{"id":476522,"date":"2023-08-09T07:29:55","date_gmt":"2023-08-09T07:29:55","guid":{"rendered":""},"modified":"2023-09-05T11:12:54","modified_gmt":"2023-09-05T11:12:54","slug":"cve","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/vn\/wiki\/cve\/","title":{"rendered":"CVE"},"content":{"rendered":"<p>C\u00e1c l\u1ed7 h\u1ed5ng v\u00e0 r\u1ee7i ro ph\u1ed5 bi\u1ebfn (CVE) l\u00e0 m\u1ed9t h\u1ec7 th\u1ed1ng ti\u00eau chu\u1ea9n \u0111\u1ec3 x\u00e1c \u0111\u1ecbnh v\u00e0 c\u00f4ng b\u1ed1 c\u00e1c l\u1ed7 h\u1ed5ng an ninh m\u1ea1ng. M\u1ee5c \u0111\u00edch ch\u00ednh c\u1ee7a n\u00f3 l\u00e0 t\u1ea1o \u0111i\u1ec1u ki\u1ec7n thu\u1eadn l\u1ee3i cho vi\u1ec7c chia s\u1ebb v\u00e0 ph\u00e2n ph\u1ed1i d\u1eef li\u1ec7u v\u1ec1 c\u00e1c l\u1ed7 h\u1ed5ng nh\u1eb1m h\u1ed7 tr\u1ee3 c\u00e1c chi\u1ebfn l\u01b0\u1ee3c ph\u00f2ng th\u1ee7 t\u1ed1t h\u01a1n v\u00e0 th\u00fac \u0111\u1ea9y s\u1ef1 h\u1ee3p t\u00e1c trong c\u1ed9ng \u0111\u1ed3ng an ninh m\u1ea1ng.<\/p>\n<h2>L\u1ecbch s\u1eed v\u00e0 ngu\u1ed3n g\u1ed1c c\u1ee7a CVE<\/h2>\n<p>Kh\u00e1i ni\u1ec7m CVE b\u1eaft ngu\u1ed3n t\u1eeb cu\u1ed1i nh\u1eefng n\u0103m 1990 trong c\u1ed9ng \u0111\u1ed3ng b\u1ea3o m\u1eadt m\u00e1y t\u00ednh, ch\u1ee7 y\u1ebfu l\u00e0 s\u00e1ng ki\u1ebfn c\u1ee7a MITER Corporation. H\u1ec7 th\u1ed1ng n\u00e0y \u0111\u01b0\u1ee3c ra m\u1eaft v\u00e0o th\u00e1ng 9 n\u0103m 1999 v\u1edbi Danh s\u00e1ch CVE \u0111\u1ea7u ti\u00ean, m\u1ed9t c\u01a1 s\u1edf d\u1eef li\u1ec7u v\u1ec1 c\u00e1c m\u00e3 nh\u1eadn d\u1ea1ng \u0111\u01b0\u1ee3c ti\u00eau chu\u1ea9n h\u00f3a cho c\u00e1c l\u1ed7 h\u1ed5ng an ninh m\u1ea1ng \u0111\u00e3 bi\u1ebft.<\/p>\n<p>M\u1ee5c \u0111\u00edch ban \u0111\u1ea7u c\u1ee7a CVE l\u00e0 cung c\u1ea5p m\u1ed9t ng\u00f4n ng\u1eef chung \u0111\u1ec3 th\u1ea3o lu\u1eadn v\u00e0 chia s\u1ebb th\u00f4ng tin v\u1ec1 c\u00e1c l\u1ed7 h\u1ed5ng. Tr\u01b0\u1edbc khi gi\u1edbi thi\u1ec7u CVE, c\u00e1c nh\u00e0 cung c\u1ea5p v\u00e0 nh\u00e0 nghi\u00ean c\u1ee9u kh\u00e1c nhau \u0111\u00e3 s\u1eed d\u1ee5ng c\u00e1c t\u00ean v\u00e0 m\u00f4 t\u1ea3 kh\u00e1c nhau cho c\u00f9ng m\u1ed9t l\u1ed7 h\u1ed5ng, d\u1eabn \u0111\u1ebfn nh\u1ea7m l\u1eabn v\u00e0 hi\u1ec3u sai.<\/p>\n<h2>Hi\u1ec3u CVE<\/h2>\n<p>M\u1ed7i M\u1ee5c nh\u1eadp CVE bao g\u1ed3m m\u1ed9t s\u1ed1 nh\u1eadn d\u1ea1ng, m\u1ed9t m\u00f4 t\u1ea3 v\u00e0 \u00edt nh\u1ea5t m\u1ed9t t\u00e0i li\u1ec7u tham kh\u1ea3o c\u00f4ng khai. S\u1ed1 nh\u1eadn d\u1ea1ng tu\u00e2n theo \u0111\u1ecbnh d\u1ea1ng c\u1ee5 th\u1ec3: CVE-YYYY-NNNNN, trong \u0111\u00f3 \u201cYYYY\u201d l\u00e0 n\u0103m ID CVE \u0111\u01b0\u1ee3c ch\u1ec9 \u0111\u1ecbnh ho\u1eb7c l\u1ed7 h\u1ed5ng \u0111\u01b0\u1ee3c c\u00f4ng khai v\u00e0 \u201cNNNNN\u201d l\u00e0 s\u1ed1 duy nh\u1ea5t cho l\u1ed7 h\u1ed5ng \u0111\u00f3.<\/p>\n<p>H\u1ec7 th\u1ed1ng CVE kh\u00f4ng cung c\u1ea5p b\u1ea5t k\u1ef3 th\u00f4ng tin n\u00e0o v\u1ec1 m\u1ee9c \u0111\u1ed9 nghi\u00eam tr\u1ecdng ho\u1eb7c r\u1ee7i ro li\u00ean quan \u0111\u1ebfn m\u1ed9t l\u1ed7 h\u1ed5ng c\u1ee5 th\u1ec3. Tuy nhi\u00ean, n\u00f3 cung c\u1ea5p c\u01a1 s\u1edf c\u01a1 s\u1edf \u0111\u1ec3 c\u00e1c t\u1ed5 ch\u1ee9c kh\u00e1c, nh\u01b0 C\u01a1 s\u1edf d\u1eef li\u1ec7u v\u1ec1 l\u1ed7 h\u1ed5ng qu\u1ed1c gia (NVD), c\u00f3 th\u1ec3 \u0111\u00ednh k\u00e8m si\u00eau d\u1eef li\u1ec7u b\u1ed5 sung, ch\u1eb3ng h\u1ea1n nh\u01b0 \u0111i\u1ec3m r\u1ee7i ro ho\u1eb7c ch\u1ec9 s\u1ed1 kh\u1ea3 n\u0103ng khai th\u00e1c.<\/p>\n<h2>C\u1ea5u tr\u00fac b\u00ean trong v\u00e0 ch\u1ee9c n\u0103ng c\u1ee7a CVE<\/h2>\n<p>H\u1ec7 th\u1ed1ng CVE ho\u1ea1t \u0111\u1ed9ng b\u1eb1ng c\u00e1ch g\u00e1n m\u1ed9t m\u00e3 \u0111\u1ecbnh danh duy nh\u1ea5t cho m\u1ecdi l\u1ed7 h\u1ed5ng \u0111\u00e3 bi\u1ebft. M\u00e3 \u0111\u1ecbnh danh n\u00e0y gi\u00fap nh\u1eefng ng\u01b0\u1eddi th\u1ef1c hi\u1ec7n b\u1ea3o m\u1eadt \u0111\u1ec1 c\u1eadp \u0111\u1ebfn m\u1ed9t l\u1ed7 h\u1ed5ng c\u1ee5 th\u1ec3 b\u1eb1ng c\u00e1ch s\u1eed d\u1ee5ng m\u1ed9t ng\u00f4n ng\u1eef chung, h\u1ed7 tr\u1ee3 c\u00e1c n\u1ed7 l\u1ef1c gi\u1ea3m thi\u1ec3u.<\/p>\n<p>ID CVE \u0111\u01b0\u1ee3c y\u00eau c\u1ea7u v\u00e0 ch\u1ec9 \u0111\u1ecbnh b\u1edfi C\u01a1 quan \u0111\u00e1nh s\u1ed1 CVE (CNA). CNA l\u00e0 c\u00e1c t\u1ed5 ch\u1ee9c t\u1eeb kh\u1eafp n\u01a1i tr\u00ean th\u1ebf gi\u1edbi \u0111\u00e3 h\u1ee3p t\u00e1c v\u1edbi Ch\u01b0\u01a1ng tr\u00ecnh CVE \u0111\u1ec3 g\u00e1n ID CVE cho c\u00e1c l\u1ed7 h\u1ed5ng \u1ea3nh h\u01b0\u1edfng \u0111\u1ebfn s\u1ea3n ph\u1ea9m trong ph\u1ea1m vi ri\u00eang bi\u1ec7t \u0111\u00e3 \u0111\u01b0\u1ee3c th\u1ed1ng nh\u1ea5t c\u1ee7a h\u1ecd.<\/p>\n<p>Danh s\u00e1ch CVE do MITER duy tr\u00ec sau \u0111\u00f3 \u0111\u01b0\u1ee3c c\u1eadp nh\u1eadt v\u1edbi c\u00e1c m\u1ee5c m\u1edbi n\u00e0y. C\u01a1 s\u1edf d\u1eef li\u1ec7u v\u1ec1 l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt, nh\u01b0 NVD, l\u1ea5y d\u1eef li\u1ec7u t\u1eeb Danh s\u00e1ch CVE \u0111\u1ec3 t\u1ea1o danh s\u00e1ch l\u1ed7 h\u1ed5ng chi ti\u1ebft h\u01a1n.<\/p>\n<h2>C\u00e1c t\u00ednh n\u0103ng ch\u00ednh c\u1ee7a CVE<\/h2>\n<ol>\n<li><strong>M\u00e3 \u0111\u1ecbnh danh \u0111\u01b0\u1ee3c chu\u1ea9n h\u00f3a:<\/strong> M\u1ed7i CVE ID \u0111\u1ec1 c\u1eadp \u0111\u1ebfn m\u1ed9t l\u1ed7 h\u1ed5ng duy nh\u1ea5t, gi\u00fap tr\u00e1nh nh\u1ea7m l\u1eabn khi th\u1ea3o lu\u1eadn ho\u1eb7c chia s\u1ebb th\u00f4ng tin v\u1ec1 c\u00e1c l\u1ed7 h\u1ed5ng.<\/li>\n<li><strong>C\u01a1 s\u1edf d\u1eef li\u1ec7u c\u00f3 th\u1ec3 truy c\u1eadp c\u00f4ng khai:<\/strong> Danh s\u00e1ch CVE \u0111\u01b0\u1ee3c cung c\u1ea5p mi\u1ec5n ph\u00ed cho c\u00f4ng ch\u00fang, th\u00fac \u0111\u1ea9y t\u00ednh minh b\u1ea1ch v\u00e0 h\u1ee3p t\u00e1c.<\/li>\n<li><strong>\u01afng du\u0323ng r\u00f4\u0323ng Rai:<\/strong> ID CVE \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng r\u1ed9ng r\u00e3i b\u1edfi c\u00e1c nh\u00e0 cung c\u1ea5p v\u00e0 nh\u00e0 nghi\u00ean c\u1ee9u an ninh m\u1ea1ng tr\u00ean to\u00e0n th\u1ebf gi\u1edbi, khi\u1ebfn n\u00f3 tr\u1edf th\u00e0nh m\u1ed9t ti\u00eau chu\u1ea9n \u0111\u01b0\u1ee3c c\u00f4ng nh\u1eadn tr\u00ean to\u00e0n c\u1ea7u.<\/li>\n<li><strong>Ng\u00f4n ng\u1eef th\u00f4ng d\u1ee5ng:<\/strong> Vi\u1ec7c s\u1eed d\u1ee5ng m\u1ed9t m\u00e3 \u0111\u1ecbnh danh chung gi\u00fap c\u1ea3i thi\u1ec7n s\u1ef1 ph\u1ed1i h\u1ee3p v\u00e0 c\u1ed9ng t\u00e1c v\u1ec1 an ninh m\u1ea1ng b\u1eb1ng c\u00e1ch cung c\u1ea5p m\u1ed9t c\u00e1ch ti\u00eau chu\u1ea9n \u0111\u1ec3 th\u1ea3o lu\u1eadn v\u1ec1 c\u00e1c l\u1ed7 h\u1ed5ng ri\u00eang l\u1ebb.<\/li>\n<\/ol>\n<h2>C\u00e1c lo\u1ea1i CVE<\/h2>\n<p>Kh\u00f4ng c\u00f3 s\u1ef1 ph\u00e2n lo\u1ea1i ch\u00ednh th\u1ee9c v\u1ec1 c\u00e1c lo\u1ea1i CVE, nh\u01b0ng c\u00e1c l\u1ed7 h\u1ed5ng c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c ph\u00e2n lo\u1ea1i d\u1ef1a tr\u00ean c\u00e1c ti\u00eau ch\u00ed kh\u00e1c nhau, ch\u1eb3ng h\u1ea1n nh\u01b0 khu v\u1ef1c ch\u00fang t\u00e1c \u0111\u1ed9ng (v\u00ed d\u1ee5: b\u1ed9 nh\u1edb, h\u1ec7 \u0111i\u1ec1u h\u00e0nh, \u1ee9ng d\u1ee5ng), c\u00e1ch ch\u00fang c\u00f3 th\u1ec3 b\u1ecb khai th\u00e1c (v\u00ed d\u1ee5: t\u1eeb xa, c\u1ee5c b\u1ed9). ) v\u00e0 t\u00e1c \u0111\u1ed9ng c\u1ee7a ch\u00fang (v\u00ed d\u1ee5: r\u00f2 r\u1ec9 d\u1eef li\u1ec7u, s\u1ef1 c\u1ed1 h\u1ec7 th\u1ed1ng).<\/p>\n<p>V\u00ed d\u1ee5: xem x\u00e9t c\u00e1ch khai th\u00e1c l\u1ed7 h\u1ed5ng, ch\u00fang ta c\u00f3 th\u1ec3 c\u00f3:<\/p>\n<table>\n<thead>\n<tr>\n<th>Vector khai th\u00e1c<\/th>\n<th>S\u1ef1 mi\u00eau t\u1ea3<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u0110\u1ecba ph\u01b0\u01a1ng<\/td>\n<td>K\u1ebb t\u1ea5n c\u00f4ng c\u1ea7n quy\u1ec1n truy c\u1eadp v\u1eadt l\u00fd ho\u1eb7c \u0111\u1eb7c quy\u1ec1n c\u1ee7a ng\u01b0\u1eddi d\u00f9ng c\u1ee5c b\u1ed9 \u0111\u1ec3 khai th\u00e1c l\u1ed7 h\u1ed5ng<\/td>\n<\/tr>\n<tr>\n<td>Li\u1ec1n k\u1ec1<\/td>\n<td>K\u1ebb t\u1ea5n c\u00f4ng ph\u1ea3i c\u00f3 quy\u1ec1n truy c\u1eadp v\u00e0o c\u00f9ng m\u1ea1ng v\u1edbi h\u1ec7 th\u1ed1ng m\u1ee5c ti\u00eau \u0111\u1ec3 khai th\u00e1c l\u1ed7 h\u1ed5ng<\/td>\n<\/tr>\n<tr>\n<td>Xa<\/td>\n<td>K\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 khai th\u00e1c l\u1ed7 h\u1ed5ng tr\u00ean internet<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Vi\u1ec7c s\u1eed d\u1ee5ng, v\u1ea5n \u0111\u1ec1 v\u00e0 gi\u1ea3i ph\u00e1p li\u00ean quan \u0111\u1ebfn CVE<\/h2>\n<p>CVE \u0111\u01b0\u1ee3c c\u00e1c chuy\u00ean gia an ninh m\u1ea1ng s\u1eed d\u1ee5ng \u0111\u1ec3 x\u00e1c \u0111\u1ecbnh c\u00e1c l\u1ed7 h\u1ed5ng, \u0111\u00e1nh gi\u00e1 t\u00e1c \u0111\u1ed9ng c\u1ee7a ch\u00fang v\u00e0 \u0111\u01b0a ra c\u00e1c chi\u1ebfn l\u01b0\u1ee3c gi\u1ea3m thi\u1ec3u. Tuy nhi\u00ean, h\u1ec7 th\u1ed1ng n\u00e0y kh\u00f4ng ph\u1ea3i l\u00e0 kh\u00f4ng c\u00f3 th\u00e1ch th\u1ee9c. \u0110\u00e1ng ch\u00fa \u00fd, h\u1ec7 th\u1ed1ng CVE c\u00f3 th\u1ec3 ch\u1eadm g\u00e1n m\u00e3 nh\u1eadn d\u1ea1ng cho c\u00e1c l\u1ed7 h\u1ed5ng m\u1edbi, g\u00e2y ra l\u1ed7 h\u1ed5ng trong ph\u1ea1m vi b\u1ea3o hi\u1ec3m. Ngo\u00e0i ra, v\u00ec CVE kh\u00f4ng cung c\u1ea5p th\u00f4ng tin v\u1ec1 m\u1ee9c \u0111\u1ed9 nghi\u00eam tr\u1ecdng ho\u1eb7c r\u1ee7i ro n\u00ean c\u00e1c t\u1ed5 ch\u1ee9c ph\u1ea3i d\u1ef1a v\u00e0o c\u00e1c t\u00e0i nguy\u00ean kh\u00e1c \u0111\u1ec3 c\u00f3 d\u1eef li\u1ec7u n\u00e0y.<\/p>\n<p>\u0110\u1ec3 gi\u1ea3i quy\u1ebft nh\u1eefng v\u1ea5n \u0111\u1ec1 n\u00e0y, c\u1ed9ng \u0111\u1ed3ng an ninh m\u1ea1ng \u0111\u00e3 ph\u00e1t tri\u1ec3n c\u00e1c c\u00f4ng c\u1ee5 v\u00e0 t\u00e0i nguy\u00ean b\u1ed5 sung. V\u00ed d\u1ee5: C\u01a1 s\u1edf d\u1eef li\u1ec7u v\u1ec1 l\u1ed7 h\u1ed5ng qu\u1ed1c gia cung c\u1ea5p \u0111i\u1ec3m m\u1ee9c \u0111\u1ed9 nghi\u00eam tr\u1ecdng v\u00e0 si\u00eau d\u1eef li\u1ec7u b\u1ed5 sung cho t\u1eebng CVE, trong khi c\u00e1c t\u1ed5 ch\u1ee9c nh\u01b0 CERT\/CC v\u00e0 S\u00e1ng ki\u1ebfn Zero Day th\u01b0\u1eddng g\u00e1n m\u00e3 nh\u1eadn d\u1ea1ng t\u1ea1m th\u1eddi cho c\u00e1c l\u1ed7 h\u1ed5ng m\u1edbi tr\u01b0\u1edbc khi ch\u1ec9 \u0111\u1ecbnh ID CVE.<\/p>\n<h2>So s\u00e1nh v\u1edbi c\u00e1c \u0111i\u1ec1u kho\u1ea3n t\u01b0\u01a1ng t\u1ef1<\/h2>\n<table>\n<thead>\n<tr>\n<th>Thu\u1eadt ng\u1eef<\/th>\n<th>S\u1ef1 mi\u00eau t\u1ea3<\/th>\n<th>So s\u00e1nh v\u1edbi CVE<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVSS<\/td>\n<td>H\u1ec7 th\u1ed1ng ch\u1ea5m \u0111i\u1ec3m l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt th\u00f4ng th\u01b0\u1eddng (CVSS) cung c\u1ea5p m\u1ed9t c\u00e1ch \u0111\u1ec3 n\u1eafm b\u1eaft c\u00e1c \u0111\u1eb7c \u0111i\u1ec3m ch\u00ednh c\u1ee7a l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt v\u00e0 t\u1ea1o ra \u0111i\u1ec3m s\u1ed1 th\u1ec3 hi\u1ec7n m\u1ee9c \u0111\u1ed9 nghi\u00eam tr\u1ecdng c\u1ee7a l\u1ed7 h\u1ed5ng \u0111\u00f3.<\/td>\n<td>Trong khi CVE x\u00e1c \u0111\u1ecbnh c\u00e1c l\u1ed7 h\u1ed5ng, CVSS s\u1ebd ch\u1ea5m \u0111i\u1ec3m ch\u00fang d\u1ef1a tr\u00ean m\u1ee9c \u0111\u1ed9 nghi\u00eam tr\u1ecdng c\u1ee7a ch\u00fang.<\/td>\n<\/tr>\n<tr>\n<td>CWE<\/td>\n<td>B\u1ea3ng li\u1ec7t k\u00ea \u0111i\u1ec3m y\u1ebfu chung (CWE) l\u00e0 danh s\u00e1ch c\u00e1c \u0111i\u1ec3m y\u1ebfu b\u1ea3o m\u1eadt ph\u1ea7n m\u1ec1m ph\u1ed5 bi\u1ebfn do c\u1ed9ng \u0111\u1ed3ng ph\u00e1t tri\u1ec3n. N\u00f3 ph\u1ee5c v\u1ee5 nh\u01b0 m\u1ed9t ng\u00f4n ng\u1eef chung \u0111\u1ec3 m\u00f4 t\u1ea3 nh\u1eefng \u0111i\u1ec3m y\u1ebfu n\u00e0y.<\/td>\n<td>Trong khi CVE x\u00e1c \u0111\u1ecbnh c\u00e1c l\u1ed7 h\u1ed5ng c\u1ee5 th\u1ec3 th\u00ec CWE m\u00f4 t\u1ea3 c\u00e1c lo\u1ea1i \u0111i\u1ec3m y\u1ebfu b\u1ea3o m\u1eadt c\u00f3 th\u1ec3 d\u1eabn \u0111\u1ebfn l\u1ed7 h\u1ed5ng.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Quan \u0111i\u1ec3m t\u01b0\u01a1ng lai v\u00e0 c\u00f4ng ngh\u1ec7 li\u00ean quan \u0111\u1ebfn CVE<\/h2>\n<p>Khi c\u00e1c m\u1ed1i \u0111e d\u1ecda an ninh m\u1ea1ng ti\u1ebfp t\u1ee5c ph\u00e1t tri\u1ec3n, h\u1ec7 th\u1ed1ng CVE c\u0169ng s\u1ebd c\u1ea7n ph\u1ea3i th\u00edch \u1ee9ng. C\u00e1c c\u1ea3i ti\u1ebfn trong t\u01b0\u01a1ng lai c\u1ee7a h\u1ec7 th\u1ed1ng CVE c\u00f3 th\u1ec3 bao g\u1ed3m ph\u00e1t hi\u1ec7n v\u00e0 b\u00e1o c\u00e1o l\u1ed7 h\u1ed5ng t\u1ef1 \u0111\u1ed9ng, ph\u1ea1m vi m\u1edf r\u1ed9ng cho CNA v\u00e0 t\u00edch h\u1ee3p v\u1edbi c\u00f4ng ngh\u1ec7 tr\u00ed tu\u1ec7 nh\u00e2n t\u1ea1o (AI) v\u00e0 m\u00e1y h\u1ecdc (ML) \u0111\u1ec3 ph\u00e2n t\u00edch d\u1ef1 \u0111o\u00e1n.<\/p>\n<h2>M\u00e1y ch\u1ee7 proxy v\u00e0 CVE<\/h2>\n<p>C\u00e1c m\u00e1y ch\u1ee7 proxy, gi\u1ed1ng nh\u01b0 c\u00e1c m\u00e1y ch\u1ee7 do OneProxy cung c\u1ea5p, c\u00f3 th\u1ec3 v\u1eeba l\u00e0 m\u1ee5c ti\u00eau v\u1eeba l\u00e0 c\u00f4ng c\u1ee5 trong b\u1ed1i c\u1ea3nh CVE. L\u00e0 m\u1ee5c ti\u00eau, c\u00e1c l\u1ed7 h\u1ed5ng trong ph\u1ea7n m\u1ec1m m\u00e1y ch\u1ee7 proxy c\u00f3 th\u1ec3 nh\u1eadn \u0111\u01b0\u1ee3c ID CVE c\u1ee7a ri\u00eang ch\u00fang n\u1ebfu ch\u00fang g\u00e2y ra r\u1ee7i ro b\u1ea3o m\u1eadt. L\u00e0 c\u00f4ng c\u1ee5, m\u00e1y ch\u1ee7 proxy c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c c\u1ea5u h\u00ecnh \u0111\u1ec3 gi\u1ea3m thi\u1ec3u t\u00e1c \u0111\u1ed9ng c\u1ee7a m\u1ed9t s\u1ed1 l\u1ed7 h\u1ed5ng, ch\u1eb3ng h\u1ea1n nh\u01b0 b\u1eb1ng c\u00e1ch l\u1ecdc l\u01b0u l\u01b0\u1ee3ng truy c\u1eadp \u0111\u1ed9c h\u1ea1i li\u00ean quan \u0111\u1ebfn CVE \u0111\u00e3 bi\u1ebft.<\/p>\n<h2>Li\u00ean k\u1ebft li\u00ean quan<\/h2>\n<ol>\n<li><a href=\"https:\/\/cve.mitre.org\/\" target=\"_new\" rel=\"noopener nofollow\">MITRE CVE<\/a><\/li>\n<li><a href=\"https:\/\/nvd.nist.gov\/\" target=\"_new\" rel=\"noopener nofollow\">C\u01a1 s\u1edf d\u1eef li\u1ec7u v\u1ec1 l\u1ed7 h\u1ed5ng qu\u1ed1c gia<\/a><\/li>\n<li><a href=\"https:\/\/www.cvedetails.com\/\" target=\"_new\" rel=\"noopener nofollow\">Chi ti\u1ebft CVE<\/a><\/li>\n<li><a href=\"https:\/\/www.cert.org\/\" target=\"_new\" rel=\"noopener nofollow\">CERT\/CC<\/a><\/li>\n<li><a href=\"https:\/\/www.zerodayinitiative.com\/\" target=\"_new\" rel=\"noopener nofollow\">S\u00e1ng ki\u1ebfn Ng\u00e0y Kh\u00f4ng<\/a><\/li>\n<\/ol>","protected":false},"featured_media":476523,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-476522","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>An In-depth Overview of Common Vulnerabilities and Exposures (CVE)<\/mark>","faq_items":[{"question":"What is the Common Vulnerabilities and Exposures (CVE) system?","answer":"<p>The Common Vulnerabilities and Exposures (CVE) system is a standardized approach to identifying and publishing cybersecurity vulnerabilities. It provides a common language for the cybersecurity community to share and discuss information about vulnerabilities.<\/p>"},{"question":"When and why was the CVE system introduced?","answer":"<p>The CVE system was introduced in September 1999 by the MITRE Corporation. The primary aim was to provide a standard language for discussing and sharing information about vulnerabilities, which previously lacked standardization leading to miscommunication and confusion.<\/p>"},{"question":"What information does a CVE Entry include?","answer":"<p>A CVE Entry includes an identification number, a description, and at least one public reference. The identification number follows a specific format: CVE-YYYY-NNNNN, where \"YYYY\" is the year the CVE ID was assigned or the vulnerability was made public, and \"NNNNN\" is a unique identifier for the vulnerability.<\/p>"},{"question":"How does the CVE system work?","answer":"<p>The CVE system assigns a unique identifier to each known vulnerability, which is done by CVE Numbering Authorities (CNAs). These are partner organizations of the CVE Program who assign CVE IDs to vulnerabilities within their agreed-upon scope. The main CVE List is updated with these new entries and this list is used by various vulnerability databases to create detailed vulnerability listings.<\/p>"},{"question":"What are the key features of the CVE system?","answer":"<p>The key features of the CVE system include standardized identifiers for each vulnerability, a publicly accessible database, widespread adoption among cybersecurity vendors and researchers, and the provision of a common language to improve cybersecurity coordination and collaboration.<\/p>"},{"question":"What types of vulnerabilities can be found in the CVE system?","answer":"<p>The CVE system does not classify vulnerabilities into types. However, vulnerabilities can be grouped based on different criteria such as the area they impact (like memory, OS, or application), how they can be exploited (such as remotely or locally), and the impact they have (like data leakage or system crash).<\/p>"},{"question":"What are some challenges associated with using the CVE system?","answer":"<p>Challenges with the CVE system include slow assignment of identifiers to new vulnerabilities and the absence of severity or risk information for each vulnerability. However, these challenges are mitigated by complementary tools and resources like the National Vulnerability Database and organizations like CERT\/CC and Zero Day Initiative.<\/p>"},{"question":"How do the CVE, CVSS, and CWE systems differ?","answer":"<p>The CVE system provides standardized identifiers for known vulnerabilities. The Common Vulnerability Scoring System (CVSS) provides severity scores for vulnerabilities. The Common Weakness Enumeration (CWE) is a list of common software security weaknesses.<\/p>"},{"question":"What future technologies and advancements are expected in the CVE system?","answer":"<p>The future of the CVE system may include automated vulnerability detection and reporting, expanded scopes for CNAs, and integration with artificial intelligence and machine learning technologies for predictive analysis.<\/p>"},{"question":"How are proxy servers related to the CVE system?","answer":"<p>Proxy servers can be both targets and tools in the context of CVE. As targets, vulnerabilities in proxy server software may receive their own CVE IDs. As tools, proxy servers can be configured to mitigate the impact of some vulnerabilities by filtering malicious traffic related to a known CVE.<\/p>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/wiki\/476522","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/wiki\/476522\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/media\/476523"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/media?parent=476522"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}