{"id":122126,"date":"2024-05-15T14:56:42","date_gmt":"2024-05-15T14:56:42","guid":{"rendered":"https:\/\/bas-ip.com\/?page_id=122126"},"modified":"2024-11-05T11:16:25","modified_gmt":"2024-11-05T11:16:25","slug":"bsa-000001","status":"publish","type":"page","link":"https:\/\/bas-ip.com\/vi\/bsa-000001\/","title":{"rendered":"BSA-000001"},"content":{"rendered":"<h2 class=\"wp-block-heading\" id=\"bsa-000001\">T\u1ed5ng quan<\/h2>\n\n\n\n<p>M\u1ed9t v\u1ea5n \u0111\u1ec1 \u0111\u00e3 \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n trong m\u1ed9t s\u1ed1 thi\u1ebft b\u1ecb li\u00ean l\u1ea1c n\u1ed9i b\u1ed9 BAS-IP. B\u1eb1ng c\u00e1ch truy c\u1eadp v\u00e0o giao di\u1ec7n web ho\u1eb7c API c\u1ee7a thi\u1ebft b\u1ecb, k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 l\u1ea5y \u0111\u01b0\u1ee3c m\u1eadt kh\u1ea9u cho m\u00e1y ch\u1ee7 RTSP v\u00e0 t\u00e0i kho\u1ea3n SIP c\u1ee7a thi\u1ebft b\u1ecb.<\/p>\n\n\n\n<p>BAS-IP ph\u00e2n lo\u1ea1i c\u00e1c l\u1ed7 h\u1ed5ng n\u00e0y l\u00e0 trung b\u00ecnh v\u00e0 khuy\u1ebfn ngh\u1ecb kh\u00e1ch h\u00e0ng n\u00e2ng c\u1ea5p c\u00e1c m\u00f4 h\u00ecnh BAS-IP b\u1ecb \u1ea3nh h\u01b0\u1edfng l\u00ean phi\u00ean b\u1ea3n ch\u01b0\u01a1ng tr\u00ecnh c\u01a1 s\u1edf m\u1edbi nh\u1ea5t.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"risk-assessment\">\u0110\u00e1nh gi\u00e1 r\u1ee7i ro<\/h2>\n\n\n\n<p>K\u1ebb t\u1ea5n c\u00f4ng ti\u1ec1m \u1ea9n c\u1ea7n c\u00f3 quy\u1ec1n truy c\u1eadp m\u1ea1ng v\u00e0o thi\u1ebft b\u1ecb \u0111\u1ec3 khai th\u00e1c c\u00e1c l\u1ed7 h\u1ed5ng. K\u1ebb t\u1ea5n c\u00f4ng y\u00eau c\u1ea7u th\u00f4ng tin x\u00e1c th\u1ef1c \u0111\u1ec3 x\u00e2m nh\u1eadp th\u00e0nh c\u00f4ng v\u00e0o thi\u1ebft b\u1ecb. R\u1ee7i ro ph\u1ee5 thu\u1ed9c v\u00e0o m\u1ee9c \u0111\u1ed9 thi\u1ebft b\u1ecb b\u1ecb l\u1ed9. Thi\u1ebft b\u1ecb k\u1ebft n\u1ed1i Internet (v\u00ed d\u1ee5: b\u1ecb l\u1ed9 qua c\u1ed5ng chuy\u1ec3n ti\u1ebfp b\u1ed9 \u0111\u1ecbnh tuy\u1ebfn) c\u00f3 r\u1ee7i ro cao. C\u00e1c s\u1ea3n ph\u1ea9m \u0111\u01b0\u1ee3c tri\u1ec3n khai tr\u00ean m\u1ea1ng c\u1ee5c b\u1ed9 \u0111\u01b0\u1ee3c b\u1ea3o v\u1ec7 c\u00f3 r\u1ee7i ro th\u1ea5p h\u01a1n.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"risk-mitigation\">Gi\u1ea3m thi\u1ec3u r\u1ee7i ro<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ch\u00fang t\u00f4i khuy\u1ebfn ngh\u1ecb m\u1ea1nh m\u1ebd n\u00e2ng c\u1ea5p c\u00e1c m\u1eabu b\u1ecb \u1ea3nh h\u01b0\u1edfng l\u00ean ch\u01b0\u01a1ng tr\u00ecnh c\u01a1 s\u1edf m\u1edbi nh\u1ea5t.<\/li>\n\n\n\n<li>Kh\u00f4ng khuy\u1ebfn kh\u00edch \u0111\u1ec3 c\u00e1c thi\u1ebft b\u1ecb ti\u1ebfp x\u00fac tr\u1ef1c ti\u1ebfp v\u1edbi Internet (chuy\u1ec3n ti\u1ebfp c\u1ed5ng).<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"affected-models-and-patched-firmware\">C\u00e1c m\u1eabu b\u1ecb \u1ea3nh h\u01b0\u1edfng v\u00e0 ph\u1ea7n m\u1ec1m \u0111\u00e3 v\u00e1<\/h2>\n\n\n\n<p>Danh s\u00e1ch c\u00e1c m\u1eabu b\u1ecb \u1ea3nh h\u01b0\u1edfng:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>AV-01D<\/li>\n\n\n\n<li>AV-01MD<\/li>\n\n\n\n<li>AV-01MFD<\/li>\n\n\n\n<li>AV-01ED<\/li>\n\n\n\n<li>AV-01KD<\/li>\n\n\n\n<li>AV-01BD<\/li>\n\n\n\n<li>AV-01KBD<\/li>\n\n\n\n<li>AV-02D<\/li>\n\n\n\n<li>AV-02IDE<\/li>\n\n\n\n<li>AV-02IDR<\/li>\n\n\n\n<li>AV-02IPD<\/li>\n\n\n\n<li>AV-02FDE<\/li>\n\n\n\n<li>AV-02FDR<\/li>\n\n\n\n<li>AV-03D<\/li>\n\n\n\n<li>AV-03BD<\/li>\n\n\n\n<li>AV-04AFD<\/li>\n\n\n\n<li>AV-04ASD<\/li>\n\n\n\n<li>AV-04FD<\/li>\n\n\n\n<li>AV-04SD<\/li>\n\n\n\n<li>AV-05FD<\/li>\n\n\n\n<li>AV-05SD<\/li>\n\n\n\n<li>AA-07BD<\/li>\n\n\n\n<li>AA-07BDI<\/li>\n\n\n\n<li>BA-04BD<\/li>\n\n\n\n<li>BA-04MD<\/li>\n\n\n\n<li>BA-08BD<\/li>\n\n\n\n<li>BA-08MD<\/li>\n\n\n\n<li>BA-12BD<\/li>\n\n\n\n<li>BA-12MD<\/li>\n\n\n\n<li>CR-02BD<\/li>\n<\/ul>\n\n\n\n<p>Phi\u00ean b\u1ea3n ph\u1ea7n m\u1ec1m \u0111\u00e3 v\u00e1:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>3.9.2<\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>T\u1ed5ng quan M\u1ed9t v\u1ea5n \u0111\u1ec1 \u0111\u00e3 \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n trong m\u1ed9t s\u1ed1 thi\u1ebft b\u1ecb li\u00ean l\u1ea1c n\u1ed9i b\u1ed9 BAS-IP. B\u1eb1ng c\u00e1ch truy c\u1eadp v\u00e0o giao di\u1ec7n web ho\u1eb7c API c\u1ee7a thi\u1ebft b\u1ecb, k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 l\u1ea5y \u0111\u01b0\u1ee3c m\u1eadt kh\u1ea9u cho m\u00e1y ch\u1ee7 RTSP v\u00e0 t\u00e0i kho\u1ea3n SIP c\u1ee7a thi\u1ebft b\u1ecb. BAS-IP ph\u00e2n lo\u1ea1i [&hellip;]<\/p>","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-122126","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/pages\/122126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/comments?post=122126"}],"version-history":[{"count":1,"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/pages\/122126\/revisions"}],"predecessor-version":[{"id":122128,"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/pages\/122126\/revisions\/122128"}],"wp:attachment":[{"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/media?parent=122126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}