{"id":151332,"date":"2024-02-15T17:00:26","date_gmt":"2024-02-15T17:00:26","guid":{"rendered":"https:\/\/bas-ip.com\/security-policy\/"},"modified":"2025-11-28T13:15:45","modified_gmt":"2025-11-28T13:15:45","slug":"security-policy","status":"publish","type":"page","link":"https:\/\/bas-ip.com\/vi\/security-policy\/","title":{"rendered":"Ch\u00ednh s\u00e1ch b\u1ea3o m\u1eadt"},"content":{"rendered":"<h1 class=\"wp-block-heading\">Ch\u00ednh s\u00e1ch c\u00f4ng b\u1ed1 l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt<\/h1>\n\n\n\n<h1 class=\"wp-block-heading\">Th\u00f4ng tin chung<\/h1>\n\n\n\n<p>BAS-IP tu\u00e2n th\u1ee7 c\u00e1c th\u1ef1c ti\u1ec5n h\u00e0ng \u0111\u1ea7u trong ng\u00e0nh v\u1ec1 qu\u1ea3n l\u00fd v\u00e0 ph\u1ea3n h\u1ed3i c\u00e1c l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n trong c\u00e1c s\u1ea3n ph\u1ea9m c\u1ee7a ch\u00fang t\u00f4i. Kh\u00f4ng th\u1ec3 \u0111\u1ea3m b\u1ea3o r\u1eb1ng c\u00e1c s\u1ea3n ph\u1ea9m v\u00e0 d\u1ecbch v\u1ee5 do c\u00f4ng ty ch\u00fang t\u00f4i cung c\u1ea5p ho\u00e0n to\u00e0n kh\u00f4ng c\u00f3 l\u1ed7 h\u1ed5ng. \u0110\u00e2y kh\u00f4ng ph\u1ea3i l\u00e0 m\u1ed9t \u0111\u1eb7c \u0111i\u1ec3m ri\u00eang bi\u1ec7t, m\u00e0 l\u00e0 m\u1ed9t \u0111i\u1ec1u ki\u1ec7n chung cho t\u1ea5t c\u1ea3 c\u00e1c ph\u1ea7n m\u1ec1m v\u00e0 d\u1ecbch v\u1ee5, nh\u01b0ng ch\u00fang t\u00f4i c\u00f3 th\u1ec3 \u0111\u1ea3m b\u1ea3o r\u1eb1ng \u1edf t\u1ea5t c\u1ea3 c\u00e1c giai \u0111o\u1ea1n ph\u00e1t tri\u1ec3n, ch\u00fang t\u00f4i s\u1ebd n\u1ed7 l\u1ef1c \u0111\u1ec3 x\u00e1c \u0111\u1ecbnh v\u00e0 lo\u1ea1i b\u1ecf c\u00e1c l\u1ed7 h\u1ed5ng ti\u1ec1m \u1ea9n, t\u1eeb \u0111\u00f3 gi\u1ea3m thi\u1ec3u r\u1ee7i ro li\u00ean quan \u0111\u1ebfn vi\u1ec7c tri\u1ec3n khai c\u00e1c s\u1ea3n ph\u1ea9m v\u00e0 d\u1ecbch v\u1ee5 c\u1ee7a BAS-IP trong m\u00f4i tr\u01b0\u1eddng kh\u00e1ch h\u00e0ng.<\/p>\n\n\n\n<p>BAS-IP nh\u1eadn ra r\u1eb1ng m\u1ed9t s\u1ed1 giao th\u1ee9c v\u00e0 d\u1ecbch v\u1ee5 m\u1ea1ng ti\u00eau chu\u1ea9n c\u00f3 th\u1ec3 c\u00f3 nh\u1eefng \u0111i\u1ec3m y\u1ebfu c\u1ed1 h\u1eefu c\u00f3 th\u1ec3 b\u1ecb khai th\u00e1c. M\u1eb7c d\u00f9 BAS-IP kh\u00f4ng ch\u1ecbu tr\u00e1ch nhi\u1ec7m v\u1ec1 c\u00e1c giao th\u1ee9c v\u00e0 d\u1ecbch v\u1ee5 n\u00e0y, ch\u00fang t\u00f4i cung c\u1ea5p c\u00e1c khuy\u1ebfn ngh\u1ecb \u0111\u1ec3 gi\u1ea3m thi\u1ec3u r\u1ee7i ro li\u00ean quan \u0111\u1ebfn c\u00e1c s\u1ea3n ph\u1ea9m, ph\u1ea7n m\u1ec1m v\u00e0 d\u1ecbch v\u1ee5 c\u1ee7a BAS-IP d\u01b0\u1edbi d\u1ea1ng c\u00e1c <a href=\"https:\/\/basip.atlassian.net\/wiki\/spaces\/HP\/pages\/5046705\/The+practice+of+building+IP+intercom+systems\" target=\"_blank\" rel=\"noopener\">h\u01b0\u1edbng d\u1eabn kh\u00e1c nhau<\/a>.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Ph\u1ea1m vi \u00e1p d\u1ee5ng c\u1ee7a Ch\u00ednh s\u00e1ch<\/h1>\n\n\n\n<p>Ch\u00ednh s\u00e1ch qu\u1ea3n l\u00fd l\u1ed7 h\u1ed5ng \u0111\u01b0\u1ee3c m\u00f4 t\u1ea3 trong t\u00e0i li\u1ec7u n\u00e0y \u00e1p d\u1ee5ng cho t\u1ea5t c\u1ea3 c\u00e1c s\u1ea3n ph\u1ea9m, ph\u1ea7n m\u1ec1m v\u00e0 d\u1ecbch v\u1ee5 mang th\u01b0\u01a1ng hi\u1ec7u BAS-IP.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Nh\u1eefng \u0111i\u1ec3m Ch\u00ednh s\u00e1ch kh\u00f4ng bao g\u1ed3m<\/h1>\n\n\n\n<p>M\u1ed9t s\u1ed1 l\u1ed7 h\u1ed5ng kh\u00f4ng \u0111\u01b0\u1ee3c \u0111\u1ec1 c\u1eadp trong ch\u00ednh s\u00e1ch qu\u1ea3n l\u00fd l\u1ed7 h\u1ed5ng c\u1ee7a BAS-IP. Vui l\u00f2ng kh\u00f4ng g\u1eedi c\u00e1c b\u00e1o c\u00e1o l\u1ed7 h\u1ed5ng kh\u00f4ng thu\u1ed9c ph\u1ea1m vi c\u1ee7a ch\u00ednh s\u00e1ch qu\u1ea3n l\u00fd l\u1ed7 h\u1ed5ng t\u1edbi <a href=\"mailto:security@bas-ip.com\" data-type=\"link\" data-id=\"security@bas-ip.com\">security@bas-ip.com<\/a>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>C\u00e1c l\u1ed7 h\u1ed5ng y\u00eau c\u1ea7u <strong>\u0111\u1eb7c quy\u1ec1n cao<\/strong> v\u00e0\/ho\u1eb7c <strong>k\u1ef9 thu\u1eadt x\u00e3 h\u1ed9i<\/strong> \u0111\u01b0\u1ee3c k\u00edch ho\u1ea1t\/th\u1ef1c thi b\u1eb1ng quy\u1ec1n truy c\u1eadp <em>root<\/em>\/qu\u1ea3n tr\u1ecb vi\u00ean v\u00e0\/ho\u1eb7c y\u00eau c\u1ea7u <strong>t\u01b0\u01a1ng t\u00e1c ph\u1ee9c t\u1ea1p<\/strong> c\u1ee7a ng\u01b0\u1eddi d\u00f9ng<\/li>\n\n\n\n<li><strong>Chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n t\u00ean mi\u1ec1n ph\u1ee5<\/strong> (<em>Subdomain takeover<\/em>), v\u00ed d\u1ee5: gi\u00e0nh quy\u1ec1n ki\u1ec3m so\u00e1t m\u1ed9t n\u00fat tr\u1ecf \u0111\u1ebfn m\u1ed9t d\u1ecbch v\u1ee5 hi\u1ec7n kh\u00f4ng \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng<\/li>\n\n\n\n<li><strong>C\u1ea5u h\u00ecnh ng\u01b0\u1eddi d\u00f9ng kh\u00f4ng ch\u00ednh x\u00e1c<\/strong> c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c ng\u0103n ch\u1eb7n b\u1eb1ng c\u00e1ch l\u00e0m theo c\u00e1c h\u01b0\u1edbng d\u1eabn c\u1ee7a BAS-IP<\/li>\n\n\n\n<li>C\u00e1c l\u1ed7 h\u1ed5ng trong n\u1ed9i dung ho\u1eb7c \u1ee9ng d\u1ee5ng do <strong>ng\u01b0\u1eddi d\u00f9ng ho\u1eb7c \u0111\u1ed1i t\u00e1c b\u00ean th\u1ee9 ba<\/strong> t\u1ea1o ra, ch\u1eb3ng h\u1ea1n nh\u01b0 c\u00e1c \u1ee9ng d\u1ee5ng c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c t\u1ea3i xu\u1ed1ng v\u00e0 ch\u1ea1y tr\u00ean thi\u1ebft b\u1ecb BAS-IP<\/li>\n\n\n\n<li>C\u00e1c l\u1ed7 h\u1ed5ng <strong>Gi\u1ea3 m\u1ea1o y\u00eau c\u1ea7u ch\u00e9o trang (CSRF)<\/strong> ho\u1eb7c <strong>T\u1ea5n c\u00f4ng k\u1ecbch b\u1ea3n ch\u00e9o trang (XSS)<\/strong> l\u1eeba ng\u01b0\u1eddi d\u00f9ng truy c\u1eadp m\u1ed9t trang web \u0111\u1ed9c h\u1ea1i ho\u1eb7c nh\u1ea5p v\u00e0o m\u1ed9t li\u00ean k\u1ebft ng\u1ee5y trang khi truy c\u1eadp giao di\u1ec7n web c\u1ee7a thi\u1ebft b\u1ecb BAS-IP<\/li>\n\n\n\n<li><strong>C\u00e1c l\u1ed7 h\u1ed5ng <em>open-source<\/em> c\u1ee7a b\u00ean th\u1ee9 ba<\/strong> \u0111\u00e3 \u0111\u0103ng k\u00fd v\u1edbi m\u00e3 \u0111\u1ecbnh danh CVE n\u1eb1m trong c\u00e1c th\u00e0nh ph\u1ea7n ho\u1eb7c g\u00f3i ph\u1ea7n m\u1ec1m \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng trong c\u00e1c s\u1ea3n ph\u1ea9m, ph\u1ea7n m\u1ec1m ho\u1eb7c d\u1ecbch v\u1ee5 c\u1ee7a BAS-IP. C\u00e1c v\u00ed d\u1ee5 ph\u1ed5 bi\u1ebfn c\u1ee7a c\u00e1c th\u00e0nh ph\u1ea7n ph\u1ea7n m\u1ec1m n\u00e0y bao g\u1ed3m <em>kernel<\/em> Linux, OpenSSL, AOSP, v\u00e0 c\u00e1c ph\u1ea7n m\u1ec1m kh\u00e1c<\/li>\n\n\n\n<li><strong>Thi\u1ebfu c\u00e1c <em>header<\/em> b\u1ea3o m\u1eadt<\/strong> HTTP(S), ch\u1eb3ng h\u1ea1n nh\u01b0 X-Frame-Options<\/li>\n\n\n\n<li>C\u00e1c b\u00e1o c\u00e1o l\u1ed7 h\u1ed5ng \u0111\u01b0\u1ee3c t\u1ea1o ra b\u1edfi <strong>c\u00e1c tr\u00ecnh qu\u00e9t b\u1ea3o m\u1eadt m\u1ea1ng c\u1ee7a b\u00ean th\u1ee9 ba<\/strong><\/li>\n\n\n\n<li>S\u1ea3n ph\u1ea9m\/ph\u1ea7n m\u1ec1m\/d\u1ecbch v\u1ee5 <strong>kh\u00f4ng \u0111\u01b0\u1ee3c h\u1ed7 tr\u1ee3<\/strong><\/li>\n\n\n\n<li>C\u00e1c th\u1eed nghi\u1ec7m <strong>T\u1eeb ch\u1ed1i D\u1ecbch v\u1ee5 M\u1ea1ng (DoS ho\u1eb7c DDoS)<\/strong> ho\u1eb7c c\u00e1c th\u1eed nghi\u1ec7m kh\u00e1c l\u00e0m gi\u00e1n \u0111o\u1ea1n quy\u1ec1n truy c\u1eadp v\u00e0o h\u1ec7 th\u1ed1ng ho\u1eb7c d\u1eef li\u1ec7u ho\u1eb7c g\u00e2y h\u01b0 h\u1ecfng cho ch\u00fang<\/li>\n<\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">Ngh\u0129a v\u1ee5<\/h1>\n\n\n\n<p>BAS-IP coi tr\u1ecdng v\u00e0 khuy\u1ebfn kh\u00edch n\u1ed7 l\u1ef1c c\u1ee7a c\u00e1c nh\u00e0 nghi\u00ean c\u1ee9u trong vi\u1ec7c x\u00e1c \u0111\u1ecbnh v\u00e0 b\u00e1o c\u00e1o c\u00e1c l\u1ed7 h\u1ed5ng trong c\u00e1c s\u1ea3n ph\u1ea9m, ph\u1ea7n m\u1ec1m v\u00e0 d\u1ecbch v\u1ee5 c\u1ee7a BAS-IP. Theo quy tr\u00ecnh c\u00f4ng b\u1ed1 c\u00f3 tr\u00e1ch nhi\u1ec7m, nh\u00f3m b\u1ea3o m\u1eadt s\u1ea3n ph\u1ea9m c\u1ee7a BAS-IP s\u1ebd, trong kh\u1ea3 n\u0103ng t\u1ed1t nh\u1ea5t c\u1ee7a h\u1ecd, t\u00f4n tr\u1ecdng l\u1ee3i \u00edch c\u1ee7a c\u00e1c nh\u00e0 nghi\u00ean c\u1ee9u th\u00f4ng qua s\u1ef1 h\u1ee3p t\u00e1c l\u1eabn nhau v\u00e0 t\u00ednh minh b\u1ea1ch trong su\u1ed1t qu\u00e1 tr\u00ecnh c\u00f4ng b\u1ed1.<\/p>\n\n\n\n<p>C\u00f4ng ty BAS-IP mong \u0111\u1ee3i r\u1eb1ng c\u00e1c nh\u00e0 nghi\u00ean c\u1ee9u <strong>s\u1ebd kh\u00f4ng ti\u1ebft l\u1ed9 c\u00e1c l\u1ed7 h\u1ed5ng cho \u0111\u1ebfn khi h\u1ebft th\u1eddi h\u1ea1n 90 ng\u00e0y ho\u1eb7c m\u1ed9t ng\u00e0y \u0111\u01b0\u1ee3c th\u1ecfa thu\u1eadn chung<\/strong> v\u00e0 s\u1ebd ti\u1ebfn h\u00e0nh nghi\u00ean c\u1ee9u l\u1ed7 h\u1ed5ng trong <strong>ph\u1ea1m vi ph\u00e1p l\u00fd<\/strong>, kh\u00f4ng g\u00e2y h\u1ea1i, kh\u00f4ng ti\u1ebft l\u1ed9 th\u00f4ng tin m\u1eadt ho\u1eb7c g\u00e2y nguy hi\u1ec3m cho an ninh c\u1ee7a C\u00f4ng ty BAS-IP, c\u00e1c \u0111\u1ed1i t\u00e1c v\u00e0 kh\u00e1ch h\u00e0ng c\u1ee7a h\u1ecd.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Qu\u1ea3n l\u00fd L\u1ed7 h\u1ed5ng <\/h1>\n\n\n\n<p>C\u00f4ng ty BAS-IP \u0111\u00e1nh gi\u00e1 c\u00e1c l\u1ed7 h\u1ed5ng b\u1eb1ng c\u00e1ch s\u1eed d\u1ee5ng h\u1ec7 th\u1ed1ng x\u1ebfp h\u1ea1ng <a href=\"https:\/\/www.first.org\/cvss\/calculator\/3-1\" target=\"_blank\" rel=\"noopener\"><strong>CVSS<\/strong> n\u1ed5i ti\u1ebfng<\/a>.<\/p>\n\n\n\n<p>\u0110\u1ed1i v\u1edbi c\u00e1c l\u1ed7 h\u1ed5ng th\u00e0nh ph\u1ea7n <em>open-source<\/em>, BAS-IP c\u00f3 th\u1ec3 \u0111\u00e1nh gi\u00e1 l\u1ed7 h\u1ed5ng t\u00f9y thu\u1ed9c v\u00e0o t\u1ea7m quan tr\u1ecdng c\u1ee7a n\u00f3 trong b\u1ed1i c\u1ea3nh BAS-IP khuy\u1ebfn ngh\u1ecb c\u00e1ch tri\u1ec3n khai c\u00e1c s\u1ea3n ph\u1ea9m, ph\u1ea7n m\u1ec1m v\u00e0 d\u1ecbch v\u1ee5 c\u1ee7a m\u00ecnh. C\u00e1c t\u01b0 v\u1ea5n b\u1ea3o m\u1eadt th\u01b0\u1eddng ch\u1ec9 \u0111\u01b0\u1ee3c cung c\u1ea5p cho c\u00e1c l\u1ed7 h\u1ed5ng c\u1ee5 th\u1ec3 c\u1ee7a BAS-IP.<\/p>\n\n\n\n<p><strong>Ph\u00e2n b\u1ed5 \u01b0u ti\u00ean<\/strong> khi m\u1ed9t l\u1ed7 h\u1ed5ng \u0111\u00e3 \u0111\u01b0\u1ee3c \u0111\u00e1nh gi\u00e1 v\u00e0 c\u1ea7n \u0111\u01b0\u1ee3c kh\u1eafc ph\u1ee5c:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>CVSS 3.1 high\/critical (7.0 &#8211; 10.0)<\/strong><br>BAS-IP c\u1ed1 g\u1eafng kh\u1eafc ph\u1ee5c l\u1ed7 h\u1ed5ng tr\u01b0\u1edbc ho\u1eb7c trong v\u00f2ng <strong>4 tu\u1ea7n<\/strong> sau khi c\u00f4ng b\u1ed1 b\u00ean ngo\u00e0i. \u0110\u1ed1i v\u1edbi c\u00e1c th\u00e0nh ph\u1ea7n <em>open-source<\/em>, khung th\u1eddi gian th\u01b0\u1eddng d\u00e0i h\u01a1n, v\u00ec BAS-IP ph\u1ee5 thu\u1ed9c v\u00e0o c\u00e1c b\u00ean b\u00ean ngo\u00e0i \u0111\u1ec3 c\u00f3 th\u00f4ng tin, b\u1ea3n v\u00e1 v\u00e0\/ho\u1eb7c x\u00e1c minh<\/li>\n\n\n\n<li><strong>CVSS 3.1 medium (4.0 &#8211; 6.9)<\/strong><br>BAS-IP \u0111\u1eb7t m\u1ee5c ti\u00eau kh\u1eafc ph\u1ee5c l\u1ed7 h\u1ed5ng, th\u01b0\u1eddng trong v\u00f2ng <strong>2-3 th\u00e1ng<\/strong><\/li>\n\n\n\n<li><strong>CVSS 3.1 low (0.1 &#8211; 3.9)<\/strong><br>BAS-IP c\u00f3 k\u1ebf ho\u1ea1ch kh\u1eafc ph\u1ee5c l\u1ed7 h\u1ed5ng trong <strong>b\u1ea3n ph\u00e1t h\u00e0nh theo l\u1ecbch tr\u00ecnh ti\u1ebfp theo<\/strong><\/li>\n\n\n\n<li>Ph\u1ea7n m\u1ec1m\/d\u1ecbch v\u1ee5 \u0111\u01b0\u1ee3c h\u1ed7 tr\u1ee3 (Supported software\/services)<br>Giai \u0111o\u1ea1n h\u1ed7 tr\u1ee3 c\u1ee7a ph\u1ea7n m\u1ec1m\/d\u1ecbch v\u1ee5 BAS-IP \u0111\u01b0\u1ee3c x\u00e1c \u0111\u1ecbnh trong quy tr\u00ecnh t\u1ed5ng th\u1ec3 c\u1ee7a v\u00f2ng \u0111\u1eddi ph\u1ea7n m\u1ec1m. Ph\u1ea7n m\u1ec1m\/d\u1ecbch v\u1ee5 BAS-IP th\u01b0\u1eddng \u0111\u01b0\u1ee3c h\u1ed7 tr\u1ee3 trong <strong>1 n\u0103m sau th\u00f4ng b\u00e1o k\u1ebft th\u00fac v\u00f2ng \u0111\u1eddi<\/strong> (<em>end-of-life<\/em>).<\/li>\n<\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">B\u00e1o c\u00e1o L\u1ed7 h\u1ed5ng<\/h1>\n\n\n\n<p>BAS-IP kh\u00f4ng ng\u1eebng n\u1ed7 l\u1ef1c \u0111\u1ec3 x\u00e1c \u0111\u1ecbnh v\u00e0 gi\u1ea3m thi\u1ec3u r\u1ee7i ro li\u00ean quan \u0111\u1ebfn c\u00e1c l\u1ed7 h\u1ed5ng trong s\u1ea3n ph\u1ea9m c\u1ee7a ch\u00fang t\u00f4i. Tuy nhi\u00ean, n\u1ebfu b\u1ea1n \u0111\u00e3 ph\u00e1t hi\u1ec7n ra m\u1ed9t l\u1ed7 h\u1ed5ng h\u1ec7 th\u1ed1ng b\u1ea3o m\u1eadt li\u00ean quan \u0111\u1ebfn m\u1ed9t s\u1ea3n ph\u1ea9m, ph\u1ea7n m\u1ec1m ho\u1eb7c d\u1ecbch v\u1ee5 c\u1ee7a BAS-IP, ch\u00fang t\u00f4i \u0111\u1eb7c bi\u1ec7t khuy\u00ean b\u1ea1n n\u00ean <strong>b\u00e1o c\u00e1o v\u1ea5n \u0111\u1ec1 ngay l\u1eadp t\u1ee9c<\/strong>. Vi\u1ec7c b\u00e1o c\u00e1o k\u1ecbp th\u1eddi c\u00e1c l\u1ed7 h\u1ed5ng h\u1ec7 th\u1ed1ng b\u1ea3o m\u1eadt l\u00e0 r\u1ea5t quan tr\u1ecdng \u0111\u1ec3 gi\u1ea3m kh\u1ea3 n\u0103ng ch\u00fang \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng trong th\u1ef1c t\u1ebf. C\u00e1c l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt li\u00ean quan \u0111\u1ebfn c\u00e1c th\u00e0nh ph\u1ea7n ph\u1ea7n m\u1ec1m <em>open-source<\/em> n\u00ean \u0111\u01b0\u1ee3c b\u00e1o c\u00e1o tr\u1ef1c ti\u1ebfp cho t\u1ed5 ch\u1ee9c ch\u1ecbu tr\u00e1ch nhi\u1ec7m.<\/p>\n\n\n\n<p>Ng\u01b0\u1eddi d\u00f9ng cu\u1ed1i, \u0111\u1ed1i t\u00e1c, nh\u00e0 cung c\u1ea5p, c\u00e1c nh\u00f3m ng\u00e0nh v\u00e0 c\u00e1c nh\u00e0 nghi\u00ean c\u1ee9u \u0111\u1ed9c l\u1eadp \u0111\u00e3 ph\u00e1t hi\u1ec7n ra m\u1ed9t l\u1ed7 h\u1ed5ng ti\u1ec1m \u1ea9n \u0111\u01b0\u1ee3c khuy\u1ebfn kh\u00edch b\u00e1o c\u00e1o ph\u00e1t hi\u1ec7n c\u1ee7a h\u1ecd t\u1edbi <strong><a href=\"mailto:security@bas-ip.com\">security@bas-ip.com<\/a><\/strong> ho\u1eb7c b\u1eb1ng c\u00e1ch \u0111i\u1ec1n v\u00e0o <strong><a href=\"https:\/\/docs.google.com\/forms\/d\/e\/1FAIpQLSdetHDUfdt0Fxk9ctY1-XWJARmQA_2-wBeXVbX2fnweQasVAA\/viewform\" target=\"_blank\" rel=\"noopener\">m\u1eabu \u1ea9n danh<\/a><\/strong>.<\/p>\n\n\n\n<p>B\u00e1o c\u00e1o \u0111\u00e3 g\u1eedi n\u00ean bao g\u1ed3m:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Th\u00f4ng tin k\u1ef9 thu\u1eadt v\u1ec1 l\u1ed7 h\u1ed5ng ti\u1ec1m \u1ea9n<\/li>\n\n\n\n<li>C\u00e1c b\u01b0\u1edbc \u0111\u1ec3 t\u00e1i t\u1ea1o<\/li>\n\n\n\n<li>\u01af\u1edbc t\u00ednh t\u00e1c \u0111\u1ed9ng v\u00e0 m\u1ee9c \u0111\u1ed9 nghi\u00eam tr\u1ecdng trong tr\u01b0\u1eddng h\u1ee3p b\u1ecb khai th\u00e1c theo CVSS 3.1<\/li>\n\n\n\n<li>Ch\u00ednh s\u00e1ch c\u00f4ng b\u1ed1 l\u1ed7 h\u1ed5ng c\u1ee7a ri\u00eang nh\u00e0 nghi\u00ean c\u1ee9u, n\u1ebfu c\u00f3<\/li>\n<\/ul>\n\n\n\n<p>B\u1ea1n c\u00f3 th\u1ec3 mong \u0111\u1ee3i nh\u1eefng \u0111i\u1ec1u sau t\u1eeb C\u00f4ng ty BAS-IP:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Th\u1eddi gian ph\u1ea3n h\u1ed3i l\u1ea7n \u0111\u1ea7u \u2014 trong v\u00f2ng <strong>3 ng\u00e0y l\u00e0m vi\u1ec7c<\/strong> sau khi nh\u1eadn \u0111\u01b0\u1ee3c tin nh\u1eafn ban \u0111\u1ea7u<\/li>\n\n\n\n<li>Th\u1eddi gian x\u1eed l\u00fd (k\u1ec3 t\u1eeb th\u1eddi \u0111i\u1ec3m nh\u1eadn \u0111\u01b0\u1ee3c ph\u1ea3n h\u1ed3i \u0111\u1ea7u ti\u00ean) \u2014 trong v\u00f2ng <strong>10 ng\u00e0y l\u00e0m vi\u1ec7c<\/strong><\/li>\n\n\n\n<li>Ch\u00fang t\u00f4i s\u1ebd minh b\u1ea1ch nh\u1ea5t c\u00f3 th\u1ec3 v\u1ec1 c\u00e1c b\u01b0\u1edbc ch\u00fang t\u00f4i th\u1ef1c hi\u1ec7n trong qu\u00e1 tr\u00ecnh kh\u1eafc ph\u1ee5c, bao g\u1ed3m c\u00e1c c\u00e2u h\u1ecfi v\u00e0 v\u1ea5n \u0111\u1ec1 c\u00f3 th\u1ec3 l\u00e0m ch\u1eadm gi\u1ea3i ph\u00e1p<\/li>\n\n\n\n<li>Ch\u00fang t\u00f4i s\u1ebd duy tr\u00ec m\u1ed9t cu\u1ed9c \u0111\u1ed1i tho\u1ea1i c\u1edfi m\u1edf \u0111\u1ec3 th\u1ea3o lu\u1eadn c\u00e1c v\u1ea5n \u0111\u1ec1<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">C\u00f4ng b\u1ed1 L\u1ed7 h\u1ed5ng<\/h2>\n\n\n\n<p>Khi b\u00e1o c\u00e1o v\u1ec1 m\u1ed9t l\u1ed7 h\u1ed5ng \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n \u0111\u00e3 \u0111\u01b0\u1ee3c xem x\u00e9t v\u00e0 x\u00e1c nh\u1eadn l\u00e0 ch\u00ednh x\u00e1c, BAS-IP s\u1ebd b\u1eaft \u0111\u1ea7u qu\u00e1 tr\u00ecnh <strong>c\u00f4ng b\u1ed1 c\u00f3 tr\u00e1ch nhi\u1ec7m<\/strong>. BAS-IP c\u1ed1 g\u1eafng h\u1ee3p t\u00e1c v\u1edbi nh\u00e0 nghi\u00ean c\u1ee9u v\u1ec1 c\u00e1c chi ti\u1ebft b\u1ed5 sung, ch\u1eb3ng h\u1ea1n nh\u01b0 \u0111\u00e1nh gi\u00e1 CVSS 3.1, n\u1ed9i dung khuy\u1ebfn ngh\u1ecb b\u1ea3o m\u1eadt v\u00e0\/ho\u1eb7c th\u00f4ng c\u00e1o b\u00e1o ch\u00ed (n\u1ebfu c\u00f3), v\u00e0 ng\u00e0y c\u00f4ng b\u1ed1 b\u00ean ngo\u00e0i.<\/p>\n\n\n\n<p>Sau khi c\u00f3 th\u1ecfa thu\u1eadn gi\u1eefa C\u00f4ng ty BAS-IP v\u00e0 nh\u00e0 nghi\u00ean c\u1ee9u, l\u1ed7 h\u1ed5ng s\u1ebd \u0111\u01b0\u1ee3c c\u00f4ng b\u1ed1 cho m\u1ee5c \u0111\u00edch b\u00ean ngo\u00e0i b\u1eb1ng c\u00e1ch C\u00f4ng ty BAS-IP xu\u1ea5t b\u1ea3n c\u00e1c khuy\u1ebfn ngh\u1ecb b\u1ea3o m\u1eadt v\u00e0\/ho\u1eb7c m\u1ed9t th\u00f4ng c\u00e1o b\u00e1o ch\u00ed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">L\u1ecbch s\u1eed Thay \u0111\u1ed5i T\u00e0i li\u1ec7u<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><th>Phi\u00ean b\u1ea3n<\/th><th>Ng\u00e0y<\/th><th>M\u00f4 t\u1ea3<\/th><\/tr><tr><td>1.0<\/td><td>15.02.2024<\/td><td>B\u1ea3n ph\u00e1t h\u00e0nh \u0111\u1ea7u ti\u00ean<\/td><\/tr><\/tbody><\/table><\/figure>","protected":false},"excerpt":{"rendered":"<p>Ch\u00ednh s\u00e1ch c\u00f4ng b\u1ed1 l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt Th\u00f4ng tin chung BAS-IP tu\u00e2n th\u1ee7 c\u00e1c th\u1ef1c ti\u1ec5n h\u00e0ng \u0111\u1ea7u trong ng\u00e0nh v\u1ec1 qu\u1ea3n l\u00fd v\u00e0 ph\u1ea3n h\u1ed3i c\u00e1c l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n trong c\u00e1c s\u1ea3n ph\u1ea9m c\u1ee7a ch\u00fang t\u00f4i. Kh\u00f4ng th\u1ec3 \u0111\u1ea3m b\u1ea3o r\u1eb1ng c\u00e1c s\u1ea3n ph\u1ea9m v\u00e0 d\u1ecbch v\u1ee5 do c\u00f4ng [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-151332","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/pages\/151332","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/comments?post=151332"}],"version-history":[{"count":2,"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/pages\/151332\/revisions"}],"predecessor-version":[{"id":151418,"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/pages\/151332\/revisions\/151418"}],"wp:attachment":[{"href":"https:\/\/bas-ip.com\/vi\/wp-json\/wp\/v2\/media?parent=151332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}