bb6\u30ec\u30d9\u30eb\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306b\u5e30\u5c5e\u3059\u308b<\/span>\u53ef\u80fd\u6027\u3092\u88cf\u4ed8\u3051\u308b\u3082\u306e\u3067\u3057\u305f\u3002<\/p>\n<p><span style=\"font-weight: 400;\">\u65b0\u305f\u306b\u958b\u793a\u3055\u308c\u305f 2 \u3064 CVE \u306b\u3064\u3044\u3066\u3044\u3048\u3070\u3001\u79c1\u305f\u3061\u306f CVE-2024-21888 \u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u8a3c\u62e0\u306f\u307e\u3060\u89b3\u6e2c\u3057\u3066\u3044\u307e\u305b\u3093\u3002\u305f\u3060\u3057 Ivanti \u306f\u3001CVE-2024-21893 \u306b\u3088\u308b\u5f71\u97ff\u306e\u6a19\u7684\u3068\u306a\u3063\u305f\u9867\u5ba2\u3092\u8907\u6570\u8a8d\u8b58\u3057\u3066\u3044\u308b\u3068\u5831\u544a\u3057\u3066\u3044\u307e\u3059\u3002\u3088\u308a\u591a\u304f\u306e\u60c5\u5831\u304c\u5165\u624b\u53ef\u80fd\u306b\u306a\u308b\u306b\u3064\u308c\u3001\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u304c\u3088\u308a\u5e83\u304f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3055\u308c\u308b\u3088\u3046\u306b\u306a\u308b\u3053\u3068\u3092\u3001\u79c1\u305f\u3061\u306f\u9ad8\u3044\u78ba\u5ea6\u3067\u8a55\u4fa1\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u3053\u306e2\u3064\u306e Ivanti \u88fd\u54c1\u306f\u5e83\u304f\u4f7f\u308f\u308c\u3066\u3044\u307e\u3059\u3002Unit 42 \u306f 2024 \u5e74 1 \u6708 26 \u65e5\u304b\u3089 30 \u65e5\u306b\u304b\u3051\u3066\u3001145 \u30ab\u56fd\u3067 28,474 \u4ef6\u3001\u9732\u51fa\u3057\u305f Connect Secure \u3068 Policy Secure \u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f\u307e\u305f\u3001\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306e\u95a2\u4e0e\u304c\u78ba\u8a8d\u3055\u308c\u305f\u3044\u304f\u3064\u304b\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u6848\u4ef6\u306b\u3082\u5f93\u4e8b\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u79c1\u305f\u3061\u306f\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc (\u304a\u305d\u3089\u304f\u56fd\u5bb6\u30ec\u30d9\u30eb) \u304c\u3001\u30b9\u30d1\u30a4\u6d3b\u52d5\u3092\u76ee\u7684\u3068\u3057\u3001\u6a19\u7684\u74b0\u5883\u3078\u306e\u521d\u671f\u30a2\u30af\u30bb\u30b9 \u30d9\u30af\u30c8\u30eb\u3068\u3057\u3066\u3001\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306e\u5f71\u97ff\u3092\u53d7\u3051\u308b\u30c7\u30d0\u30a4\u30b9\u3092\u72d9\u3063\u3066\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3057\u7d9a\u3051\u308b\u3082\u306e\u3068\u300c\u4e2d\u300d\u304b\u3089\u300c\u9ad8\u300d\u306e\u78ba\u5ea6\u3067\u8a55\u4fa1\u3057\u3066\u3044\u307e\u3059\u3002\u79c1\u305f\u3061\u306f\u3001\u91d1\u92ad\u7684\u52d5\u6a5f\u3092\u3082\u3061\u3001\u6280\u8853\u529b\u304c\u9ad8\u304f\u3001\u5341\u5206\u306a\u8cc7\u91d1\u3092\u6301\u3064\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u3089\u304c\u3001\u3053\u306e\u30d9\u30af\u30c8\u30eb\u3092\u7d4c\u7531\u3057\u3066\u7d44\u7e54\u3078\u306e\u4fb5\u5bb3\u3092\u8a66\u307f\u308b\u3053\u3068\u3092\u3001\u4e2d\u7a0b\u5ea6\u306e\u78ba\u5ea6\u3067\u8a55\u4fa1\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001\u4ee5\u4e0b\u306e\u65b9\u6cd5\u3067 CVE-2023-46805 \u3068 CVE-2024-21887 \u306e\u8106\u5f31\u6027\u306b\u5bfe\u3057\u3066\u3088\u308a\u78ba\u5b9f\u306b\u4fdd\u8b77\u3055\u308c\u3001\u307e\u305f\u7de9\u548c\u7b56\u3092\u5b9f\u65bd\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs-cortex.paloaltonetworks.com\/p\/XPANSE\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Cortex Xpanse<\/span><\/a><span style=\"font-weight: 400;\"> \u3092\u3054\u5229\u7528\u306e\u304a\u5ba2\u69d8\u306f\u3001\u30a2\u30bf\u30c3\u30af \u30b5\u30fc\u30d5\u30a7\u30b9 (\u653b\u6483\u5bfe\u8c61\u9818\u57df) \u30eb\u30fc\u30eb\u300cIvanti Connect Secure\u300d\u304a\u3088\u3073\u300cIvanti Policy Secure\u300d\u3092\u901a\u3058\u3001\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u306b\u516c\u958b\u3055\u308c\u305f\u5f71\u97ff\u3092\u53d7\u3051\u308b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u7279\u5b9a\u3067\u304d\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs.paloaltonetworks.com\/ngfw\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb<\/span><\/a><span style=\"font-weight: 400;\">\u3067<\/span><a href=\"https:\/\/docs.paloaltonetworks.com\/advanced-threat-prevention\/administration\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\"> Advanced Threat Prevention <\/span><\/a>\u306e<span style=\"font-weight: 400;\">\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30b5\u30d6\u30b9\u30af\u30ea\u30d7\u30b7\u30e7\u30f3\u3092\u6709\u52b9\u306b\u3057\u3066\u3044\u308b\u5834\u5408\u3001Threat Prevention \u306e\u30b7\u30b0\u30cd\u30c1\u30e3\u30fc\u3092\u901a\u3058\u305f\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u304c\u653b\u6483\u9632\u6b62\u306b\u5f79\u7acb\u3061\u307e\u3059\u3002Advanced Threat Prevention \u306f\u3001\u8106\u5f31\u6027\u306e\u4e00\u822c\u958b\u793a\u306b\u5148\u3093\u3058\u3066\u3053\u306e\u8106\u5f31\u6027\u3092\u30d7\u30ed\u30a2\u30af\u30c6\u30a3\u30d6\u306b\u691c\u51fa\u3067\u304d\u307e\u3057\u305f\u3002<\/span><\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/docs.paloaltonetworks.com\/advanced-wildfire\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Advanced WildFire<\/span><\/a><span style=\"font-weight: 400;\"> \u306b\u306f\u3001\u3053\u308c\u3089\u306e\u653b\u6483\u306b\u4f7f\u7528\u3055\u308c\u308b\u30af\u30ea\u30d7\u30c8\u30de\u30a4\u30ca\u30fc\u306e\u691c\u51fa\u304c\u8ffd\u52a0\u3055\u308c\u307e\u3057\u305f\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs.paloaltonetworks.com\/pan-os\/10-1\/pan-os-new-features\/url-filtering-features\/advanced-url-filtering\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Advanced URL Filtering<\/span><\/a><span style=\"font-weight: 400;\"> \u3068 <\/span><a href=\"https:\/\/docs.paloaltonetworks.com\/dns-security\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/a><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"> \u306f\u540c\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305f\u65e2\u77e5\u306e\u60aa\u610f\u306e\u3042\u308b\u30c9\u30e1\u30a4\u30f3\u3092\u60aa\u610f\u304c\u3042\u308b\u3082\u306e\u3068\u3057\u3066\u5206\u985e\u3057\u307e\u3059\u3002<\/span><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs.paloaltonetworks.com\/pan-os\/10-1\/pan-os-new-features\/url-filtering-features\/advanced-url-filtering\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Advanced URL Filtering<\/span><\/a> <span style=\"font-weight: 400;\">\u306f\u3001\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3068\u30b9\u30ad\u30e3\u30f3\u306e\u8a66\u307f\u3092 Scanning Activity (\u30b9\u30ad\u30e3\u30f3 \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3) \u3068\u3057\u3066\u5206\u985e\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs-cortex.paloaltonetworks.com\/p\/XDR\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Cortex XDR<\/span><\/a><span style=\"font-weight: 400;\"> \u304a\u3088\u3073 <\/span><a href=\"https:\/\/docs-cortex.paloaltonetworks.com\/p\/XSIAM\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Cortex XSIAM <\/span><\/a> <span style=\"font-weight: 400;\">\u306f\u591a\u5c64\u4fdd\u8b77\u306e\u30a2\u30d7\u30ed\u30fc\u30c1\u306b\u3088\u308a\u3001\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u5f8c\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u304b\u3089\u306e\u4fdd\u8b77\u306b\u5f79\u7acb\u3061\u307e\u3059\u3002<\/span><\/li>\n<li aria-level=\"1\">\u307e\u305f\u3001<a href=\"https:\/\/start.paloaltonetworks.jp\/contact-unit42.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Unit 42\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8 \u30ec\u30b9\u30dd\u30f3\u30b9 \u30c1\u30fc\u30e0<\/span><\/a>\u306f\u3001\u4fb5\u5bb3\u3092\u53d7\u3051\u305f\u5834\u5408\u306e\u652f\u63f4\u3084\u3001\u304a\u5ba2\u69d8\u306e\u30ea\u30b9\u30af\u4f4e\u6e1b\u306e\u305f\u3081\u306e\u4e8b\u524d\u30b5\u30a4\u30d0\u30fc\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6e96\u5099\u72b6\u6cc1\u8a55\u4fa1\u3092\u884c\u3063\u3066\u3044\u307e\u3059\u3002<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Ivanti \u306f\u307e\u305f\u3001\u30d1\u30c3\u30c1\u9069\u7528\u524d\u5f8c\u306b External Integrity Checker \u306e\u30b9\u30ad\u30e3\u30f3\u5b9f\u884c\u3092\u63a8\u5968\u3057\u3066\u3044\u307e\u3059\u3002Ivanti \u306f\u300c\u3053\u306e\u30b9\u30ad\u30e3\u30f3\u304c\u30af\u30ea\u30fc\u30f3\u3067\u3042\u308c\u3070\u3001\u9867\u5ba2\u306f\u901a\u5e38\u306e\u30b5\u30fc\u30d3\u30b9\u6642\u9593\u5185\u3067\u30a2\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u306e\u5de5\u5834\u51fa\u8377\u6642\u30ea\u30bb\u30c3\u30c8\u3092\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3067\u304d\u308b\u300d\u3068\u8ff0\u3079\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u540c\u793e\u306f\u300c\u30d1\u30c3\u30c1\u306e\u9069\u7528\u524d\u306a\u3044\u3057\u5f8c\u306b\u30b9\u30ad\u30e3\u30f3\u304c\u967d\u6027\u3067\u3042\u3063\u305f\u5834\u5408\u3001\u9867\u5ba2\u306f\u5de5\u5834\u51fa\u8377\u6642\u30ea\u30bb\u30c3\u30c8\u3092\u884c\u3044\u3001\u3055\u3089\u306b<\/span><a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306b\u95a2\u3059\u308b\u30ca\u30ec\u30c3\u30b8\u30d9\u30fc\u30b9\u306e\u8a18\u4e8b\u306e\u6307\u793a<\/span><\/a>\u306b\u5f93\u3046\u5fc5\u8981\u304c\u3042\u308b\u300d\u3068\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-weight: 400;\">\u672c\u4ef6\u306f\u72b6\u6cc1\u306e\u5909\u5316\u304c\u65e9\u3044\u3053\u3068\u304b\u3089\u3001Ivanti \u306b\u3088\u308b\u52e7\u544a\u3092\u983b\u7e41\u306b\u78ba\u8a8d\u3059\u308b\u3053\u3068\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002<\/span><\/p>\n<p><iframe loading=\"lazy\" width=\"100%\" height=\"200\" frameborder=\"0\" scrolling=\"no\" src=\"https:\/\/playlist.megaphone.fm\/?e=CYBW7473450221\"><\/iframe><\/p>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<td style=\"width: 35%;\"><b>\u672c\u7a3f\u3067\u6271\u3046\u8106\u5f31\u6027<\/b><\/td>\n<td style=\"width: 100%;\"><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/cve-2023-46805-ja\/\" target=\"_blank\" rel=\"noopener\"><b>CVE-2023-46805<\/b><\/a>, <strong><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/cve-2024-21887-ja\/\" target=\"_blank\" rel=\"noopener\">CVE-2024-21887<\/a>, <span style=\"font-weight: 400;\"><strong><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/cve-2024-21888-ja\/\" target=\"_blank\" rel=\"noopener\">CVE-2024-21888<\/a><\/strong>, <strong><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/cve-2024-21893-ja\/\" target=\"_blank\" rel=\"noopener\">CVE-2024-21893<\/a>, <a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/cve-2024-22024-ja\/\" target=\"_blank\" rel=\"noopener\">CVE-2024-22024<\/a><\/strong><\/span><\/strong><\/td>\n<\/tr>\n<\/thead>\n<\/table>\n<h2><a id=\"post-132058-_wven14kmgum2\"><\/a>Ivanti \u306e\u8106\u5f31\u6027\u306e\u8a73\u7d30<\/h2>\n<p><span style=\"font-weight: 400;\">1 \u3064\u3081\u306e\u8106\u5f31\u6027 CVE-2023-46805 \u306f\u3001\u5168\u30b5\u30dd\u30fc\u30c8\u5bfe\u8c61\u30d0\u30fc\u30b8\u30e7\u30f3\u306e Ivanti Connect Secure \u3068 Ivanti Policy Secure (\u30d0\u30fc\u30b8\u30e7\u30f3 9.x \u304a\u3088\u3073 22.x) \u306e Web \u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306b\u5b58\u5728\u3059\u308b\u8a8d\u8a3c\u30d0\u30a4\u30d1\u30b9\u306e\u8106\u5f31\u6027\u3067\u3059\u3002\u3053\u306e\u8106\u5f31\u6027\u306b\u3088\u308a\u3001\u30ea\u30e2\u30fc\u30c8\u306b\u3044\u308b\u653b\u6483\u8005\u306f\u3001\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb \u30c1\u30a7\u30c3\u30af\u3092\u30d0\u30a4\u30d1\u30b9\u3057\u3001\u5236\u9650\u3055\u308c\u305f\u30ea\u30bd\u30fc\u30b9\u306b\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">2 \u3064\u3081\u306e\u8106\u5f31\u6027 CVE-2024-21887 \u306f\u3001Ivanti Connect Secure \u3068 Ivanti Policy Secure (\u30d0\u30fc\u30b8\u30e7\u30f3 9.x \u304a\u3088\u3073 22.x) \u306e\u8907\u6570\u306e Web \u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306b\u5b58\u5728\u3059\u308b\u30b3\u30de\u30f3\u30c9 \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u306e\u8106\u5f31\u6027\u3067\u3059\u3002\u3053\u306e\u8106\u5f31\u6027\u306f\u3001\u8a8d\u8a3c\u3055\u308c\u305f\u7ba1\u7406\u8005\u304c\u3001\u7279\u5225\u306b\u7d30\u5de5\u3057\u305f\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9001\u4fe1\u3057\u3001\u30a2\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u4e0a\u3067\u4efb\u610f\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u3092\u53ef\u80fd\u306b\u3057\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">3 \u3064\u3081\u306e\u8106\u5f31\u6027 CVE-2024-21888 \u306f\u3001Ivanti Connect Secure (9.x, 22.x) \u304a\u3088\u3073 Ivanti Policy Secure (9.x, 22.x) \u306e Web \u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306b\u304a\u3051\u308b\u7279\u6a29\u6607\u683c\u306e\u8106\u5f31\u6027\u3067\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u7ba1\u7406\u8005\u306e\u7279\u6a29\u306b\u6607\u683c\u53ef\u80fd\u3067\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">4 \u3064\u3081\u306e\u8106\u5f31\u6027 CVE-2024-21893 \u306f\u3001Ivanti Connect Secure (9.x, 22.x)\u3001Ivanti Policy Secure (9.x, 22.x)\u3001Ivanti Neurons for ZTA \u306e SAML \u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306b\u5b58\u5728\u3059\u308b\u30b5\u30fc\u30d0\u30fc\u30b5\u30a4\u30c9 \u30ea\u30af\u30a8\u30b9\u30c8 \u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u306e\u8106\u5f31\u6027\u3067\u3001\u653b\u6483\u8005\u306f\u8a8d\u8a3c\u306a\u3057\u3067\u7279\u5b9a\u306e\u5236\u9650\u3055\u308c\u305f\u30ea\u30bd\u30fc\u30b9\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">5 \u3064\u3081\u306e\u8106\u5f31\u6027\u3067\u3042\u308b<\/span><span style=\"font-weight: 400;\"> CVE-2024-22024 <\/span><span style=\"font-weight: 400;\">\u306f\u3001Ivanti Connect Secure (9.x, 22.x)\u3001Ivanti Policy Secure (9.x, 22.x)\u3001ZTA \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u88fd\u54c1\u306e SAML \u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306b\u5b58\u5728\u3059\u308b XML \u5916\u90e8\u5b9f\u4f53\u53c2\u7167 (XML eXternal Entity: XXE) \u306e\u8106\u5f31\u6027\u3067\u3059\u3002\u3053\u308c\u304c\u60aa\u7528\u3055\u308c\u308b\u3068\u3001\u653b\u6483\u8005\u306f\u8a8d\u8a3c\u306a\u3057\u3067\u7279\u5b9a\u306e\u5236\u9650\u3055\u308c\u305f\u30ea\u30bd\u30fc\u30b9\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/span><\/p>\n<h2><a id=\"post-132058-_50343o6a6han\"><\/a>Ivanti \u88fd\u54c1\u306b\u5bfe\u3059\u308b\u73fe\u5728\u306e\u653b\u6483\u30b9\u30b3\u30fc\u30d7<\/h2>\n<p><span style=\"font-weight: 400;\">Ivanti \u306f\u3001\u540c\u793e\u88fd\u54c1\u304c\u4e16\u754c\u4e2d\u3067<\/span> <a href=\"https:\/\/www.ivanti.com\/customers\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">4 \u4e07\u793e\u4ee5\u4e0a\u306e\u4f01\u696d\u306b\u5229\u7528<\/span><\/a>\u3055\u308c\u3066\u3044\u308b\u3068\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-weight: 400;\">Unit 42 \u306f 2024 \u5e74 1 \u6708 26 \u65e5\u304b\u3089 30 \u65e5\u306b\u304b\u3051\u3066\u3001145 \u30ab\u56fd\u3067 28,474 \u4ef6\u3001\u9732\u51fa\u3057\u305f Connect Secure \u3068 Policy Secure \u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002\u56f3 1 \u306f<\/span><span style=\"font-weight: 400;\">\u5f71\u97ff\u3092\u53d7\u3051\u305f\u5730\u57df\u3092\u793a\u3057\u305f\u5730\u56f3\u3067\u3059\u3002<\/span><span style=\"font-weight: 400;\">\u4e0a\u4f4d 10 \u30ab\u56fd\u3067\u4e16\u754c\u5168\u4f53\u306e\u30a8\u30af\u30b9\u30dd\u30fc\u30b8\u30e3\u30fc\u306e 70\uff05 \u8fd1\u304f\u3092\u5360\u3081\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059 (Connect Secure \u304a\u3088\u3073 Policy Secure \u30c7\u30d0\u30a4\u30b9\u306e\u89b3\u6e2c\u306b\u57fa\u3065\u304f)\u3002<\/span><\/p>\n<figure id=\"attachment_132387\" aria-describedby=\"caption-attachment-132387\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132387 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Global-Distribution-Jan-30.png\" alt=\"\u753b\u50cf 1 \u306f\u3001Ivanti Connect Secure \u30c7\u30d0\u30a4\u30b9\u306e\u30b0\u30ed\u30fc\u30d0\u30eb\u3067\u306e\u5206\u5e03\u3092\u8868\u3057\u305f\u30d2\u30fc\u30c8\u30de\u30c3\u30d7\u3067\u3059\u30022024 \u5e74 1 \u6708 30 \u65e5\u73fe\u5728\u306e\u5185\u5bb9\u3067\u3059\u3002\u6700\u3082\u5206\u5e03\u304c\u591a\u3044\u306e\u306f\u7c73\u56fd\u3067\u3059\u3002\" width=\"900\" height=\"557\" \/><figcaption id=\"caption-attachment-132387\" class=\"wp-caption-text\">\u56f3 1. Ivanti Connect Secure \u304a\u3088\u3073 Policy Secure \u30c7\u30d0\u30a4\u30b9\u306e\u30b0\u30ed\u30fc\u30d0\u30eb\u3067\u306e\u5206\u5e03 (2024 \u5e74 1 \u6708 30 \u65e5\u73fe\u5728)\u3002Cortex Xpanse \u306e Internet Landscape Intelligence \u306b\u57fa\u3065\u304f<\/figcaption><\/figure>\n<p><span style=\"font-weight: 400;\">Unit 42 \u306f 2024 \u5e74 1 \u6708 23 \u65e5\u73fe\u5728\u300144 \u30ab\u56fd\u3067 610 \u53f0\u306e\u4fb5\u5bb3\u3055\u308c\u305f Connect Secure \u3068 Policy Secure \u30c7\u30d0\u30a4\u30b9\u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u89b3\u6e2c\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u60c5\u5831\u306f\u3001\u6700\u521d\u306e 2 \u3064\u306e CVE \u3067\u3042\u308b CVE-2023-46805 \u3068 CVE-2024-21887 \u3092\u30ab\u30d0\u30fc\u3057\u3066\u3044\u307e\u3059\u3002\u56f3 2 \u306f\u5f71\u97ff\u3092\u53d7\u3051\u305f\u5730\u57df\u3092\u793a\u3057\u305f\u5730\u56f3\u3067\u3059\u3002\u4e0a\u4f4d 10 \u30ab\u56fd\u3067\u3001\u4e16\u754c\u5168\u4f53\u3067\u89b3\u6e2c\u3055\u308c\u305f\u4fb5\u5bb3\u30c7\u30d0\u30a4\u30b9\u306e 70\uff05 \u8fd1\u304f\u3092\u5360\u3081\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<figure id=\"attachment_132389\" aria-describedby=\"caption-attachment-132389\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132389 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Global-Distribution-Jan-23.png\" alt=\"\u753b\u50cf 2 \u306f\u3001Ivanti Connect Secure \u30c7\u30d0\u30a4\u30b9\u306e\u30b0\u30ed\u30fc\u30d0\u30eb\u3067\u306e\u5206\u5e03\u3092\u8868\u3057\u305f\u30d2\u30fc\u30c8\u30de\u30c3\u30d7\u3067\u3059\u30022024 \u5e74 1 \u6708 23 \u65e5\u73fe\u5728\u306e\u5185\u5bb9\u3067\u3059\u3002\u6700\u3082\u5206\u5e03\u304c\u591a\u3044\u306e\u306f\u7c73\u56fd\u3067\u3059\u3002\" width=\"900\" height=\"556\" \/><figcaption id=\"caption-attachment-132389\" class=\"wp-caption-text\">\u56f3 2. \u4fb5\u5bb3\u3055\u308c\u305f Ivanti \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u88fd\u54c1\u306e\u30b0\u30ed\u30fc\u30d0\u30eb\u3067\u306e\u5206\u5e03 (2024 \u5e74 1 \u6708 23 \u65e5\u73fe\u5728)Cortex Xpanse \u306e Internet Landscape Intelligence \u306b\u57fa\u3065\u304f<\/figcaption><\/figure>\n<p><span style=\"font-weight: 400;\">\u56f3 3 \u306b\u793a\u3059\u3088\u3046\u306b\u3001\u79c1\u305f\u3061\u306e\u30c6\u30ec\u30e1\u30c8\u30ea\u30fc\u304b\u3089\u306f\u3001\u6700\u521d\u306e 2 \u3064\u306e Ivanti \u306e\u8106\u5f31\u6027\u306b\u5bfe\u3059\u308b\u30b9\u30ad\u30e3\u30f3\u3068\u30d7\u30ed\u30fc\u30d6\u304c\u3001\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306e\u958b\u793a\u7fcc\u65e5\u306e 2024 \u5e74 1 \u6708 13 \u65e5\u304b\u3089\u3001\u9855\u8457\u306b\u5897\u52a0\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u660e\u3089\u304b\u306b\u306a\u308a\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f\u3001\u3053\u308c\u3089\u306e\u653b\u6483\u306b\u95a2\u4e0e\u3057\u305f 92 \u306e IPv4 \u30a2\u30c9\u30ec\u30b9\u3092\u78ba\u8a8d\u3057\u3066\u3044\u307e\u3059 (\u672c\u8105\u5a01\u6982\u8981\u306e<a href=\"#ivanti-2024-appendix\">\u4ed8\u9332<\/a>\u306b\u8a18\u8f09\u3057\u307e\u3059)\u3002<\/span><\/p>\n<figure id=\"attachment_132430\" aria-describedby=\"caption-attachment-132430\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132430 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Ivanti-F3-Scanning-Activities-Revised.png\" alt=\"CVE-2023-46805 \u304a\u3088\u3073 CVE-2024-21887 \u3092\u6a19\u7684\u3068\u3059\u308b\u30b9\u30ad\u30e3\u30f3 \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3 (1 \u6708 1 \u65e5\u301c1 \u6708 31 \u65e5)17 \u65e5\u304b\u3089\u5f37\u3044\u4e0a\u6607\u30c8\u30ec\u30f3\u30c9\u304c\u898b\u3089\u308c\u307e\u3059\u3002 \" width=\"900\" height=\"446\" \/><figcaption id=\"caption-attachment-132430\" class=\"wp-caption-text\">\u56f3 3. CVE-2023-46805 \u304a\u3088\u3073 CVE-2024-21887 \u3092\u6a19\u7684\u3068\u3059\u308b\u30b9\u30ad\u30e3\u30f3 \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3Cortex Xpanse \u306e Internet Landscape Intelligence \u306b\u57fa\u3065\u304f<\/figcaption><\/figure>\n<p><span style=\"font-weight: 400;\">\u3053\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u3001\u7c73\u56fd\u3001\u82f1\u56fd\u3001EU\u3001\u30ab\u30ca\u30c0\u3001\u30aa\u30fc\u30b9\u30c8\u30e9\u30ea\u30a2\u3001\u30b7\u30f3\u30ac\u30dd\u30fc\u30eb\u3001\u65e5\u672c\u305d\u306e\u307b\u304b\u306e\u56fd\u3005\u306e\u4e8b\u696d\u4f53\u3092\u6a19\u7684\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u6a19\u7684\u306f\u3055\u307e\u3056\u307e\u306a\u30bb\u30af\u30bf\u30fc\u306b\u307e\u305f\u304c\u3063\u3066\u304a\u308a\u3001\u305d\u306e\u306a\u304b\u306b\u306f\u3001\u30d8\u30eb\u30b9\u30b1\u30a2\u3001\u9271\u696d\u3001\u30a8\u30cd\u30eb\u30ae\u30fc\u3001\u98df\u54c1\u30fb\u8fb2\u696d\u3001\u30c6\u30af\u30ce\u30ed\u30b8\u30fc\u3001\u653f\u5e9c\u306a\u3069\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u79c1\u305f\u3061\u306f\u3001\u3053\u308c\u3089\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u307b\u3068\u3093\u3069\u304c\u3001\u65e5\u548c\u898b\u7684\u3067\u3001\u6a19\u7684\u3092\u7d5e\u3089\u305a\u3001\u81ea\u52d5\u5316\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u8a66\u884c\u3067\u3042\u3063\u305f\u3082\u306e\u3068\u9ad8\u3044\u78ba\u5ea6\u3067\u8a55\u4fa1\u3057\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u3057\u4e00\u90e8\u306e\u8a66\u307f\u306f\u7279\u5b9a\u306e\u4e8b\u696d\u4f53\u3092\u6a19\u7684\u3068\u3057\u3066\u3044\u308b\u3088\u3046\u3067\u3059\u3002<\/span><br \/>\n<a id=\"ivanti-2024-IRcases\"><\/a><\/p>\n<h3>Unit 42 \u306b\u3088\u308b\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u4e8b\u4f8b<\/h3>\n<p><span style=\"font-weight: 400;\">Ivanti \u306e\u8106\u5f31\u6027\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u306f\u3001\u72ec\u7acb\u3057\u305f\u653b\u6483\u6ce2\u304c 3 \u56de\u767a\u751f\u3057\u307e\u3057\u305f\u3002\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u6700\u521d\u306e\u653b\u6483\u6ce2\u306f\u3001\u5c11\u306a\u304f\u3068\u3082 2023 \u5e74 12 \u6708\u521d\u3081\u304b\u3089\u3001Volexity \u304c\u6700\u521d\u306e\u30d6\u30ed\u30b0\u8a18\u4e8b\u3092\u767a\u8868\u3057\u305f 2024 \u5e74 1 \u6708 10 \u65e5\u307e\u3067\u7d9a\u3044\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u306e\u653b\u6483\u306f\u6a19\u7684\u578b\u306e\u305d\u308c\u3067\u3001\u8907\u6570\u306e\u30ab\u30b9\u30bf\u30e0 Web \u30b7\u30a7\u30eb\u3068\u30e9\u30c6\u30e9\u30eb \u30e0\u30fc\u30d6\u3092\u7279\u5fb4\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002Unit 42 \u306f\u3001\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u306e\u653b\u6483\u6ce2\u306b\u5bfe\u5fdc\u3059\u308b\u3068\u8003\u3048\u3089\u308c\u308b\u8105\u5a01\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u4e8b\u4f8b\u306b\u5bfe\u5fdc\u3057\u307e\u3057\u305f\u3002 <\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u305d\u306e\u306a\u304b\u3067\u306f Volexity \u306e\u30d6\u30ed\u30b0\u8a18\u4e8b\u306b\u3066\u8ad6\u3058\u3089\u308c\u3066\u3044\u305f\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3068\u540c\u69d8\u306b\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u4ee5\u4e0b\u306e\u6d3b\u52d5\u3092\u884c\u3063\u3066\u3044\u308b\u3088\u3046\u3059\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u6f0f\u51fa\u306e\u524d\u306b 7-Zip \u3092\u4f7f\u3063\u3066<\/span> <span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">NTDS.dit<\/span><span style=\"font-weight: 400;\"> \u3092\u542b\u3080\u30d5\u30a1\u30a4\u30eb\u3092\u30a2\u30fc\u30ab\u30a4\u30d6\u3059\u308b<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows \u306e\u30bf\u30b9\u30af\u30de\u30cd\u30fc\u30b8\u30e3 (<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Taskmgr.exe<\/span><span style=\"font-weight: 400;\">) \u3092\u4f7f\u3063\u3066 LSASS \u30d7\u30ed\u30bb\u30b9\u306e\u30e1\u30e2\u30ea\u30fc \u30c0\u30f3\u30d7\u3092\u751f\u6210\u3059\u308b<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u30ea\u30e2\u30fc\u30c8 \u30c7\u30b9\u30af\u30c8\u30c3\u30d7 \u30d7\u30ed\u30c8\u30b3\u30eb (RDP) \u3092\u4ecb\u3057\u305f\u30e9\u30c6\u30e9\u30eb \u30e0\u30fc\u30d6<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u30ed\u30b0\u306e\u524a\u9664<\/span><\/li>\n<li aria-level=\"1\"><span style=\"font-weight: 400;\">\u5371\u6b86\u5316\u3057\u305f\u30b5\u30dd\u30fc\u30c8\u5bfe\u8c61\u5916\u306e Cyberoam \u4eee\u60f3\u30d7\u30e9\u30a4\u30d9\u30fc\u30c8 \u30cd\u30c3\u30c8\u30ef\u30fc\u30af (VPN) \u30a2\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u3092\u30b3\u30de\u30f3\u30c9 &amp; \u30b3\u30f3\u30c8\u30ed\u30fc\u30eb (C2) \u306b\u5229\u7528<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">\u307e\u305f\u79c1\u305f\u3061\u306f Volexity \u306b\u3088\u308b\u30d6\u30ed\u30b0\u306e\u6295\u7a3f\u5f8c\u3001Mandiant \u304c\u6700\u521d\u306b\u5831\u544a\u3057\u305f THINSPOOL \u30a4\u30f3\u30b9\u30c8\u30fc\u30eb \u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3\/\u30c9\u30ed\u30c3\u30d1\u30fc\u306e\u5b58\u5728\u3082\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u7b2c 2 \u6ce2\u306f\u30012024 \u5e74 1 \u6708 10 \u65e5\u306e Volexity \u306e\u6700\u521d\u306e\u30d6\u30ed\u30b0\u8a18\u4e8b\u306e\u5f8c\u306b\u59cb\u307e\u3063\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u653b\u6483\u6ce2\u306f\u3001\u65b0\u305f\u306a\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u53c2\u5165\u306b\u3088\u308a\u3001\u6a19\u7684\u578b\u306e\u653b\u6483\u304b\u3089\u4e0d\u7279\u5b9a\u591a\u6570\u3078\u306e\u653b\u6483\u306b\u30b7\u30d5\u30c8\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u7279\u5fb4\u3067\u3059\u3002\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Unit 42 \u3067\u306f\u7b2c 2 \u6ce2\u306b\u5bfe\u5fdc\u3059\u308b\u3068\u601d\u308f\u308c\u308b\u8105\u5a01\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u4e8b\u4f8b\u306b\u3082\u5bfe\u5fdc\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u4e8b\u4f8b\u3067\u306f\u3001\u8105\u5a01\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u304c\u4e00\u8cab\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u3055\u307e\u3056\u307e\u306a\u30e6\u30fc\u30b6\u30fc\u3084\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u30b9\u30ad\u30fc\u30de\u3001\u8a2d\u5b9a\u3001\u540d\u524d\u3001\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb (\u8a8d\u8a3c\u60c5\u5831) \u3092\u542b\u3080\u8a2d\u5b9a\u30c7\u30fc\u30bf\u3092\u30c0\u30f3\u30d7\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u5f7c\u3089\u306f\u7b2c 1 \u6ce2\u3067\u767a\u751f\u3057\u305f\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u306e\u3088\u3046\u306a\u30e9\u30c6\u30e9\u30eb \u30e0\u30fc\u30d6\u306f\u884c\u3063\u3066\u3044\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u79c1\u305f\u3061\u306f\u3001\u3053\u308c\u3089\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u80cc\u5f8c\u306b\u3044\u308b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3089\u304c\u3001\u7d44\u7e54\u304c\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3057\u3001\u7de9\u548c\u7b56\u306e\u30ac\u30a4\u30c0\u30f3\u30b9\u3092\u9069\u7528\u3057\u3060\u3059\u524d\u306b\u3001\u5f71\u97ff\u3092\u6700\u5927\u5316\u3059\u3079\u304f\u3001\u3088\u308a\u5e83\u7bc4\u306a\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3078\u3068\u30b7\u30d5\u30c8\u3057\u305f\u53ef\u80fd\u6027\u304c\u3042\u308b\u3068\u8003\u3048\u3066\u3044\u307e\u3059\u3002\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u7b2c 3 \u6ce2\u306f\u3001\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e PoC (\u6982\u5ff5\u5b9f\u8a3c\u30b3\u30fc\u30c9) \u304c\u516c\u958b\u3055\u308c\u305f 2024 \u5e74 1 \u6708 16 \u65e5\u304b\u3089\u59cb\u307e\u308a\u307e\u3057\u305f\u3002\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e PoC \u304c\u516c\u958b\u3055\u308c\u308b\u3068\u3001\u30af\u30ea\u30d7\u30c8\u30de\u30a4\u30ca\u30fc\u3084\u7a2e\u3005\u306e\u30ea\u30e2\u30fc\u30c8\u76e3\u8996\u30fb\u7ba1\u7406\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2 (RMM) \u306a\u3069\u3092\u5e83\u304f\u5c55\u958b\u3059\u308b\u72af\u7f6a\u30b0\u30eb\u30fc\u30d7\u3092\u306f\u3058\u3081\u3001\u3055\u307e\u3056\u307e\u306a\u52d5\u6a5f\u3084\u6280\u8853\u30ec\u30d9\u30eb\u306e\u30a2\u30af\u30bf\u30fc\u3089\u306b\u3088\u308b\u5927\u898f\u6a21\u306a\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306b\u3064\u306a\u304c\u308a\u307e\u3059\u3002 <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Unit42 \u3067\u306f\u3001\u4e00\u822c\u516c\u958b\u3055\u308c\u305f PoC \u3092\u4f7f\u3063\u305f\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306b\u3088\u308b\u3001\u7b2c 3 \u6ce2\u306b\u5bfe\u5fdc\u3059\u308b\u3068\u8003\u3048\u3089\u308c\u308b\u8105\u5a01\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u4e8b\u4f8b\u306b\u5bfe\u5fdc\u3057\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f\u73fe\u5728\u3001\u3053\u308c\u3089\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u3092\u8abf\u67fb\u4e2d\u306e\u304a\u5ba2\u69d8\u3092\u30b5\u30dd\u30fc\u30c8\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u5177\u4f53\u7684\u306a\u72b6\u6cc1\u3067\u3044\u3046\u3068\u3001\u30b9\u30ad\u30e3\u30f3\u306a\u3044\u3057\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u76ee\u7684\u3067\u8907\u6570\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u8a66\u884c\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u305f\u3068\u3048\u3070\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OAST \u30d9\u30fc\u30b9\u306e\u30ea\u30af\u30a8\u30b9\u30c8 (OAST \u30ea\u30af\u30a8\u30b9\u30c8\u306e\u8a73\u7d30\u306f\u4ee5\u4e0b\u53c2\u7167):<\/span><\/li>\n<\/ul>\n<p><img  class=\"wp-image-132645 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Ivanti-Dana-OAST.png\" alt=\"\" width=\"600\" height=\"47\" \/><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u30af\u30ea\u30d7\u30c8\u30de\u30a4\u30ca\u30fc\u306e\u30c9\u30ed\u30c3\u30d7\u3068\u5b9f\u884c (\u4e0b\u8a18\u3082\u53c2\u7167)<\/span><\/li>\n<\/ul>\n<p><img  class=\"wp-image-132641 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Ivanti-API-Image.png\" alt=\"\" width=\"600\" height=\"136\" \/><\/p>\n<ul>\n<li aria-level=\"1\"><span style=\"font-weight: 400;\">\u307e\u305f\u3001\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8 <span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/dana-ws\/saml20.ws<\/span> \u3078\u306e SOAP \u30d9\u30fc\u30b9\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u901a\u3058\u3001CVE-2024-21893 SSRF \u8106\u5f31\u6027\u3092\u30c8\u30ea\u30ac\u30fc\u3057\u3066\u3001\u3053\u308c\u3092 CVE-2024-21887 \u3068\u9023\u9396\u3055\u305b\u308b\u3053\u3068\u306b\u3088\u308a\u3001\u975e\u8a8d\u8a3c\u3067\u306e RCE \u3092\u9054\u6210\u3057\u3088\u3046\u3068\u3059\u308b\u8a66\u307f\u3082\u3042\u308a\u307e\u3057\u305f\u3002<\/span><\/li>\n<\/ul>\n<p><a href=\"https:\/\/attackerkb.com\/topics\/FGlK1TVnB2\/cve-2024-21893\/rapid7-analysis\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Rapid7<\/span><\/a><span style=\"font-weight: 400;\"> \u306f 1\u670816\u65e5\u306e\u6700\u521d\u306e\u5206\u6790\u3067\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p style=\"padding-left: 40px;\">\u300c<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/api\/v1\/license\/keys-status<\/span> \u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306b\u306f\u30b3\u30de\u30f3\u30c9 \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u306e\u8106\u5f31\u6027\u304c\u5b58\u5728\u3057\u3066\u3044\u3066\u3001\u3053\u306e\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306b\u306f\u5358\u4e00\u306e HTTP GET \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4ecb\u3057\u3066\u30a2\u30af\u30bb\u30b9\u3067\u304d\u307e\u3059\u3002\u3053\u306e\u5206\u6790\u3092\u3059\u308b\u306a\u304b\u3067\u79c1\u305f\u3061\u306f\u3001<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/api\/v1\/license\/keys-status<\/span><span style=\"font-weight: 400;\"> \u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u3092\u30b5\u30fc\u30d3\u30b9\u3057\u3066\u3044\u308b Python \u30d0\u30c3\u30af\u30a8\u30f3\u30c9\u304c\u3001\u30ed\u30fc\u30ab\u30eb\u306b\u30d0\u30a4\u30f3\u30c9\u3055\u308c\u305f\u30dd\u30fc\u30c8 8090 \u3067\u30ea\u30c3\u30b9\u30f3\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u77e5\u308a\u307e\u3057\u305f\u3002\u3057\u305f\u304c\u3063\u3066\u3001 \u305f\u3068\u3048\u3070 SSRF \u306e\u8106\u5f31\u6027\u306a\u3069\u3092\u4ecb\u3057\u3066 HTTP GET \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30a2\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u81ea\u4f53\u306e\u4e0a\u3067\u767a\u751f\u3055\u305b\u305f\u5834\u5408\u306b\u306f\u3001<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">http:\/\/127.0.0.1:8090\/api\/v1\/license\/keys-status<\/span> \u3078\u306e HTTP GET \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4ecb\u3059\u308b\u3053\u3068\u3067\u3001\u3053\u306e\u30b3\u30de\u30f3\u30c9 \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002\u8a8d\u8a3c\u306f\u30d0\u30c3\u30af\u30a8\u30f3\u30c9 \u30b5\u30fc\u30d3\u30b9\u3067\u306f\u306a\u304f\u30d5\u30ed\u30f3\u30c8\u30a8\u30f3\u30c9 Web \u30b5\u30fc\u30d0\u30fc\u306b\u3088\u3063\u3066\u5b9f\u884c\u3055\u308c\u308b\u306e\u3067\u8a8d\u8a3c\u306f\u5fc5\u8981\u3042\u308a\u307e\u305b\u3093\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u3053\u306e SSRF \u8106\u5f31\u6027\u3092\u5229\u7528\u3059\u308c\u3070\u3001\u30d5\u30ed\u30f3\u30c8\u30a8\u30f3\u30c9 Web \u30b5\u30fc\u30d0\u30fc\u306b\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u5236\u9650\u3092\u8ab2\u3057\u3066\u3044\u308b Ivanti \u306e\u6700\u521d\u306e\u7de9\u548c\u7b56\u3092\u30d0\u30a4\u30d1\u30b9\u3067\u304d\u307e\u3059\u3002\u300d<\/span><\/p>\n<p><img  class=\"wp-image-132639 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Ivanti-POST-image.png\" alt=\"\" width=\"600\" height=\"455\" \/><\/p>\n<p><span style=\"font-weight: 400;\">URL \u30c7\u30b3\u30fc\u30c9\u3068 Base64 \u30c7\u30b3\u30fc\u30c9\u5f8c\u306e\u6700\u7d42\u7684\u306a\u30b3\u30de\u30f3\u30c9 \u30da\u30a4\u30ed\u30fc\u30c9\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/span><\/p>\n<p><img  class=\"wp-image-132643 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Ivanti-Final-Import-Payload.png\" alt=\"\" width=\"600\" height=\"47\" \/><\/p>\n<p>\u3053\u306e\u8a66\u307f\u3067\u306f\u3001\u3053\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30c1\u30a7\u30fc\u30f3\u3092\u5229\u7528\u3057\u3066 <span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">dsls<\/span> \u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30b3\u30de\u30f3\u30c9\u306f Connect Secure \u30a2\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u306b\u7d44\u307f\u8fbc\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30c1\u30a7\u30fc\u30f3\u3092\u4f7f\u3046\u3068\u5b9f\u884c\u4e2d\u306e\u8a2d\u5b9a\u3084\u30ad\u30e3\u30c3\u30b7\u30e5\u3092\u30c0\u30f3\u30d7\u3067\u304d\u308b\u305f\u3081\u3001\u30c0\u30f3\u30d7\u306b\u306f\u975e\u5e38\u306b\u6a5f\u5fae\u306a\u30c7\u30fc\u30bf\u304c\u542b\u307e\u308c\u308b\u3053\u3068\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>\u7d50\u679c\u306f Base64 \u3067\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u3066\u3001\u30ea\u30e2\u30fc\u30c8\u304b\u3089\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u30d1\u30b9\u306b <span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">logo.gif<\/span> \u3068\u3057\u3066\u66f8\u304d\u8fbc\u307e\u308c\u308b\u3053\u3068\u306b\u306a\u308a\u307e\u3059\u3002\u6a5f\u5fae\u30c7\u30fc\u30bf\u3092\u30c0\u30f3\u30d7\u3059\u308b\u3053\u3046\u3057\u305f\u8a66\u307f\u306f\u3053\u308c\u307e\u3067\u306e\u653b\u6483\u6ce2\u3067\u3082\u89b3\u6e2c\u3055\u308c\u3066\u304d\u307e\u3057\u305f\u3002<a href=\"https:\/\/www.mandiant.com\/resources\/blog\/investigating-ivanti-zero-day-exploitation\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Mandiant<\/span><\/a> \u306e\u30ec\u30dd\u30fc\u30c8\u304c\u3053\u306e\u7279\u5b9a\u306e\u30c6\u30af\u30cb\u30c3\u30af\u3092\u8a73\u3057\u304f\u5831\u3058\u3066\u3044\u307e\u3059\u3002<\/p>\n<h3><a id=\"ivanti-2024-scandeets\"><\/a>Ivanti \u306e\u30b9\u30ad\u30e3\u30f3\u306e\u8a73\u7d30<\/h3>\n<p><span style=\"font-weight: 400;\">\u653b\u6483\u8005\u3089\u306b\u3088\u308b CVE-2023-46805 \u3068 CVE-2024-21887 \u306b\u5bfe\u3057\u3066\u8106\u5f31\u306a Ivanti \u30c7\u30d0\u30a4\u30b9\u306e\u30b9\u30ad\u30e3\u30f3\u304c\u5897\u3048\u308b\u306b\u3064\u308c\u3001\u3053\u308c\u3089\u306e\u30d7\u30ed\u30fc\u30d6\u306b\u4ee5\u4e0b\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30fc \u30d1\u30b9\u304c\u983b\u7528\u3055\u308c\u3066\u3044\u308b\u3088\u3046\u3059\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/api\/v1\/totp\/user-backup-code\/..\/..\/&lt;any_path&gt;<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/api\/v1\/totp\/user-backup-code\/..\/..\/license\/keys-status\/&lt;exploit code&gt;<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/api\/v1\/configuration\/users\/user-roles\/user-role\/rest-userrole1\/web\/web-bookmarks\/bookmark<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/api\/v1\/cav\/client\/status\/..\/..\/&lt;any_path&gt;<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">\u653b\u6483\u8005\u3089\u306f\u3001CVE-2024-21887 \u3092\u30d7\u30ed\u30fc\u30d6\u3059\u308b\u3055\u3044\u3001\u5e2f\u57df\u5916\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3 \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30c6\u30b9\u30c8 (OAST) \u30c4\u30fc\u30eb\u3092\u4f7f\u3063\u3066\u3044\u308b\u3088\u3046\u3067\u3059\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u8005\u306f\u3001cURL \u3092\u4f7f\u3063\u3066\u7279\u5225\u306b\u7d30\u5de5\u3057\u305f HTTP \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u6a19\u7684\u306e\u30c7\u30d0\u30a4\u30b9\u306b\u9001\u4fe1\u3057\u307e\u3059\u3002\u3053\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u306f\u3001\u653b\u6483\u8005\u304c\u7ba1\u7406\u3059\u308b OAST \u30b5\u30fc\u30d0\u30fc\u306e URL \u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u30c7\u30d0\u30a4\u30b9\u306f\u653b\u6483\u8005\u306e OAST \u30b5\u30fc\u30d0\u30fc\u306b\u5fdc\u7b54\u3057\u3001\u305d\u306e\u5fdc\u7b54\u306b\u306f\u30c7\u30d0\u30a4\u30b9\u304c\u8106\u5f31\u304b\u3069\u3046\u304b\u3092\u793a\u3059\u30c7\u30fc\u30bf\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p>\u3053\u306e <span style=\"font-weight: 400;\">CVE-2024-21887<\/span><span style=\"font-weight: 400;\">\u306e\u30d7\u30ed\u30fc\u30d6\u8a66\u884c\u306b\u4f7f\u308f\u308c\u305f OAST \u30c9\u30e1\u30a4\u30f3\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">oast[.]me<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">oast[.]today<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">oast[.]live<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">oast[.]site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">oast[.]pro<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">oast[.]com<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">oast[.]fun<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">oast[.]online<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">oastify[.]com<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">oastfy[.]today<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">interactred[.]net<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">dnslog[.]cn<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">dnslog[.]pw<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">dnslog[.]store<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">dnslog[.]xyz<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">dgrh3[.]cn<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ipv6.1433.eu[.]org<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">dnslog.vhope[.]top<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">z9z[.]top<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ko02[.]com<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">rbaskets[.]in<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">burpcollaborator[.]net<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">dns.outbound.watchtowr[.]com<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">g3n[.]in<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">requestrepo[.]com<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">eyes[.]sh<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">\u8106\u5f31\u6027\u306e\u958b\u793a\u4ee5\u6765\u3001Unit 42 \u306f\u3053\u308c\u307e\u3067\u306e\u3068\u3053\u308d\u3001CVE-2023-46805 \u3068 CVE-2024-21887 \u306b\u5bfe\u3059\u308b 20 \u4e07\u56de\u4ee5\u4e0a\u306e\u30b9\u30ad\u30e3\u30f3\u8a66\u884c\u3092\u89b3\u6e2c\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u3054\u304f\u4e00\u90e8\u306f\u5185\u90e8\u30c6\u30b9\u30c8\u306b\u3088\u308b\u3082\u306e\u3068\u601d\u308f\u308c\u307e\u3059\u304c\u3001\u30b9\u30ad\u30e3\u30f3\u306e\u5927\u90e8\u5206\u306f\u3001\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u4e0a\u3067\u8106\u5f31\u306a\u30c7\u30d0\u30a4\u30b9\u3092\u63a2\u3057\u56de\u308b\u653b\u6483\u8005\u304b\u3089\u306e\u3082\u306e\u3067\u3059\u3002\u3053\u308c\u3089\u306e\u30b9\u30ad\u30e3\u30f3\u306f\u305f\u3044\u3066\u3044\u8106\u5f31\u306a\u30bf\u30fc\u30b2\u30c3\u30c8\u3092\u898b\u3064\u3051\u308b\u305f\u3081\u306e\u30d7\u30ed\u30fc\u30d6\u3067\u69cb\u6210\u3055\u308c\u3066\u3044\u307e\u3059\u304c\u3001\u653b\u6483\u8005\u3089\u306b\u3088\u308b\u4fb5\u5bb3\u30db\u30b9\u30c8\u3078\u306e\u30af\u30ea\u30d7\u30c8\u30de\u30a4\u30ca\u30fc\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306b\u3064\u306a\u304c\u308b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e\u653b\u6483\u3067\u4f7f\u7528\u3055\u308c\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u4e00\u4f8b\u3092\u4ee5\u4e0b\u306b\u8a18\u8f09\u3057\u307e\u3059\u3002<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SHA256 \u30cf\u30c3\u30b7\u30e5: <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">bbfba00485901f859cf532925e83a2540adfe01556886837d8648cd92519c68d<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u5834\u6240: <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hxxp:\/\/45.130.22[.]219\/ivanti.js<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u8aac\u660e: \u30af\u30ea\u30d7\u30c8\u30de\u30a4\u30ca\u30fc \u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u7528\u306e\u30b7\u30a7\u30eb\u30b9\u30af\u30ea\u30d7\u30c8<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SHA256 \u30cf\u30c3\u30b7\u30e5: <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0c9ada54a8a928a747d29d4132565c4ccecca0a02abe8675914a70e82c5918d2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u5834\u6240: <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hxxp:\/\/45.130.22[.]219\/ivanti<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u8aac\u660e: XMRIG Monero \u30af\u30ea\u30d7\u30c8\u30de\u30a4\u30ca\u30fc\u306e ELF \u30d5\u30a1\u30a4\u30eb<\/span><\/li>\n<\/ul>\n<h2><a id=\"ivanti-2024-techana\"><\/a>Ivanti \u306e\u8106\u5f31\u6027\u306e\u6280\u8853\u5206\u6790: \u672a\u8a8d\u8a3c\u30b3\u30de\u30f3\u30c9 \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u3068 Web \u30b7\u30a7\u30eb\u306e\u57cb\u3081\u8fbc\u307f<\/h2>\n<p><span style=\"font-weight: 400;\">\u653b\u6483\u8005\u306f CVE-2023-46805 \u3068 CVE-2024-21887 \u3092\u7d44\u307f\u5408\u308f\u305b\u3066\u3001\u7121\u8a31\u53ef\u306e\u30b3\u30de\u30f3\u30c9 \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u653b\u6483\u3092\u5b9f\u884c\u3057\u3001Web \u30b7\u30a7\u30eb\u3092\u57cb\u3081\u8fbc\u3080\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u8106\u5f31\u306a API \u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8:<\/span><\/p>\n<p><img  class=\"wp-image-132647 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Ivanti-Endpoints.png\" alt=\"\" width=\"600\" height=\"52\" \/><\/p>\n<p><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e API \u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306f\u3001Python \u30e2\u30b8\u30e5\u30fc\u30eb\u306e <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">subprocess<\/span> \u3092\u4f7f\u3044\u3001<span style=\"font-weight: 400;\"> \u5165\u529b\u30d1\u30e9\u30e1\u30fc\u30bf\u30fc\u3068\u3057\u3066 <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">shell=True<\/span><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"> \u3092\u6307\u5b9a\u3057\u3066\u3001\u30b3\u30de\u30f3\u30c9\u306e\u6587\u5b57\u5217\u3092\u5b9f\u884c\u3057\u307e\u3059<\/span>\u3002<\/span><a href=\"https:\/\/docs.python.org\/ja\/3\/library\/subprocess.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Python \u306e\u516c\u5f0f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8<\/span><\/a><span style=\"font-weight: 400;\">\u306b\u3088\u308c\u3070\u3001\u3053\u306e\u5f37\u529b\u3067\u6f5c\u5728\u7684\u306b\u5371\u967a\u306a\u30d1\u30e9\u30e1\u30fc\u30bf\u30fc\u306f\u3001\u653b\u6483\u8005\u306b\u3088\u308b\u30ea\u30d0\u30fc\u30b9\u30b7\u30a7\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u3092\u53ef\u80fd\u306b\u3057\u307e\u3059\u3002\u540c\u516c\u5f0f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">\u300cshell \u304c True \u306a\u3089\u3001\u6307\u5b9a\u3055\u308c\u305f\u30b3\u30de\u30f3\u30c9\u306f\u30b7\u30a7\u30eb\u306b\u3088\u3063\u3066\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002\u3042\u306a\u305f\u304c Python \u3092\u4e3b\u3068\u3057\u3066 (\u307b\u3068\u3093\u3069\u306e\u30b7\u30b9\u30c6\u30e0\u30b7\u30a7\u30eb\u4ee5\u4e0a\u306e) \u5f37\u5316\u3055\u308c\u305f\u5236\u5fa1\u30d5\u30ed\u30fc\u306e\u305f\u3081\u306b\u4f7f\u7528\u3057\u3066\u3044\u3066\u3001\u3055\u3089\u306b\u30b7\u30a7\u30eb\u30d1\u30a4\u30d7\u3001\u30d5\u30a1\u30a4\u30eb\u540d\u30ef\u30a4\u30eb\u30c9\u30ab\u30fc\u30c9\u3001\u74b0\u5883\u5909\u6570\u5c55\u958b\u3001<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">~<\/span><span style=\"font-weight: 400;\"> \u306e\u30e6\u30fc\u30b6\u30fc\u30db\u30fc\u30e0\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3078\u306e\u5c55\u958b\u306e\u3088\u3046\u306a\u4ed6\u306e\u30b7\u30a7\u30eb\u6a5f\u80fd\u3078\u306e\u7c21\u5358\u306a\u30a2\u30af\u30bb\u30b9\u3092\u671b\u3080\u306a\u3089\u3001\u3053\u308c\u306f\u6709\u7528\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u3002\u300d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u653b\u6483\u8005\u304c\u3053\u308c\u3089\u306e API \u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u3092\u4f7f\u3063\u3066\u60aa\u610f\u306e\u3042\u308b\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u306b\u306f\u3001\u8a8d\u8a3c\u30e1\u30ab\u30cb\u30ba\u30e0\u3092\u30d0\u30a4\u30d1\u30b9\u3057\u306a\u3051\u308c\u3070\u306a\u308a\u307e\u305b\u3093\u3002\u958b\u793a\u3055\u308c\u305f\u30ea\u30bd\u30fc\u30b9\u304b\u3089\u306f\u3001\u3053\u306e\u8a8d\u8a3c\u304c\u30d5\u30ed\u30f3\u30c8 \u30a8\u30f3\u30c9\u3067\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u30d7\u30ed\u30ad\u30b7\u30fc\u306b\u57fa\u3065\u3044\u3066\u304a\u308a\u3001\u3053\u308c\u304c\u30e6\u30fc\u30b6\u30fc\u306e\u30a2\u30af\u30bb\u30b9\u8a31\u53ef\/\u62d2\u5426\u3092\u884c\u3063\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u3063\u3066\u3044\u307e\u3059\u3002 <\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u3053\u306e\u8a8d\u8a3c\u30e1\u30ab\u30cb\u30ba\u30e0\u306f\u3001\u6587\u5b57\u5217\u6bd4\u8f03\u95a2\u6570\u3092\u4f7f\u7528\u3057\u3001URI \u306e\u6700\u521d\u306e 29 \u30d0\u30a4\u30c8\u304c <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/api\/v1\/totp\/user-backup-code<\/span><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"> \u3068\u4e00\u81f4\u3059\u308b\u63a5\u982d\u8f9e\u3092\u6301\u3063\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3092\u5224\u65ad\u3057\u3066\u3044\u307e\u3059\u3002<\/span>\u3053\u306e\u691c\u8a3c\u30e1\u30ab\u30cb\u30ba\u30e0\u306f\u3001\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30fc \u30c8\u30e9\u30d0\u30fc\u30b5\u30eb\u306e\u8106\u5f31\u6027\u3092\u4f7f\u3048\u3070\u7c21\u5358\u306b\u7834\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u306e\u3067\u3001\u4e00\u81f4\u3059\u308b\u3082\u306e\u304c\u5b58\u5728\u3059\u308c\u3070\u3001\u30e6\u30fc\u30b6\u30fc\u306f\u30d0\u30c3\u30af\u30a8\u30f3\u30c9\u3067\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u3059\u3079\u3066\u306e API \u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u8a8d\u8a3c\u306e\u30d0\u30a4\u30d1\u30b9\u5f8c\u3001\u653b\u6483\u8005\u306f\u8106\u5f31\u306a API \u3092\u76f4\u63a5\u547c\u3073\u51fa\u3057\u3066\u3001\u60aa\u610f\u306e\u3042\u308b\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002<\/span><\/p>\n<h2><a id=\"ivanti-2024-exploit\"><\/a>Ivanti \u306e\u8106\u5f31\u6027\u306e\u91ce\u751f\u3067\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/h2>\n<p><span style=\"font-weight: 400;\">\u79c1\u305f\u3061\u306f\u793e\u5185\u306e\u30c6\u30ec\u30e1\u30c8\u30ea\u30fc\u3092\u901a\u3058\u3066 Ivanti \u306e\u8106\u5f31\u6027\u306b\u95a2\u9023\u3059\u308b\u91ce\u751f\u306e\u653b\u6483\u306b\u3064\u3044\u3066\u306e\u77e5\u898b\u3092\u5f97\u307e\u3057\u305f\u3002Threat Prevention \u30b7\u30b0\u30cd\u30c1\u30e3\u3092\u30ea\u30ea\u30fc\u30b9\u3057\u3066\u4ee5\u964d\u3001CVE-2024-21887 \u3092\u6a19\u7684\u3068\u3057\u305f 15,714 \u4ef6\u306e\u653b\u6483\u304c\u9632\u6b62\u3055\u308c\u307e\u3057\u305f\u30022024 \u5e74 1 \u6708 20 \u65e5\u306b\u306f 4,120 \u4ef6\u306e\u653b\u6483\u3092\u89b3\u6e2c\u3057\u3066\u304a\u308a\u3001\u3053\u308c\u306f\u3053\u306e\u8106\u5f31\u6027\u3092\u72d9\u3063\u305f\u653b\u6483\u306e\u30d4\u30fc\u30af\u3068\u3057\u3066\u969b\u7acb\u3063\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<figure id=\"attachment_132432\" aria-describedby=\"caption-attachment-132432\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132432 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Ivanti-F4.png\" alt=\"\u30d6\u30ed\u30c3\u30af\u3055\u308c\u305f\u653b\u6483\u306e\u30b0\u30e9\u30d5\u3002\" width=\"900\" height=\"405\" \/><figcaption id=\"caption-attachment-132432\" class=\"wp-caption-text\">\u56f3 4. CVE-2024-21887 \u3092\u6a19\u7684\u3068\u3057\u305f\u653b\u6483\u306e\u30d6\u30ed\u30c3\u30af\u4ef6\u6570 (2024 \u5e74 1 \u6708 17 \u65e5\u301c 2024 \u5e74 1 \u6708 23 \u65e5)<\/figcaption><\/figure>\n<p><span style=\"font-weight: 400;\">\u89b3\u6e2c\u3055\u308c\u305f\u653b\u6483\u306e\u307b\u3068\u3093\u3069\u306f\u7c73\u56fd\u5730\u57df\u304b\u3089\u306e\u3082\u306e\u3067\u3001\u3053\u308c\u304c\u653b\u6483\u5168\u4f53\u306e 74\uff05 \u3092\u5360\u3081\u3001\u6b21\u3044\u3067 EU\u3001\u30ab\u30ca\u30c0\u3068\u7d9a\u304d\u307e\u3059\u3002\u305f\u3060\u3057\u653b\u6483\u8005\u306f\u305d\u308c\u3089\u306e\u56fd\u306b\u8a2d\u7f6e\u3055\u308c\u305f\u30d7\u30ed\u30ad\u30b7\u30b5\u30fc\u30d0\u30fc\u3084 VPN \u3092\u5229\u7528\u3057\u3001\u5b9f\u969b\u306e\u7269\u7406\u7684\u306a\u5834\u6240\u3092\u96a0\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3053\u3068\u3082\u79c1\u305f\u3061\u306f\u8a8d\u8b58\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<figure id=\"attachment_132434\" aria-describedby=\"caption-attachment-132434\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132434 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Ivanti-F5.png\" alt=\"\u88ab\u5bb3\u56fd\u306e\u5186\u30b0\u30e9\u30d5\u3002\u7c73\u56fd\u304c\u5927\u534a\u3092\u5360\u3081\u308b \" width=\"700\" height=\"508\" \/><figcaption id=\"caption-attachment-132434\" class=\"wp-caption-text\">\u56f3 5. Ivanti \u306e\u8106\u5f31\u6027\u3092\u72d9\u3063\u305f\u91ce\u751f\u306e\u653b\u6483\u767a\u751f\u6e90\u3068\u601d\u308f\u308c\u308b\u5730\u57df<\/figcaption><\/figure>\n<h2><a id=\"post-132058-_zg1rezlvhwuy\"><\/a>Ivanti \u306e\u4e2d\u9593\u30ac\u30a4\u30c0\u30f3\u30b9<\/h2>\n<p><span style=\"font-weight: 400;\">Ivanti<\/span><a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\"> \u304b\u3089\u306f\u56de\u907f\u7b56\u304c\u63d0\u4f9b<\/span><\/a>\u3055\u308c\u3066\u3044\u307e\u3059\u306e\u3067\u3001<span style=\"font-weight: 400;\"> \u540c\u793e\u304c\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306b\u5bfe\u3059\u308b\u30d1\u30c3\u30c1\u3092\u516c\u958b\u3059\u308b\u307e\u3067\u306f\u3001\u3053\u308c\u3089\u306e\u56de\u907f\u7b56\u3092\u5229\u7528\u3067\u304d\u307e\u3059\u3002\u540c\u793e\u306f\u653b\u6483\u8005\u304c Ivanti \u306e\u5185\u90e8\u6574\u5408\u6027\u30c1\u30a7\u30c3\u30ab\u30fc\u3092\u6539\u3056\u3093\u3057\u3088\u3046\u3068\u3057\u305f\u8a3c\u62e0\u3092\u78ba\u8a8d\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u72b6\u6cc1\u3092\u53d7\u3051\u3001\u540c\u793e\u306f\u5168\u9867\u5ba2\u306b\u5bfe\u3057\u3001\u3053\u306e\u554f\u984c\u306b\u5bfe\u51e6\u3059\u308b\u305f\u3081\u306b\u6a5f\u80fd\u3092\u8ffd\u52a0\u3057\u305f Ivanti \u306e\u5916\u90e8\u6574\u5408\u6027\u30c1\u30a7\u30c3\u30ab\u30fc\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u3092\u63a8\u5968\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u672c\u4ef6\u306f\u72b6\u6cc1\u306e\u5909\u5316\u304c\u65e9\u3044\u3053\u3068\u304b\u3089\u3001Ivanti \u306b\u3088\u308b\u52e7\u544a\u3092\u983b\u7e41\u306b\u78ba\u8a8d\u3059\u308b\u3053\u3068\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002<\/span><\/p>\n<h2><a id=\"post-132058-_6kajjrwpgjuu\"><\/a>\u7d50\u8ad6<\/h2>\n<p><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e CVE \u306b\u5bfe\u3059\u308b\u30d1\u30c3\u30c1\u306f\u307e\u3060\u8106\u5f31\u6027\u3092\u3082\u3064\u3059\u3079\u3066\u306e\u88fd\u54c1\u306b\u5bfe\u3057\u3066\u306f\u516c\u958b\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002\u3057\u304b\u3057\u306a\u304c\u3089\u6700\u521d\u306e 2 \u3064\u306e\u8106\u5f31\u6027\u306b\u5bfe\u3059\u308b\u6982\u5ff5\u5b9f\u8a3c\u30b3\u30fc\u30c9\u304c\u4e00\u822c\u516c\u958b\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u3053\u308c\u3089 5 \u3064\u306e\u8106\u5f31\u6027\u306e\u3046\u3061 4 \u3064\u3092\u7a4d\u6975\u7684\u306b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3057\u3066\u3044\u307e\u3059\u3002\u304b\u304b\u308b\u72b6\u6cc1\u304b\u3089\u3001\u672c\u8106\u5f31\u6027\u304b\u3089\u306e\u5f71\u97ff\u3092\u53d7\u3051\u308b\u8aad\u8005\u306e\u7686\u3055\u307e\u306b\u306f\u3001<\/span><a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US\" target=\"_blank\" rel=\"noopener\">Ivanti \u306e\u63a8\u5968\u3059\u308b\u7de9\u548c\u7b56<\/a>\u306b\u5f93\u3063\u3066\u3044\u305f\u3060\u304f\u3053\u3068\u304c\u91cd\u8981\u3067\u3059\u3002\u79c1\u305f\u3061\u306f\u65b0\u3057\u3044\u60c5\u5831\u304c\u5165\u308a\u6b21\u7b2c\u672c\u7a3f\u3092\u66f4\u65b0\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-weight: 400;\">\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306f\u3001\u3053\u308c\u3089\u306e\u8abf\u67fb\u7d50\u679c\u3092 Cyber Threat Alliance (CTA: \u30b5\u30a4\u30d0\u30fc\u8105\u5a01\u30a2\u30e9\u30a4\u30a2\u30f3\u30b9) \u306e\u30e1\u30f3\u30d0\u30fc\u3068\u5171\u6709\u3057\u307e\u3057\u305f\u3002CTA \u306e\u30e1\u30f3\u30d0\u30fc\u306f\u3053\u306e\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3092\u4f7f\u3063\u3066\u3001\u304a\u5ba2\u69d8\u306b\u4fdd\u8b77\u3092\u8fc5\u901f\u306b\u63d0\u4f9b\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u3092\u4f53\u7cfb\u7684\u306b\u963b\u5bb3\u3067\u304d\u307e\u3059\u3002\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f <\/span><a href=\"https:\/\/www.cyberthreatalliance.org\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Cyber Threat Alliance<\/span><\/a> \u306b\u3066\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\uff61<\/p>\n<p><span style=\"font-weight: 400;\">\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001\u6b21\u306e\u5404\u88fd\u54c1\u306b\u3088\u3063\u3066\u3053\u306e\u8105\u5a01\u304b\u3089\u3088\u308a\u78ba\u5b9f\u306b\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u8a73\u7d30\u306a\u60c5\u5831\u304c\u5229\u7528\u53ef\u80fd\u306b\u306a\u308a\u3057\u3060\u3044\u672c\u8105\u5a01\u306b\u95a2\u3059\u308b\u60c5\u5831\u3092\u66f4\u65b0\u3057\u307e\u3059\u3002<\/span><\/p>\n<h2><a id=\"ivanti-2024-timeline\"><\/a>Ivanti \u306e\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3<\/h2>\n<figure id=\"attachment_132924\" aria-describedby=\"caption-attachment-132924\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132924 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/Ivanti-Timeline-Service-blueprint-w_-additional-elements-example.png\" alt=\"Ivanti \u306e\u8106\u5f31\u6027\u306e\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\" width=\"900\" height=\"449\" \/><figcaption id=\"caption-attachment-132924\" class=\"wp-caption-text\">\u56f3 6. Ivanti \u306e\u8106\u5f31\u6027\u306b\u95a2\u9023\u3057\u3066\u6700\u8fd1\u767a\u751f\u3057\u305f\u30a4\u30d9\u30f3\u30c8\u306e\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3<\/figcaption><\/figure>\n<h2><a id=\"post-132058-_lqzcx8cug942\"><\/a>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u88fd\u54c1\u306b\u3088\u308b Ivanti \u88fd\u54c1\u306e\u8106\u5f31\u6027\u304b\u3089\u306e\u4fdd\u8b77<\/h2>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306b\u306f\u3001\u5f0a\u793e\u88fd\u54c1\/\u30b5\u30fc\u30d3\u30b9\u306e\u4fdd\u8b77\u30fb\u66f4\u65b0\u3092\u901a\u3058\u3066\u540c\u8105\u5a01\u306e\u7279\u5b9a\u30fb\u9632\u5fa1\u304c\u63d0\u4f9b\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u4fb5\u5bb3\u306e\u61f8\u5ff5\u304c\u3042\u308a\u5f0a\u793e\u306b\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u30ec\u30b9\u30dd\u30f3\u30b9\u306b\u95a2\u3059\u308b\u3054\u76f8\u8ac7\u3092\u306a\u3055\u308a\u305f\u3044\u5834\u5408\u306f\u3001<a href=\"https:\/\/start.paloaltonetworks.jp\/contact-unit42.html\" target=\"_blank\" rel=\"noopener\">\u3053\u3061\u3089\u306e\u30d5\u30a9\u30fc\u30e0<\/a>\u304b\u3089\u3054\u9023\u7d61\u3044\u305f\u3060\u304f\u304b\u3001infojapan@paloaltonetworks.com\u307e\u3067\u30e1\u30fc\u30eb\u306b\u3066\u3054\u9023\u7d61\u3044\u305f\u3060\u304f\u304b\u3001\u4e0b\u8a18\u306e\u96fb\u8a71\u756a\u53f7\u307e\u3067\u304a\u554f\u3044\u5408\u308f\u305b\u304f\u3060\u3055\u3044 (\u3054\u76f8\u8ac7\u306f\u5f0a\u793e\u88fd\u54c1\u306e\u304a\u5ba2\u69d8\u306b\u306f\u9650\u5b9a\u3055\u308c\u307e\u305b\u3093)\u3002<\/p>\n<ul>\n<li>\u5317\u7c73\u30d5\u30ea\u30fc\u30c0\u30a4\u30e4\u30eb: 866.486.4842 (866.4.UNIT42)<\/li>\n<li>EMEA: +31.20.299.3130<\/li>\n<li>APAC: +65.6983.8730<\/li>\n<li>\u65e5\u672c: (+81) 50-1790-0200<\/li>\n<\/ul>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306f\u3001Ivanti \u88fd\u54c1\u306e\u8106\u5f31\u6027\u306b\u3088\u308a\u5f15\u304d\u8d77\u3053\u3055\u308c\u308b\u3042\u3089\u3086\u308b\u30ea\u30b9\u30af\u306e\u7279\u5b9a\u30fb\u7de9\u548c\u306e\u652f\u63f4\u306b\u5411\u3051\u3001\u30a2\u30bf\u30c3\u30af \u30b5\u30fc\u30d5\u30a7\u30b9 (\u653b\u6483\u5bfe\u8c61\u9818\u57df) \u306e\u8a55\u4fa1\u3068 Prisma Access \u306e 90 \u65e5\u9593\u30e9\u30a4\u30bb\u30f3\u30b9\u3092\u542b\u3080\u3001<a class=\"c-link\" href=\"https:\/\/start.paloaltonetworks.com\/get-help-for-Ivanti-VPN-exploit\" target=\"_blank\" rel=\"noopener noreferrer\" data-sk=\"tooltip_parent\" data-stringify-link=\"https:\/\/start.paloaltonetworks.com\/get-help-for-Ivanti-VPN-exploit\">\u7121\u511f\u3067\u7fa9\u52d9\u3092\u4f34\u308f\u306a\u3044\u7dca\u6025\u30d0\u30f3\u30c9\u30eb\u3092\u63d0\u4f9b<\/a>\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-weight: 400;\">\u306a\u304a\u3001\u672c\u30aa\u30d5\u30a1\u30fc\u306f\u30d7\u30ed\u30e2\u30fc\u30b7\u30e7\u30f3\u7528\u3067\u3042\u308a\u3001\u5e0c\u671b\u591a\u6570\u306e\u5834\u5408\u306f\u3054\u5229\u7528\u306b\u306a\u308c\u306a\u3044\u3053\u3068\u304c\u3042\u308a\u307e\u3059\u3002\u672c\u8106\u5f31\u6027\u306f\u975e\u5e38\u306b\u5909\u5316\u304c\u65e9\u3044\u305f\u3081\u3001\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306f\u540c\u30aa\u30d5\u30a1\u30fc\u3092\u66f4\u65b0\u3059\u308b\u6a29\u5229\u3092\u7559\u4fdd\u3057\u307e\u3059\u3002<\/span><\/p>\n<h3><a id=\"post-132058-_jlr298x3ynzm\"><\/a>Advanced Threat Prevention \u3092\u6709\u52b9\u306b\u3057\u305f\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3068 Prisma Access<\/h3>\n<p><a href=\"https:\/\/docs.paloaltonetworks.com\/ngfw\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb<\/span><\/a><span style=\"font-weight: 400;\">\u3067 <\/span><a href=\"https:\/\/docs.paloaltonetworks.com\/advanced-threat-prevention\/administration\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Advanced Threat Prevention<\/span><\/a> <span style=\"font-weight: 400;\">\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30b5\u30d6\u30b9\u30af\u30ea\u30d7\u30b7\u30e7\u30f3\u3092\u6709\u52b9\u306b\u3057\u3066\u3044\u308b\u5834\u5408\u3001Threat Prevention \u306e\u30b7\u30b0\u30cd\u30c1\u30e3\u30fc <a href=\"https:\/\/threatvault.paloaltonetworks.com\/?query=81872\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">81872<\/span><\/a><span style=\"font-weight: 400;\">\u3001<\/span> <a href=\"https:\/\/threatvault.paloaltonetworks.com\/?query=94885\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">94885<\/span><\/a><span style=\"font-weight: 400;\">\u3001 <\/span><a href=\"https:\/\/threatvault.paloaltonetworks.com\/?query=94886\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">94886<\/span><\/a><span style=\"font-weight: 400;\">\u3001 <\/span><a href=\"https:\/\/threatvault.paloaltonetworks.com\/?query=94888\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">94888<\/span><\/a>\u3001<\/span><a href=\"https:\/\/threatvault.paloaltonetworks.com\/?query=94976\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">94976<\/span><\/a>\u3001<a href=\"https:\/\/threatvault.paloaltonetworks.com\/?query=95024\" target=\"_blank\" rel=\"noopener\">95024<\/a> \u3092\u901a\u3058\u305f\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u304c\u653b\u6483\u9632\u6b62\u306b\u5f79\u7acb\u3061\u307e\u3059\u3002<\/p>\n<p><span style=\"font-weight: 400;\">Advanced Threat Prevention \u306e Vulnerability Prevention (\u8106\u5f31\u6027\u9632\u5fa1) \u306b\u542b\u307e\u308c\u308b Inline Cloud Analysis (\u30a4\u30f3\u30e9\u30a4\u30f3 \u30af\u30e9\u30a6\u30c9\u5206\u6790) \u306f\u3001HTTP \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u5185\u306e\u30ea\u30e2\u30fc\u30c8 \u30b3\u30fc\u30c9\u5b9f\u884c\u653b\u6483\u30d1\u30bf\u30fc\u30f3\u3092\u8b58\u5225\u3067\u304d\u307e\u3059\u3002\u3053\u306e\u307b\u304b\u3001Inline Cloud Analysis \u306f HTTP \u30d8\u30c3\u30c0\u30fc\u3084 HTTP \u30dc\u30c7\u30a3\u5185\u306e\u60aa\u610f\u306e\u3042\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u691c\u51fa\u53ef\u80fd\u3067\u3001\u6a5f\u68b0\u5b66\u7fd2\u30e2\u30c7\u30eb\u3092\u4f7f\u3063\u3066\u30b3\u30fc\u30c9\u5b9f\u884c\u306e\u69cb\u6587\u304b\u3089\u691c\u51fa\u4e0a\u91cd\u8981\u306a\u8981\u7d20\u3092\u8b58\u5225\u3057\u307e\u3059\u3002\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Advanced Threat Prevention \u306f\u3001\u8106\u5f31\u6027\u306e\u4e00\u822c\u958b\u793a\u306b\u5148\u3093\u3058\u3066\u3053\u308c\u3089 Ivanti \u306e\u8106\u5f31\u6027\u3092\u30d7\u30ed\u30a2\u30af\u30c6\u30a3\u30d6\u306b\u691c\u51fa\u3067\u304d\u307e\u3057\u305f\u3002<\/span><\/p>\n<h4><a id=\"ivanti-2024-stop0\"><\/a><b>Advanced Threat Prevention \u306b\u3088\u308b\u30bc\u30ed\u30c7\u30a4\u306e\u9632\u6b62<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Advanced Threat Prevention (ATP) \u306f\u3001\u5f93\u6765\u306e\u30d2\u30e5\u30fc\u30ea\u30b9\u30c6\u30a3\u30c3\u30af\u4fb5\u5165\u9632\u5fa1\u30b7\u30b9\u30c6\u30e0 (IPS) \u306e\u691c\u77e5\u6a5f\u80fd\u3092\u3001\u6a5f\u68b0\u5b66\u7fd2\u3084\u6df1\u5c64\u5b66\u7fd2\u30e2\u30c7\u30eb\u306e\u529b\u3068\u67d4\u8edf\u6027\u3067\u62e1\u5f35\u3057\u305f\u30a4\u30f3\u30e9\u30a4\u30f3\u306e\u30af\u30e9\u30a6\u30c9\u63d0\u4f9b\u578b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30fc\u30d3\u30b9\u3067\u3059\u3002ATP \u306f Threat Prevention (TP) \u3068\u9023\u643a\u3057\u3001\u6a5f\u68b0\u5b66\u7fd2\u6a5f\u80fd\u3092\u6d3b\u7528\u3059\u308b\u3053\u3068\u3067\u3001TP \u304c\u63d0\u4f9b\u3059\u308b\u9632\u5fa1\u3092\u62e1\u5f35\u3057\u3001\u5f37\u56fa\u3067\u591a\u5c64\u5316\u3055\u308c\u305f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u9632\u5fa1\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u3068\u304f\u306b ATP \u306e\u691c\u77e5\u30b5\u30fc\u30d3\u30b9\u306f\u3001C2\u3001\u30bc\u30ed\u30c7\u30a4\u8106\u5f31\u6027\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u8a66\u884c\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u30cf\u30c3\u30ad\u30f3\u30b0 \u30c4\u30fc\u30eb\u4f7f\u7528\u306a\u3069\u3001\u672a\u77e5\u306e\u653b\u6483\u3084\u65b0\u305f\u306a\u653b\u6483\u3092\u691c\u77e5\u3059\u308b\u3088\u3046\u30c8\u30ec\u30fc\u30cb\u30f3\u30b0\u3055\u308c\u3066\u3044\u307e\u3059\u3002ATP \u306e\u30a4\u30f3\u30e9\u30a4\u30f3 \u30af\u30e9\u30a6\u30c9\u89e3\u6790\u306f\u3001SQL\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u3068\u30b3\u30de\u30f3\u30c9\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u8a66\u884c\u3092\u691c\u51fa\u3059\u308b 2 \u3064\u306e\u6a5f\u68b0\u5b66\u7fd2\u30b5\u30fc\u30d3\u30b9\u3092\u30b5\u30dd\u30fc\u30c8\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<h5><a id=\"ivanti-2024-ML\"><\/a><span style=\"font-weight: 400;\">Machine Learning for Exploit (\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u7528\u6a5f\u68b0\u5b66\u7fd2) \u306e\u30b3\u30de\u30f3\u30c9 \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3 \u30e2\u30c7\u30eb<\/span><\/h5>\n<p><span style=\"font-weight: 400;\">Machine Learning for Exploit (\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u7528\u6a5f\u68b0\u5b66\u7fd2\u3001MLEXP) \u306f\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u653b\u6483\u306e\u6210\u529f\u3092\u9632\u3050 ATP \u691c\u51fa\u30b5\u30fc\u30d3\u30b9\u306e\u4e00\u90e8\u3067\u3059\u3002\u691c\u51fa\u30b5\u30fc\u30d3\u30b9\u306e 1 \u3064\u3067\u3042\u308b MLEXP-CMD \u306f\u3001Windows \u304a\u3088\u3073 UNIX \u30d9\u30fc\u30b9\u306e\u30b3\u30de\u30f3\u30c9 \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u653b\u6483\u3084\u30ea\u30e2\u30fc\u30c8 \u30b3\u30fc\u30c9\u5b9f\u884c\u653b\u6483\u3092\u691c\u51fa\u30fb\u9632\u6b62\u3059\u308b\u3088\u3046\u306b\u30c8\u30ec\u30fc\u30cb\u30f3\u30b0\u3055\u308c\u305f\u7573\u307f\u8fbc\u307f\u30cb\u30e5\u30fc\u30e9\u30eb \u30cd\u30c3\u30c8\u30ef\u30fc\u30af (CNN) \u6df1\u5c64\u5b66\u7fd2\u30e2\u30c7\u30eb\u3067\u3059\u3002\u3053\u306e\u30e2\u30c7\u30eb\u306f\u3001\u91ce\u751f\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u8a66\u884c\u306e\u5927\u898f\u6a21\u30c7\u30fc\u30bf\u30bb\u30c3\u30c8\u3067\u7d99\u7d9a\u7684\u306b\u30c8\u30ec\u30fc\u30cb\u30f3\u30b0\u3055\u308c\u3066\u304a\u308a\u3001\u65b0\u3057\u3044\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3084\u672a\u77e5\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u5bfe\u3059\u308b\u691c\u51fa\u4e88\u6e2c\u3092\u63d0\u4f9b\u53ef\u80fd\u3067\u3059\u3002<\/span><\/p>\n<h5><a id=\"ivanti-2024-ATPBP\"><\/a><span style=\"font-weight: 400;\">Advanced Threat Prevention \u306e\u30d9\u30b9\u30c8 \u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u306e\u5229\u7528<\/span><\/h5>\n<p><span style=\"font-weight: 400;\">\u81ea\u7d44\u7e54\u304c\u3059\u3067\u306b\u5f0a\u793e\u306e<\/span><a href=\"https:\/\/docs.paloaltonetworks.com\/best-practices.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9<\/span><\/a><span style=\"font-weight: 400;\">\u306b\u5f93\u3063\u3066\u3044\u308b\u5834\u5408\u3001\u3053\u306e\u653b\u6483\u306e\u8907\u6570\u306e\u30b9\u30c6\u30c3\u30d7\u306b\u3064\u3044\u3066\u3001\u624b\u52d5\u306b\u3088\u308b\u4ecb\u5165\u306a\u3057\u306b\u3001\u81ea\u52d5\u7684\u306b\u4fdd\u8b77\u3092\u53d7\u3051\u3089\u308c\u307e\u3059\u3002<\/span><\/p>\n<h5><a id=\"ivanti-2024-IPS\"><\/a><span style=\"font-weight: 400;\">IPS<\/span><\/h5>\n<p><span style=\"font-weight: 400;\">Advanced Threat Protection \u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30b5\u30d6\u30b9\u30af\u30ea\u30d7\u30b7\u30e7\u30f3\u306f\u3001CVE-2024-21887 \u306b\u95a2\u9023\u3059\u308b\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u81ea\u52d5\u7684\u306b\u30d6\u30ed\u30c3\u30af\u3067\u304d\u307e\u3059\u3002<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Device &gt; Dynamic Updates (\u30c0\u30a4\u30ca\u30df\u30c3\u30af\u66f4\u65b0)<\/span> \u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066<span style=\"font-weight: 400;\">\u3001 <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Applications and Threats (\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304a\u3088\u3073\u8105\u5a01)<\/span>\u3092\u78ba\u8a8d\u3057\u3001<span style=\"font-weight: 400;\">\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u3066\u3044\u308b\u30b3\u30f3\u30c6\u30f3\u30c4\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u304c 8799-8509 \u307e\u305f\u306f\u305d\u308c\u4ee5\u964d\u3067\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/span><\/p>\n<figure id=\"attachment_132436\" aria-describedby=\"caption-attachment-132436\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132436 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/F-6.png\" alt=\"\" width=\"900\" height=\"168\" \/><figcaption id=\"caption-attachment-132436\" class=\"wp-caption-text\">\u56f3 7. ATP \u306e\u30b3\u30f3\u30c6\u30f3\u30c4 \u30d0\u30fc\u30b8\u30e7\u30f3\u306e\u78ba\u8a8d\u65b9\u6cd5<\/figcaption><\/figure>\n<p><span style=\"font-weight: 400;\">\u9069\u5207\u306a\u30b3\u30f3\u30c6\u30f3\u30c4 \u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/span>\u3057\u305f\u5f8c\u3001<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Security Policy Rules (\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30dd\u30ea\u30b7\u30fc \u30eb\u30fc\u30eb)<\/span><span style=\"font-weight: 400;\">\u3092<span style=\"font-weight: 400;\">\u78ba\u8a8d\u3057\u3066<\/span>\u304f\u3060\u3055\u3044\u3002Vulnerability Protection (\u8106\u5f31\u6027\u9632\u5fa1) \u306e\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u306b\u306f\u5fc5\u305a\u300c<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">strict<\/span>\u300d\u3092\u4f7f\u7528\u3057\u3066\u304f\u3060\u3055\u3044\u3002CVE-2024-21887 \u306b\u95a2\u9023\u3059\u308b\u30b7\u30b0\u30cd\u30c1\u30e3\u306e\u6df1\u523b\u5ea6\u306f\u3059\u3079\u3066\u300cHigh (\u9ad8)\u300d\u307e\u305f\u306f\u300cCritical (\u7dca\u6025)\u300d\u3067\u3042\u308a\u3001\u5b9a\u7fa9\u6e08\u307f\u306e\u300c<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">strict<\/span>\u300d\u306e Vulnerability Protection (\u8106\u5f31\u6027\u9632\u5fa1) \u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3092\u4f7f\u3046\u3068\u4e21\u8005\u9593\u306e\u30bb\u30c3\u30b7\u30e7\u30f3\u304c\u30ea\u30bb\u30c3\u30c8\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_132438\" aria-describedby=\"caption-attachment-132438\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132438 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/F-7.png\" alt=\"\" width=\"900\" height=\"406\" \/><figcaption id=\"caption-attachment-132438\" class=\"wp-caption-text\">\u56f3 8. Vulnerability Protection (\u8106\u5f31\u6027\u9632\u5fa1) \u306e\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3092\u300cstrict\u300d\u306b\u8a2d\u5b9a\u3059\u308b\u65b9\u6cd5<\/figcaption><\/figure>\n<p>\u30ab\u30b9\u30bf\u30e0\u306e\u8106\u5f31\u6027\u9632\u5fa1\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3092\u4f7f\u3063\u3066\u3044\u308b\u5834\u5408\u306f\u3001<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Action (\u30a2\u30af\u30b7\u30e7\u30f3)<\/span>\u3092\u78ba\u8a8d\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">High (\u9ad8)<\/span>\u304a\u3088\u3073 <span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Critical (\u7dca\u6025) <\/span>\u306b\u3064\u3044\u3066\u306f\u300c<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">reset-both<\/span>\u300d\u3092\u8a2d\u5b9a\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<figure id=\"attachment_132440\" aria-describedby=\"caption-attachment-132440\" style=\"width: 859px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132440 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/F-8.png\" alt=\"\" width=\"859\" height=\"364\" \/><figcaption id=\"caption-attachment-132440\" class=\"wp-caption-text\">\u56f3 9. \u30ab\u30b9\u30bf\u30e0 Vulnerability Protection (\u8106\u5f31\u6027\u9632\u5fa1) \u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u306e\u8a2d\u5b9a\u65b9\u6cd5<\/figcaption><\/figure>\n<p><span style=\"font-weight: 400;\">\u6b63\u3057\u304f\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u3067 CVE-2024-21887 \u306b\u5bfe\u3059\u308b\u653b\u6483\u3092\u9632\u3052\u307e\u3059\u3002<\/span><\/p>\n<figure id=\"attachment_132442\" aria-describedby=\"caption-attachment-132442\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132442 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/F-9.png\" alt=\"\" width=\"900\" height=\"148\" \/><figcaption id=\"caption-attachment-132442\" class=\"wp-caption-text\">\u56f3 10. ATP \u306e\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u306b\u8868\u793a\u3055\u308c\u305f Ivanti \u306e\u8106\u5f31\u6027\u306b\u5bfe\u3059\u308b\u30a2\u30e9\u30fc\u30c8<\/figcaption><\/figure>\n<h4><a id=\"ivanti-2024-ICA\"><\/a>\u30a4\u30f3\u30e9\u30a4\u30f3 \u30af\u30e9\u30a6\u30c9\u5206\u6790<\/h4>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">Vulnerability Protection (\u8106\u5f31\u6027\u9632\u5fa1) <\/span>\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3067\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Enable cloud inline analysis (\u30af\u30e9\u30a6\u30c9 \u30a4\u30f3\u30e9\u30a4\u30f3\u5206\u6790\u306e\u6709\u52b9\u5316) <\/span> \u306e\u30c1\u30a7\u30c3\u30af \u30dc\u30c3\u30af\u30b9\u306b\u30c1\u30a7\u30c3\u30af\u304c\u5165\u3063\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002\u4e0b\u56f3\u306e\u30a6\u30a3\u30f3\u30c9\u30a6\u3067\u3001<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">SQL Injection (SQL \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3) <\/span>\u3068<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Command Injection (\u30b3\u30de\u30f3\u30c9 \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3)<\/span> \u30e2\u30c7\u30eb\u306e\u4e21\u65b9\u306e\u30a2\u30af\u30b7\u30e7\u30f3\u304c\u300c<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">reset-both<\/span>\u300d\u306b\u306a\u3063\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<figure id=\"attachment_132444\" aria-describedby=\"caption-attachment-132444\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132444 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/F-10.png\" alt=\"\" width=\"900\" height=\"704\" \/><figcaption id=\"caption-attachment-132444\" class=\"wp-caption-text\">\u56f3 11. \u30af\u30e9\u30a6\u30c9 \u30a4\u30f3\u30e9\u30a4\u30f3\u5206\u6790\u3092\u6709\u52b9\u306b\u3059\u308b\u65b9\u6cd5<\/figcaption><\/figure>\n<p><span style=\"font-weight: 400;\">\u6b63\u3057\u304f\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u3067 CVE-2024-21887 \u306b\u5bfe\u3059\u308b\u653b\u6483\u3092\u9632\u3052\u307e\u3059\u3002<\/span><\/p>\n<figure id=\"attachment_132446\" aria-describedby=\"caption-attachment-132446\" style=\"width: 1999px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132446 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/F-11.png\" alt=\"\" width=\"1999\" height=\"327\" \/><figcaption id=\"caption-attachment-132446\" class=\"wp-caption-text\">\u56f3 12. ATP \u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u306b\u8868\u793a\u3055\u308c\u305f CVE-2024-21887 \u306e\u8105\u5a01\u691c\u51fa<\/figcaption><\/figure>\n<h3><a id=\"post-132058-_6tj50ebqiikc\"><\/a>\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30af\u30e9\u30a6\u30c9\u914d\u4fe1\u578b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30fc\u30d3\u30b9<\/h3>\n<p><span style=\"font-weight: 400;\">\u3053\u306e\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3068\u95a2\u9023\u3059\u308b\u65e2\u77e5\u306e\u30c9\u30e1\u30a4\u30f3\u306f <\/span> <a href=\"https:\/\/docs.paloaltonetworks.com\/pan-os\/10-1\/pan-os-new-features\/url-filtering-features\/advanced-url-filtering\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Advanced URL Filtering<\/span><\/a><span style=\"font-weight: 400;\"> \u3068 <\/span><a href=\"https:\/\/docs.paloaltonetworks.com\/dns-security\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/a><span style=\"font-weight: 400;\"> \u306b\u3088\u308a\u300cmalicious (\u60aa\u610f\u3042\u308b\u3082\u306e)\u300d\u3068\u3057\u3066\u5206\u985e\u3055\u308c\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u8a66\u884c\u3068\u30b9\u30ad\u30e3\u30f3\u8a66\u884c\u306f\u3001<a href=\"https:\/\/docs.paloaltonetworks.com\/pan-os\/10-1\/pan-os-new-features\/url-filtering-features\/advanced-url-filtering\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Advanced URL Filtering<\/span><\/a> \u306b\u3088\u308a\u300c\u30b9\u30ad\u30e3\u30cb\u30f3\u30b0 \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u300d\u3068\u5206\u985e\u3055\u308c\u307e\u3059\u3002 <\/span><\/p>\n<h3><a id=\"ivanti-2024-advancedwildfire\"><\/a>Advanced WildFire<\/h3>\n<p><a href=\"https:\/\/docs.paloaltonetworks.com\/advanced-wildfire\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Advanced WildFire<\/span><\/a><span style=\"font-weight: 400;\"> \u306b\u306f\u3001\u3053\u308c\u3089\u306e\u653b\u6483\u306b\u4f7f\u7528\u3055\u308c\u308b\u30af\u30ea\u30d7\u30c8\u30de\u30a4\u30ca\u30fc\u306e\u691c\u51fa\u304c\u8ffd\u52a0\u3055\u308c\u307e\u3057\u305f\u3002<\/span><\/p>\n<h3><a id=\"post-132058-_2m49v0ag38qw\"><\/a>Cortex XDR \/ XSIAM<\/h3>\n<p><a href=\"https:\/\/docs-cortex.paloaltonetworks.com\/p\/XDR\" target=\"_blank\" rel=\"noopener\">Cortex XDR<\/a> \u304a\u3088\u3073 <a href=\"https:\/\/docs-cortex.paloaltonetworks.com\/p\/XSIAM\" target=\"_blank\" rel=\"noopener\">Cortex XSIAM <\/a>\u306f\u591a\u5c64\u4fdd\u8b77\u306e\u30a2\u30d7\u30ed\u30fc\u30c1\u306b\u3088\u308a\u3001\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u5f8c\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u304b\u3089\u306e\u4fdd\u8b77\u306b\u5f79\u7acb\u3061\u307e\u3059\u3002<\/p>\n<h3><a id=\"post-132058-_m5cvrg1ww3e6\"><\/a>Prisma Cloud<\/h3>\n<p><a href=\"https:\/\/docs.paloaltonetworks.com\/prisma\/prisma-cloud\" target=\"_blank\" rel=\"noopener\">Prisma Cloud<\/a> \u306f\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306b\u5bfe\u3059\u308b\u8106\u5f31\u6027\u306e\u78ba\u8a8d\u3055\u308c\u3066\u3044\u306a\u3044 Ivanti Cloud Secure \u88fd\u54c1\u3092\u76e3\u8996\u3057\u3066\u3044\u307e\u3059\u3002Prisma Cloud \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30ea\u30b5\u30fc\u30c1 \u30c1\u30fc\u30e0\u306f\u3001\u5f15\u304d\u7d9a\u304d\u72b6\u6cc1\u3092\u76e3\u8996\u3057\u3001Ivanti Cloud Connect \u304c\u3053\u308c\u3089\u306e\u8105\u5a01\u306b\u5bfe\u3057\u3066\u8106\u5f31\u3067\u3042\u308b\u3068\u5224\u660e\u3057\u305f\u5834\u5408\u3001 Prisma Cloud \u306e\u691c\u51fa\u7d50\u679c\u3092\u66f4\u65b0\u3057\u307e\u3059\u3002<\/p>\n<h3><a id=\"post-132058-_67p9j1tlynst\"><\/a>Cortex Xpanse<\/h3>\n<p><a href=\"https:\/\/docs-cortex.paloaltonetworks.com\/p\/XPANSE\" target=\"_blank\" rel=\"noopener\">Cortex Xpanse<\/a> \u3092\u3054\u5229\u7528\u306e\u304a\u5ba2\u69d8\u306f\u3001\u30a2\u30bf\u30c3\u30af \u30b5\u30fc\u30d5\u30a7\u30b9 (\u653b\u6483\u5bfe\u8c61\u9818\u57df) \u30eb\u30fc\u30eb\u300cIvanti Connect Secure\u300d\u304a\u3088\u3073\u300cIvanti Policy Secure\u300d\u3092\u901a\u3058\u3001\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u306b\u516c\u958b\u3055\u308c\u305f\u5f71\u97ff\u3092\u53d7\u3051\u308b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u7279\u5b9a\u3067\u304d\u307e\u3059\u3002<span style=\"font-weight: 400;\">\u5b89\u5168\u3067\u306a\u3044 Ivanti Connect Secure \u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u691c\u51fa\u306f\u3001\u5168\u9867\u5ba2\u306b\u3064\u3044\u3066\u30c7\u30d5\u30a9\u30eb\u30c8\u3067\u6709\u52b9\u3067\u3059\u3002<\/span><\/p>\n<figure id=\"attachment_132051\" aria-describedby=\"caption-attachment-132051\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-132051 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/word-image-132040-2-1.png\" alt=\"\u753b\u50cf 2 \u306f\u3001Cortex Xpanse \u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002Attack Surface Rules. Columns: Status, Severity, Rule Name, Description, Remediation Guidance, ASM Alert Categories.\" width=\"900\" height=\"240\" \/><figcaption id=\"caption-attachment-132051\" class=\"wp-caption-text\">\u56f3 13. Ivanti Policy Secure \u304a\u3088\u3073 Connect Secure \u306b\u3064\u3044\u3066\u691c\u51fa\u3092\u6709\u52b9\u306b\u3059\u308b\u8a2d\u5b9a\u3092\u8868\u793a\u3057\u3066\u3044\u308b Cortex Xpanse \u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9<\/figcaption><\/figure>\n<p>Cortex Xpanse \u306e Threat Response Center \u304b\u3089\u306f\u3001\u53b3\u9078\u3055\u308c\u305f\u8105\u5a01\u60c5\u5831\u306e\u6982\u8981\u3001\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306b\u3088\u308b\u5f71\u97ff\u3001\u4ee5\u524d\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3001\u8ffd\u52a0\u60c5\u5831\u53d6\u5f97\u7528\u306e\u5225\u30bd\u30fc\u30b9\u3078\u306e\u30ea\u30f3\u30af\u306a\u3069\u3092\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u7d44\u7e54\u306e\u3069\u3053\u306b\u3069\u306e\u3088\u3046\u306b\u30ea\u30b9\u30af\u304c\u5206\u5e03\u3057\u3066\u3044\u308b\u304b\u3092\u78ba\u8a8d\u3057\u305f\u4e0a\u3067\u3001\u63d0\u4f9b\u3055\u308c\u305f\u30ac\u30a4\u30c0\u30f3\u30b9\u306b\u57fa\u3065\u3044\u305f\u4fee\u5fa9\u8a08\u753b\u3092\u7acb\u3066\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002Cortex Xpanse \u306f\u30b5\u30fc\u30d3\u30b9\u306e\u6240\u6709\u8005\u3092\u81ea\u52d5\u7684\u306b\u8b58\u5225\u3059\u308b\u306e\u3067\u3001\u9069\u5207\u306a\u62c5\u5f53\u8005\u306b\u30c1\u30b1\u30c3\u30c8\u3092\u5272\u308a\u5f53\u3066\u308b\u3053\u3068\u3082\u5bb9\u6613\u3067\u3059\u3002<\/p>\n<h2><a id=\"ivanti-faqs\"><\/a>Ivanti \u306e\u3088\u304f\u3042\u308b\u8cea\u554f<\/h2>\n<p><b>\u8cea\u554f:<\/b><span style=\"font-weight: 400;\"> Ivanti \u304c\u6700\u8fd1\u5831\u544a\u3057\u305f\u65b0\u305f\u306a\u8106\u5f31\u6027\u306e\u4ef6\u6570\u306f\u4f55\u4ef6\u3067\u3059\u304b\u3002<\/span><\/p>\n<p><em><b>\u56de\u7b54: <\/b><span style=\"font-weight: 400;\">Ivanti \u304c 1 \u6708\u521d\u65ec\u4ee5\u964d\u5831\u544a\u3057\u305f\u8106\u5f31\u6027\u306e\u4ef6\u6570\u306f <a href=\"#post-132058-_wven14kmgum2\">5 \u4ef6\u3067\u3059\u3002\u300cHigh (\u9ad8)\u300d\u307e\u305f\u306f\u300cCritical (\u6df1\u523b)\u300d\u306e\u6df1\u523b\u5ea6\u3092\u3082\u3061\u307e\u3059<\/a>\u3002\u3053\u308c\u3089\u306f CVE-2023-46805\u3001CVE-2024-21887\u3001CVE-2024-21888\u3001CVE-2024-21893\u3001CVE-2024-22024 \u306e CVE \u756a\u53f7\u3067\u30c8\u30e9\u30c3\u30ad\u30f3\u30b0\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/span><\/em><\/p>\n<p><b>\u8cea\u554f: <\/b><span style=\"font-weight: 400;\">\u6700\u8fd1\u5831\u544a\u3055\u308c\u305f\u8106\u5f31\u6027\u306e\u5f71\u97ff\u3092\u53d7\u3051\u308b Ivanti \u88fd\u54c1\u306f\u3069\u308c\u3067\u3059\u304b\u3002<\/span><\/p>\n<p><em><b>\u56de\u7b54: <\/b><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306f\u3001Ivanti Connect Secure (\u30d0\u30fc\u30b8\u30e7\u30f3 9.x\u300122.x)\u3001Ivanti Policy Secure (\u30d0\u30fc\u30b8\u30e7\u30f3 9.x\u300122.x) \u88fd\u54c1\u306b\u5f71\u97ff\u3057\u307e\u3059\u3002CVE-2024-21893 \u3068 CVE-2024-22024 \u306f Ivanti Neurons for ZTA \u306b\u3082\u5f71\u97ff\u3057\u307e\u3059\u3002<\/span><\/em><\/p>\n<p><b>\u8cea\u554f: <\/b><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u304b\u3089\u3069\u306e\u3088\u3046\u306a\u5f71\u97ff\u3092\u53d7\u3051\u3046\u308b\u306e\u304b\u3092\u77e5\u308a\u305f\u3044\u3002<\/span><\/p>\n<p><em><b>\u56de\u7b54: <\/b><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u304c\u60aa\u7528\u3055\u308c\u305f\u5834\u5408\u3001\u7121\u8a31\u53ef\u306e\u8a8d\u8a3c\u30d0\u30a4\u30d1\u30b9\u3001\u30ea\u30e2\u30fc\u30c8 \u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u3001\u6a29\u9650\u6607\u683c\u3001\u30b5\u30fc\u30d0\u30fc\u30b5\u30a4\u30c9 \u30ea\u30af\u30a8\u30b9\u30c8 \u30d5\u30a9\u30fc\u30b8\u30a7\u30ea<a href=\"#ivanti-2024-techana\">\u304c\u8d77\u3053\u308a\u3048\u307e\u3059<\/a><\/span>\u3002<\/em><\/p>\n<p><b>\u8cea\u554f: <\/b><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306b\u3088\u308b\u5f71\u97ff\u3092\u53d7\u3051\u3046\u308b Ivanti \u30b7\u30b9\u30c6\u30e0\u306f\u4f55\u53f0\u3042\u308a\u307e\u3059\u304b\u3002<\/span><\/p>\n<p><em><b>\u56de\u7b54: <\/b><span style=\"font-weight: 400;\">Unit 42 \u306f\u3001<a href=\"#post-132058-_50343o6a6han\">2024 \u5e74 1 \u6708 26 \u65e5\u304b\u3089 30 \u65e5\u306e\u9593\u306b 145 \u304b\u56fd\u3067<\/a> 28,474 \u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e Ivanti Connect Secure \u304a\u3088\u3073 Policy Secure \u306e\u30a8\u30af\u30b9\u30dd\u30fc\u30b8\u30e3\u30fc (\u9732\u51fa) \u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002<\/span><\/em><\/p>\n<p><b>\u8cea\u554f: <\/b><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306e\u7a4d\u6975\u7684\u306a\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306f\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u304b\u3002<\/span><\/p>\n<p><em><b>\u56de\u7b54: <\/b><span style=\"font-weight: 400;\">\u306f\u3044\u3002\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306e\u3046\u3061 CVE-2023-46805\u3001CVE-2024-21887\u3001CVE-2024-21893 \u306e 3 \u3064\u306f\u3059\u3067\u306b\u3055\u307e\u3056\u307e\u306a\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u7a4d\u6975\u7684\u306b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306e\u3046\u3061\u6700\u521d\u306e 2 \u3064\u3001CVE-2023-46805 \u3068 CVE-2024-21887 \u306f\u3001\u5c11\u306a\u304f\u3068\u3082 2023 \u5e74 12 \u6708\u521d\u65ec\u304b\u3089\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/span><\/em><\/p>\n<p><b>\u8cea\u554f: <\/b><span style=\"font-weight: 400;\">\u653b\u6483\u8005\u304c\u91ce\u751f\u3067\u4f7f\u3063\u3066\u3044\u308b\u6226\u8853\u306f\u3069\u306e\u3088\u3046\u306a\u3082\u306e\u3067\u3059\u304b\u3002<\/span><\/p>\n<p><em><b>\u56de\u7b54: <\/b><span style=\"font-weight: 400;\"><a href=\"#ivanti-2024-exploit\">\u4e00\u90e8\u306e\u653b\u6483\u8005<\/a>\u306f\u3001\u904e\u53bb\u306e\u4e2d\u56fd\u3068\u3064\u306a\u304c\u308a\u306e\u3042\u308b APT \u4e8b\u4f8b\u3068\u4e00\u81f4\u3059\u308b TTP (\u6226\u8853\u30fb\u6280\u8853\u30fb\u624b\u9806) \u3092\u4f7f\u3063\u3066\u3044\u307e\u3059\u3002\u79c1\u305f\u3061\u304c\u89b3\u6e2c\u3057\u305f\u653b\u6483\u306f\u30012023 \u5e74 12 \u6708\u304b\u3089\u3001\u8907\u6570\u306e\u653b\u6483\u6ce2\u3068\u3057\u3066\u767a\u751f\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/span><\/em><\/p>\n<p><em><span style=\"font-weight: 400;\">\u7b2c 1 \u306e\u653b\u6483\u6ce2\u306f\u6a19\u7684\u578b\u3067\u3001\u8907\u6570\u306e\u30ab\u30b9\u30bf\u30e0 Web \u30b7\u30a7\u30eb\u3068\u30e9\u30c6\u30e9\u30eb \u30e0\u30fc\u30d6\u3092\u7279\u5fb4\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u653b\u6483\u6ce2\u306e\u653b\u6483\u8005\u306e\u306a\u304b\u306b\u306f\u3001 LSASS \u30d7\u30ed\u30bb\u30b9\u306e\u30e1\u30e2\u30ea\u30fc\u304b\u3089\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb (\u8a8d\u8a3c\u60c5\u5831) \u3092\u30c0\u30f3\u30d7\u3057\u3001\u305d\u308c\u3092\u4f7f\u3063\u3066\u5f71\u97ff\u3092\u53d7\u3051\u305f\u74b0\u5883\u306e\u30ef\u30fc\u30af\u30b9\u30c6\u30fc\u30b7\u30e7\u30f3\u3084\u30b5\u30fc\u30d0\u30fc\u306b\u30ed\u30b0\u30a4\u30f3\u3057\u3001\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3067\u5f97\u305f\u7d50\u679c\u3092\u6f0f\u51fa\u3055\u305b\u3066\u3044\u305f\u8005\u304c\u3044\u307e\u3057\u305f\u3002<\/span><\/em><\/p>\n<p><em><span style=\"font-weight: 400;\">\u7b2c 2 \u306e\u653b\u6483\u6ce2\u306f\u3001\u65b0\u305f\u306a\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u53c2\u5165\u306b\u3088\u308a\u3001\u6a19\u7684\u578b\u306e\u653b\u6483\u304b\u3089\u4e0d\u7279\u5b9a\u591a\u6570\u3078\u306e\u653b\u6483\u306b\u30b7\u30d5\u30c8\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u3055\u307e\u3056\u307e\u306a\u30e6\u30fc\u30b6\u30fc\u3084\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u30b9\u30ad\u30fc\u30de\u3001\u8a2d\u5b9a\u3001\u540d\u524d\u3001\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb (\u8a8d\u8a3c\u60c5\u5831) \u3092\u542b\u3080\u8a2d\u5b9a\u30c7\u30fc\u30bf\u3092\u30c0\u30f3\u30d7\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u5f7c\u3089\u306f\u7b2c 1 \u6ce2\u3067\u767a\u751f\u3057\u305f\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u306e\u3088\u3046\u306a\u30e9\u30c6\u30e9\u30eb \u30e0\u30fc\u30d6\u306f\u884c\u3063\u3066\u3044\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u00a0<\/span><\/em><\/p>\n<p><em><span style=\"font-weight: 400;\">\u7b2c 3 \u306e\u653b\u6483\u6ce2\u306f\u3001\u30af\u30ea\u30d7\u30c8\u30de\u30a4\u30ca\u30fc\u3084\u7a2e\u3005\u306e\u30ea\u30e2\u30fc\u30c8\u76e3\u8996\u30fb\u7ba1\u7406\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2 (RMM) \u306a\u3069\u3092\u5e83\u304f\u5c55\u958b\u3059\u308b\u72af\u7f6a\u30b0\u30eb\u30fc\u30d7\u3092\u306f\u3058\u3081\u3001\u3055\u307e\u3056\u307e\u306a\u52d5\u6a5f\u3084\u6280\u8853\u30ec\u30d9\u30eb\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3089\u306b\u3088\u308b\u5927\u898f\u6a21\u306a\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306b\u3064\u306a\u304c\u308a\u307e\u3057\u305f\u3002\u00a0<\/span><\/em><\/p>\n<p><b>\u8cea\u554f: <\/b><span style=\"font-weight: 400;\">\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306b\u5bfe\u51e6\u3059\u308b\u305f\u3081\u306b Ivanti \u306f\u3069\u306e\u3088\u3046\u306a\u5bfe\u7b56\u3092\u63a8\u5968\u3057\u3066\u3044\u307e\u3059\u304b\u3002<\/span><\/p>\n<p><em><b>\u56de\u7b54: <\/b><span style=\"font-weight: 400;\">Ivanti \u306f\u3001<a href=\"#post-132058-_zg1rezlvhwuy\">5 \u3064\u306e CVE \u3059\u3079\u3066\u306e\u30d1\u30c3\u30c1\u306e\u30ea\u30ea\u30fc\u30b9<\/a>\u3092\u958b\u59cb\u3057\u3001\u30d1\u30c3\u30c1\u304c\u307e\u3060\u63d0\u4f9b\u3055\u308c\u3066\u3044\u306a\u3044\u88fd\u54c1\u306b\u3064\u3044\u3066\u306f\u56de\u907f\u7b56\u3092\u5b9f\u884c\u3059\u308b\u3088\u3046\u540c\u793e\u9867\u5ba2\u306b\u63a8\u5968\u3057\u3066\u3044\u307e\u3059\u3002\u3055\u3089\u306b Ivanti \u306e\u5916\u90e8\u6574\u5408\u6027\u30c1\u30a7\u30c3\u30ab\u30fc\u3092\u5b9f\u884c\u3057\u3001\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u306b\u3064\u3044\u3066\u306e\u30ca\u30ec\u30c3\u30b8 \u30d9\u30fc\u30b9\u8a18\u4e8b\u306e\u6307\u793a\u306b\u5f93\u3046\u3053\u3068\u3082\u63a8\u5968\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/em><\/p>\n<p><script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [{\n    \"@type\": \"Question\",\n    \"name\": \"How many new vulnerabilities has Ivanti announced recently?\",\n    \"acceptedAnswer\": {\n      \"@type\": \"Answer\",\n      \"text\": \"Ivanti has announced five High or Critical vulnerabilities since the beginning of January. These are tracked as CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893 and CVE-2024-22024.\"\n    }\n  },{\n    \"@type\": \"Question\",\n    \"name\": \"Which Ivanti products are affected by the recently announced vulnerabilities?\",\n    \"acceptedAnswer\": {\n      \"@type\": \"Answer\",\n      \"text\": \"The vulnerabilities affect Ivanti's Connect Secure (versions 9.x, 22.x) and Policy Secure (versions 9.x, 22.x) products. Additionally, CVE-2024-21893 and CVE-2024-22024 also impact Ivanti Neurons for ZTA.\"\n    }\n  },{\n    \"@type\": \"Question\",\n    \"name\": \"What is the potential impact of these vulnerabilities?\",\n    \"acceptedAnswer\": {\n      \"@type\": \"Answer\",\n      \"text\": \"If exploited, these vulnerabilities can allow unauthorized authentication bypass, remote command execution, privilege escalation, and server-side request forgery.\"\n    }\n  },{\n    \"@type\": \"Question\",\n    \"name\": \"How many Ivanti systems are potentially affected by these vulnerabilities?\",\n    \"acceptedAnswer\": {\n      \"@type\": \"Answer\",\n      \"text\": \"Unit 42 observed 28,474 exposed instances of Ivanti Connect Secure and Policy Secure in 145 countries between Jan. 26-30, 2024.\"\n    }\n  },{\n    \"@type\": \"Question\",\n    \"name\": \"Are there any known active exploitations of these vulnerabilities?\",\n    \"acceptedAnswer\": {\n      \"@type\": \"Answer\",\n      \"text\": \"Yes, three of these vulnerabilities, CVE-2023-46805, CVE-2024-21887 and CVE-2024-21893 have been actively exploited by a range of threat actors. The first two of these vulnerabilities, CVE-2023-46805 and CVE-2024-21887, have been observed being exploited since at least early December 2023.\"\n    }\n  },{\n    \"@type\": \"Question\",\n    \"name\": \"What tactics are the attackers using in the wild?\",\n    \"acceptedAnswer\": {\n      \"@type\": \"Answer\",\n      \"text\": \"Some attackers are using tactics, techniques and procedures consistent with past China-nexus APT cases. The attacks we\u2019ve observed have come in multiple waves beginning in December 2023. The attacks in the first wave were targeted and featured multiple custom web shells and lateral movement. This wave also included attackers using credentials dumped from the memory of the LSASS process to log into workstations and servers in the affected environment and exfiltrating the output of this activity. The second wave shifted from targeted attacks to mass exploitation by additional threat actors. The threat actor dumped configuration data containing schema, settings, names and credentials of the various users and accounts within the network. They did not perform any lateral movements like the incidents that occurred in the first wave. The third wave led to mass exploitation by a range of threat actors with various motivations and degrees of sophistication, including criminal entities deploying cryptominers and various remote monitoring and management software.\"\n    }\n  },{\n    \"@type\": \"Question\",\n    \"name\": \"What measures have been recommended by Ivanti to address these vulnerabilities?\",\n    \"acceptedAnswer\": {\n      \"@type\": \"Answer\",\n      \"text\": \"Ivanti has begun releasing patches for all five CVEs and recommends customers perform a workaround for products that don\u2019t yet have an available patch. They also suggest running Ivanti\u2019s external integrity checker and following the instructions in its knowledge base article for these vulnerabilities.\"\n    }\n  }]\n}\n<\/script><\/p>\n<h2><a id=\"ivanti-2024-addit-resources\"><\/a>\u8ffd\u52a0\u30ea\u30bd\u30fc\u30b9<\/h2>\n<ul>\n<li class=\"article__header__title mb-sm-30 mb-40\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/threat-brief-cve-2023-35078\/\" target=\"_blank\" rel=\"noopener\">\u8105\u5a01\u306b\u95a2\u3059\u308b\u60c5\u5831: Ivanti Endpoint Manager Mobile \u306b\u30bc\u30ed\u30c7\u30a4\u306e\u30ea\u30e2\u30fc\u30c8\u306e\u672a\u8a8d\u8a3c API \u30a2\u30af\u30bb\u30b9\u3092\u542b\u3080\u8907\u6570\u306e\u8106\u5f31\u6027 (CVE-2023-35078, CVE-2023-35081, CVE-2023-35082, CVE-2023-32560, CVE-2023-3803)<\/a> \u2013 \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9 Unit 42<\/li>\n<li class=\"article__header__title mb-sm-30 mb-40\"><a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/ivanti-VPN-vulnerability-what-you-need-to-know\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Ivanti VPN Vulnerability: What You Need to Know<\/span><\/a><span style=\"font-weight: 400;\"> \u2013 Cyberpedia, Palo Alto Networks<\/span><\/li>\n<li><a href=\"https:\/\/www.paloaltonetworks.com\/Ivanti-VPN-exploit-response\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Ivanti Vulnerabilities Overview<\/span><\/a><span style=\"font-weight: 400;\"> \u2013 Palo Alto Networks<\/span><\/li>\n<\/ul>\n<h2><a id=\"ivanti-2024-appendix\"><\/a>\u4ed8\u9332<\/h2>\n<p><span style=\"font-weight: 400;\">Ivanti \u306e\u8106\u5f31\u6027\u306e\u30b9\u30ad\u30e3\u30f3\u307e\u305f\u306f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304c\u691c\u51fa\u3055\u308c\u305f IP \u30a2\u30c9\u30ec\u30b9:<\/span><b><\/b><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">1.65.216[.]83<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">8.220.24[.]104<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">5.188.34[.]119<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">5.188.230[.]159<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">8.210.101[.]116<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">20.0.28[.]174<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">23.224.195[.]27<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">27.199.34[.]232<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">37.19.207[.]89<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">38.47.103[.]245<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">39.144.158[.]6<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">45.14.244[.]52<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">45.76.92[.]144<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">45.133.238[.]41<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">45.147.51[.]78<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">50.114.59[.]3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">50.114.59[.]5<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">51.255.62[.]4<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">51.255.62[.]12<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">52.172.236[.]151<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">54.38.214[.]131<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">64.176.194[.]7<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">74.48.82[.]246<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">84.32.131[.]51<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">84.32.248[.]20<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">85.106.119[.]0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">88.151.32[.]164<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">89.185.30[.]166<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">91.203.134[.]122<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">93.95.228[.]81<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">94.131.105[.]192<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">95.164.22[.]41<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">97.106.38[.]138<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">101.71.37[.]222<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">103.119.174[.]37<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">103.189.234[.]200<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">103.233.11[.]5<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">103.235.16[.]57<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">104.223.91[.]19<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">104.238.130[.]6<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">106.52.127[.]12<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">111.85.176[.]202<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">111.90.143[.]184<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">111.253.200[.]166<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">112.96.226[.]103<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">113.128.81[.]59<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">113.137.148[.]49<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">113.225.152[.]7<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">114.236.225[.]219<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">116.204.211[.]132<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">118.74.246[.]29<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">118.74.246[.]133<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">118.74.90[.]191<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">118.167.12[.]237<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">122.155.209[.]123<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">137.175.19[.]209<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">139.162.21[.]6<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">139.227.33[.]78<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">149.104.23[.]171<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">159.203.33[.]199<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">161.35.44[.]205<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">161.35.172[.]122<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">167.114.113[.]160<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">167.172.250[.]222<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">170.64.149[.]53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">172.59.193[.]252<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">171.241.43[.]110<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">172.232.146[.]231<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">174.135.110[.]233<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">178.17.169[.]245<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">182.239.92[.]100<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">183.128.182[.]227<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">185.132.125[.]11<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">185.152.67[.]168<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">185.156.72[.]51<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">185.212.61[.]84<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">185.217.125[.]210<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">185.243.41[.]201<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">185.244.208[.]65<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">185.248.185[.]93<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">194.233.93[.]67<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">195.85.115[.]80<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">202.55.67[.]195<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">203.160.86[.]236<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">210.182.85[.]3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">212.71.232[.]212<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">220.246.88[.]207<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">221.15.158[.]245<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">221.216.117[.]171<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">222.180.198[.]54<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">223.70.179[.]234<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-family: 'courier new', courier, monospace;\">223.104.151[.]181<\/span><\/li>\n<\/ul>\n<p>Ivanti \u306e\u8106\u5f31\u6027\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3057\u3066\u3044\u305f\u60aa\u8cea\u306a\u30da\u30a4\u30ed\u30fc\u30c9:<\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">103.233.11[.]5:1999\/doc<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">45.130.22[.]219\/ivanti.js<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">45.130.22[.]219\/ivanti<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">138.68.61[.]82<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">192.252.183[.]116<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">137.220.130[.]2\/doc<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">124.156.132[.]142:6999\/python<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">141.98.7[.]6<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">103.215.77[.]51<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">45.152.66[.]151<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">raw.githubusercontent[.]com\/momika233\/test\/main\/m.sh<\/span><\/li>\n<\/ul>\n<p class=\"p1\"><i>2024-01-18 09:30 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-01-16 14:00 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001Threat Prevension \u30b7\u30b0\u30cd\u30c1\u30e3\u30fc\u3092\u8ffd\u52a0\u3001\u300c\u8ffd\u52a0\u30ea\u30bd\u30fc\u30b9\u300d\u30bb\u30af\u30b7\u30e7\u30f3\u306b\u53c2\u8003\u8cc7\u6599\u3092\u8ffd\u8a18\u00a0<\/i><\/p>\n<p><em>2024-01-22 13:00 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-01-19 11:00 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001\u88fd\u54c1\u306b\u3088\u308b\u4fdd\u8b77\u7bc4\u56f2\u306e\u62e1\u5927\u3001\u305d\u306e\u307b\u304b\u306e\u8a73\u7d30\u60c5\u5831\u3092\u8ffd\u8a18\u00a0<\/em><\/p>\n<p><em>2024-02-02 10:15 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-01 07:32 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001Ivanti \u304c\u66f4\u65b0\u3057\u305f\u5fa9\u65e7\u624b\u9806\u3001Volexity \u306e\u767a\u898b\u5185\u5bb9\u306e\u8a73\u7d30\u3092\u8ffd\u8a18\u00a0<\/em><\/p>\n<p><em>2024-02-02 10:15 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-01 14:48 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001Ivanti \u304c\u958b\u793a\u3057\u305f\u65b0\u305f\u306a\u8106\u5f31\u6027\u304a\u3088\u3073\u52e7\u544a\u306b\u3064\u3044\u3066\u8ffd\u8a18\u00a0\u00a0<\/em><\/p>\n<p><em>2024-02-05 15:00 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-02 13:31 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001CISA \u304b\u3089\u306e\u30a2\u30c9\u30d0\u30a4\u30b6\u30ea\u30fc\u306e\u6642\u523b\u3092\u6539\u8a02\u00a0<\/em><\/p>\n<p><em>2024-02-05 15:00 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-02 17:23 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001\u672c\u7a3f\u3092\u5927\u5e45\u6539\u8a02\u3002Invati \u306b\u3088\u308b\u52e7\u544a\u5185\u5bb9\u306e\u62e1\u5145\u3001Unit 42 \u306b\u3088\u308b\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u4e8b\u4f8b\u306e\u60c5\u5831\u3001\u30b9\u30ad\u30e3\u30f3 \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3001\u30c6\u30ec\u30e1\u30c8\u30ea\u30fc\u3084\u30b0\u30e9\u30d5\u306e\u66f4\u65b0\u306a\u3069\u00a0<\/em><\/p>\n<p><em>2024-02-05 15:00 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-03 09:30 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001\u7d44\u7e54\u3092 Ivanti \u306e\u8106\u5f31\u6027\u304b\u3089\u304f\u308b\u3042\u3089\u3086\u308b\u9732\u51fa\u306e\u7279\u5b9a\u30fb\u7de9\u548c\u3067\u652f\u63f4\u3059\u308b\u305f\u3081\u306e\u7121\u511f\u30fb\u4ed8\u5e2f\u6761\u4ef6\u306a\u3057\u306e\u7dca\u6025\u30d0\u30f3\u30c9\u30eb\u306b\u95a2\u3059\u308b\u60c5\u5831\u3092\u66f4\u65b0<\/em><\/p>\n<p><em>2024-02-05 15:00 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-03 11:00 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001IoC \u306e\u8aa4\u8a18\u3092\u4fee\u6b63<\/em><\/p>\n<p><em>2024-02-07 17:30 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-06 13:30 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\u3001\u6280\u8853\u5206\u6790\u3001\u91ce\u751f\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306b\u3064\u3044\u3066\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3092\u8ffd\u52a0\u3002Advanced Threat Prevention \u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3092\u62e1\u5f35\u3002Threat Prevention \u30b7\u30b0\u30cd\u30c1\u30e3\u3092\u8ffd\u8a18\u3002\u88fd\u54c1\u306b\u3088\u308b\u4fdd\u8b77\u306b Advanced WildFire \u3092\u8ffd\u8a18\u3002\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u52d5\u753b\u300cSecurity in 42 Seconds (42 \u79d2\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3)\u300d\u3092\u66f4\u65b0\u00a0<\/em><\/p>\n<p><em>2024-02-07 17:30 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-06 15:21 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001\u56f3 1\u301c3 \u306e\u30ad\u30e3\u30d7\u30b7\u30e7\u30f3\u306b\u30bd\u30fc\u30b9 \u30c7\u30fc\u30bf\u3092\u8ffd\u8a18\u00a0<\/em><\/p>\n<p><em>2024-02-08 09:45 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-07 14:56 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u7528\u8a9e\u3092\u4fee\u6b63<\/em><\/p>\n<p><em>2024-02-09 10:30 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-08 12:30 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001Ivanti \u304c\u958b\u793a\u3057\u305f <\/em><span style=\"font-weight: 400;\"><em>CVE-2024-22024 \u306b\u3064\u3044\u3066\u8ffd\u8a18\u3002\u8ffd\u52a0\u30ea\u30bd\u30fc\u30b9\u3078\u306e\u30ea\u30f3\u30af\u3092\u8ffd\u52a0\u3002\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\u3092\u66f4\u65b0<\/em><\/span><\/p>\n<p><em>2024-02-09 10:30 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-08 14:10 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u300c\u3088\u304f\u3042\u308b\u8cea\u554f\u300d\u30bb\u30af\u30b7\u30e7\u30f3\u3092\u8ffd\u52a0\u00a0<\/em><\/p>\n<p><em>2024-02-14 09:30 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-13 12:25 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057Threat Prevention \u30b7\u30b0\u30cd\u30c1\u30e3 95024 \u3092\u8ffd\u52a0<\/em><\/p>\n<p><em>2024-02-19 09:50 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-15 12:14 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001\u7dca\u6025\u30d0\u30f3\u30c9\u30eb\u306e\u30aa\u30d5\u30a1\u30fc\u306b\u95a2\u3059\u308b\u6587\u8a00\u3092\u6539\u6b63<\/em><\/p>\n<p><em>2023-02-21 09:30 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-20 08:02 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057 Unit 42 Threat Vector \u30dd\u30c3\u30c9\u30ad\u30e3\u30b9\u30c8\u3078\u306e\u30ea\u30f3\u30af\u3092\u8ffd\u8a18<\/em><\/p>\n<p><em>2024-02-21 09:30 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-20 12:32 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u300cIvanti \u88fd\u54c1\u306b\u5bfe\u3059\u308b\u73fe\u5728\u306e\u653b\u6483\u30b9\u30b3\u30fc\u30d7\u300d\u300cUnit 42 \u306b\u3088\u308b\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u4e8b\u4f8b\u300d\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u306b\u8a73\u7d30\u3092\u8ffd\u8a18\u3002\u300c\u6280\u8853\u5206\u6790\u300d\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3092\u7de8\u96c6\u3002\u6982\u8981\u306e 4 \u6bb5\u843d\u76ee\u306e CVE \u756a\u53f7\u3092\u4fee\u6b63\u3002\u00a0<\/em><\/p>\n<p><em>2024-03-01 09:45 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2024-02-29 12:20 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620\u3057\u3001CISA \u306b\u3088\u308b\u5408\u540c\u52e7\u544a (CSA) \u306e\u60c5\u5831\u3092\u8ffd\u8a18\u3057\u3001\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\u3092\u66f4\u65b0\u3002\u00a0<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>3 \u6708 1 \u65e5 JST \u66f4\u65b0 \u7c73\u56fd\u653f\u5e9c\u306f\u56fd\u969b\u7684\u306a\u653f\u5e9c\u306e\u540c\u76df\u56fd\u3068\u5354\u529b\u3057\u3001\u540c\u30b0\u30eb\u30fc\u30d7\u306e\u6d3b\u52d5\u306b\u95a2\u3059\u308b\u5408\u540c\u30b5\u30a4\u30d0\u30fc\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u52e7\u544a (CSA) \u3092\u767a\u8868\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u52e7\u544a\u306b\u306f\u3001Ivanti \u88fd\u54c1\u306e\u8106\u5f31\u6027\u60aa\u7528\u306b\u95a2\u3059\u308b\u6700\u8fd1\u306e\u8abf\u67fb\u7d50\u679c\u3082<\/p>\n","protected":false},"author":23,"featured_media":135216,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4432,4470],"tags":[4741,4743,4745,4747,4749,4545,4751],"product_categories":[4441,4442,4443,4450,4451,4456],"coauthors":[1025],"class_list":["post-132058","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-top-cyberthreats-ja","category-vulnerabilities-ja","tag-cve-2023-46805-ja","tag-cve-2024-21887-ja","tag-cve-2024-21888-ja","tag-cve-2024-21893-ja","tag-cve-2024-22024-ja","tag-ivanti-ja","tag-vpns-ja","product_categories-advanced-dns-security-ja","product_categories-advanced-threat-prevention-ja","product_categories-advanced-url-filtering-ja","product_categories-cortex-xsiam-ja","product_categories-cortex-xsoar-ja","product_categories-next-generation-firewall-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>[2024-03-01 JST \u66f4\u65b0] \u8105\u5a01\u306b\u95a2\u3059\u308b\u60c5\u5831: Ivanti Connect Secure\u3001Ivanti Policy Secure \u306b\u304a\u3051\u308b\u8106\u5f31\u6027 (CVE-2023-46805\u3001CVE-2024-21887\u3001CVE-2024-21888\u3001CVE-2024-21893\u3001CVE-2024-22024)<\/title>\n<meta name=\"description\" content=\"Ivanti\u306f\u540c\u793eVPN\u88fd\u54c1\u306b\u5b58\u5728\u3059\u308b2\u3064\u306e\u8106\u5f31CVE-2023-46805(\u6df1\u523b\u5ea6: \u9ad8)\u3068CVE-2024-21887(\u6df1\u523b\u5ea6: \u7dca\u6025) \u958b\u793a\u3057\u307e\u3057\u305f\u3002\u4e21\u8106\u5f31\u6027\u3092\u9023\u9396\u7684\u306b\u5229\u7528\u3059\u308c\u3070\u653b\u6483\u8005\u304c\u6a19\u7684\u30a2\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u4e0a\u3067\u8a8d\u8a3c\u4e0d\u8981\u3067\u4efb\u610f\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"[2024-03-01 JST \u66f4\u65b0] \u8105\u5a01\u306b\u95a2\u3059\u308b\u60c5\u5831: Ivanti Connect Secure\u3001Ivanti Policy Secure \u306b\u304a\u3051\u308b\u8106\u5f31\u6027 (CVE-2023-46805\u3001CVE-2024-21887\u3001CVE-2024-21888\u3001CVE-2024-21893\u3001CVE-2024-22024)\" \/>\n<meta property=\"og:description\" content=\"Ivanti\u306f\u540c\u793eVPN\u88fd\u54c1\u306b\u5b58\u5728\u3059\u308b2\u3064\u306e\u8106\u5f31CVE-2023-46805(\u6df1\u523b\u5ea6: \u9ad8)\u3068CVE-2024-21887(\u6df1\u523b\u5ea6: \u7dca\u6025) \u958b\u793a\u3057\u307e\u3057\u305f\u3002\u4e21\u8106\u5f31\u6027\u3092\u9023\u9396\u7684\u306b\u5229\u7528\u3059\u308c\u3070\u653b\u6483\u8005\u304c\u6a19\u7684\u30a2\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u4e0a\u3067\u8a8d\u8a3c\u4e0d\u8981\u3067\u4efb\u610f\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-17T01:52:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-06-24T12:12:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/unit42-vulnerabilities.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Unit 42\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"[2024-03-01 JST \u66f4\u65b0] \u8105\u5a01\u306b\u95a2\u3059\u308b\u60c5\u5831: Ivanti Connect Secure\u3001Ivanti Policy Secure \u306b\u304a\u3051\u308b\u8106\u5f31\u6027 (CVE-2023-46805\u3001CVE-2024-21887\u3001CVE-2024-21888\u3001CVE-2024-21893\u3001CVE-2024-22024)","description":"Ivanti\u306f\u540c\u793eVPN\u88fd\u54c1\u306b\u5b58\u5728\u3059\u308b2\u3064\u306e\u8106\u5f31CVE-2023-46805(\u6df1\u523b\u5ea6: \u9ad8)\u3068CVE-2024-21887(\u6df1\u523b\u5ea6: \u7dca\u6025) \u958b\u793a\u3057\u307e\u3057\u305f\u3002\u4e21\u8106\u5f31\u6027\u3092\u9023\u9396\u7684\u306b\u5229\u7528\u3059\u308c\u3070\u653b\u6483\u8005\u304c\u6a19\u7684\u30a2\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u4e0a\u3067\u8a8d\u8a3c\u4e0d\u8981\u3067\u4efb\u610f\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/","og_locale":"ja_JP","og_type":"article","og_title":"[2024-03-01 JST \u66f4\u65b0] \u8105\u5a01\u306b\u95a2\u3059\u308b\u60c5\u5831: Ivanti Connect Secure\u3001Ivanti Policy Secure \u306b\u304a\u3051\u308b\u8106\u5f31\u6027 (CVE-2023-46805\u3001CVE-2024-21887\u3001CVE-2024-21888\u3001CVE-2024-21893\u3001CVE-2024-22024)","og_description":"Ivanti\u306f\u540c\u793eVPN\u88fd\u54c1\u306b\u5b58\u5728\u3059\u308b2\u3064\u306e\u8106\u5f31CVE-2023-46805(\u6df1\u523b\u5ea6: \u9ad8)\u3068CVE-2024-21887(\u6df1\u523b\u5ea6: \u7dca\u6025) \u958b\u793a\u3057\u307e\u3057\u305f\u3002\u4e21\u8106\u5f31\u6027\u3092\u9023\u9396\u7684\u306b\u5229\u7528\u3059\u308c\u3070\u653b\u6483\u8005\u304c\u6a19\u7684\u30a2\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u4e0a\u3067\u8a8d\u8a3c\u4e0d\u8981\u3067\u4efb\u610f\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/","og_site_name":"Unit 42","article_published_time":"2024-01-17T01:52:59+00:00","article_modified_time":"2024-06-24T12:12:00+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/unit42-vulnerabilities.jpg","type":"image\/jpeg"}],"author":"Unit 42","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/"},"author":{"name":"Unit 42","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"headline":"[2024-03-01 JST \u66f4\u65b0] \u8105\u5a01\u306b\u95a2\u3059\u308b\u60c5\u5831: Ivanti Connect Secure\u3001Ivanti Policy Secure \u306b\u304a\u3051\u308b\u8106\u5f31\u6027 (CVE-2023-46805\u3001CVE-2024-21887\u3001CVE-2024-21888\u3001CVE-2024-21893\u3001CVE-2024-22024)","datePublished":"2024-01-17T01:52:59+00:00","dateModified":"2024-06-24T12:12:00+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/"},"wordCount":1167,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/unit42-vulnerabilities.jpg","keywords":["CVE-2023-46805","CVE-2024-21887","CVE-2024-21888","CVE-2024-21893","CVE-2024-22024","Ivanti","VPNs"],"articleSection":["\u4e3b\u306a\u30b5\u30a4\u30d0\u30fc\u8105\u5a01","\u8106\u5f31\u6027"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/","name":"[2024-03-01 JST \u66f4\u65b0] \u8105\u5a01\u306b\u95a2\u3059\u308b\u60c5\u5831: Ivanti Connect Secure\u3001Ivanti Policy Secure \u306b\u304a\u3051\u308b\u8106\u5f31\u6027 (CVE-2023-46805\u3001CVE-2024-21887\u3001CVE-2024-21888\u3001CVE-2024-21893\u3001CVE-2024-22024)","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/unit42-vulnerabilities.jpg","datePublished":"2024-01-17T01:52:59+00:00","dateModified":"2024-06-24T12:12:00+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"description":"Ivanti\u306f\u540c\u793eVPN\u88fd\u54c1\u306b\u5b58\u5728\u3059\u308b2\u3064\u306e\u8106\u5f31CVE-2023-46805(\u6df1\u523b\u5ea6: \u9ad8)\u3068CVE-2024-21887(\u6df1\u523b\u5ea6: \u7dca\u6025) \u958b\u793a\u3057\u307e\u3057\u305f\u3002\u4e21\u8106\u5f31\u6027\u3092\u9023\u9396\u7684\u306b\u5229\u7528\u3059\u308c\u3070\u653b\u6483\u8005\u304c\u6a19\u7684\u30a2\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u4e0a\u3067\u8a8d\u8a3c\u4e0d\u8981\u3067\u4efb\u610f\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/#primaryimage","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/unit42-vulnerabilities.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/01\/unit42-vulnerabilities.jpg","width":1920,"height":900},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/threat-brief-ivanti-cve-2023-46805-cve-2024-21887\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"[2024-03-01 JST \u66f4\u65b0] \u8105\u5a01\u306b\u95a2\u3059\u308b\u60c5\u5831: Ivanti Connect Secure\u3001Ivanti Policy Secure \u306b\u304a\u3051\u308b\u8106\u5f31\u6027 (CVE-2023-46805\u3001CVE-2024-21887\u3001CVE-2024-21888\u3001CVE-2024-21893\u3001CVE-2024-22024)"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63","name":"Unit 42","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/4ffb3c2d260a0150fb91b3715442f8b3","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Unit 42"},"url":"https:\/\/unit42.paloaltonetworks.com\/ja\/author\/unit42\/"}]}},"_links":{"self":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/132058","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=132058"}],"version-history":[{"count":24,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/132058\/revisions"}],"predecessor-version":[{"id":134976,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/132058\/revisions\/134976"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/135216"}],"wp:attachment":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=132058"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=132058"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=132058"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=132058"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=132058"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}