Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2018-03-29

This SRU number: 2018-03-29-001
Previous SRU number: 2018-03-26-001

Applies to:

This SEU number: 1817
Previous SEU: 1815

Applies to:

This is the complete list of rules added in SRU 2018-03-29-001 and SEU 1817.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
346095POLICY-OTHERCisco IOS XE default one-time password login detectedoffoffalertalert
346096SERVER-OTHERCisco SMI invalid discovery init message memory corruption or denial of service attemptoffdropdropdrop
146099MALWARE-CNCWin.Trojan.Modimer Trojanized MediaGet outbound connectionoffdropdropdrop
146100SERVER-WEBAPPLaerdal SimMan-3G arbitrary file upload attemptoffoffdropdrop
346102POLICY-OTHERFlash file external url request attemptoffoffoffoff
346103POLICY-OTHERFlash file external url request attemptoffoffoffoff
346104SERVER-OTHERCisco IOS DHCP relay agent information memory corruption attemptoffoffdropdrop
146106FILE-OFFICEMicrosoft Office Equation Editor RTF evasion attemptoffoffdropdrop
146107FILE-OFFICEMicrosoft Office Equation Editor RTF evasion attemptoffoffdropdrop
346108SERVER-WEBAPPCisco Prime Collaboration Provisioning writable file privilege escalation attemptoffoffoffoff
346109SERVER-WEBAPPCisco Prime Collaboration Provisioning writable file privilege escalation attemptoffoffoffoff
346110SERVER-OTHERCisco ASR1001 IKEv2 memory leak attemptoffdropdropdrop
346111SERVER-OTHERCisco IOS Adaptive QoS message parsing stack buffer overflow attemptoffoffdropdrop
146112SERVER-WEBAPPAdvantech WebAccess directory traversal attemptoffoffoffoff
146113SERVER-WEBAPPAdvantech WebAccess directory traversal attemptoffoffoffoff
146114SERVER-WEBAPPAdvantech WebAccess directory traversal attemptoffoffoffoff
146115SERVER-APACHEFrontPage privilege escalation attemptoffoffoffoff
146116SERVER-APACHEFrontPage privilege escalation attemptoffoffoffoff
146117FILE-OTHERAdobe Acrobat Pro JPEG embedded XPS file heap overflow attemptoffoffoffdrop
146118FILE-OTHERAdobe Acrobat Pro JPEG embedded XPS file heap overflow attemptoffoffoffdrop
346119SERVER-OTHERCisco IOS DHCP relay reply integer underflow attemptoffoffdropdrop
346120SERVER-OTHERCisco IOS DHCP relay integer underflow attemptoffoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
346097SERVER-OTHERCisco SMI invalid discovery init message denial of service attemptoffdropdropdrop
146098PROTOCOL-OTHERRouting Information Protocol version 1 potential amplified distributed denial of service attemptoffoffoffoff
346101PROTOCOL-SNMPCisco IOS SNMP ciscoFlashFileEntry OID denial of service attemptoffoffdropdrop
346105PROTOCOL-SNMPCisco IOS SNMP natPoolRange OID denial of service attemptoffoffdropdrop
346125SERVER-OTHERCisco IOS invalid IKEv1 payload denial of service attemptoffoffdropdrop
346126SERVER-OTHERCisco IOS XE IGMP denial of service attemptoffoffoffoff
346127SERVER-OTHERCisco IOS XE IGMP denial of service attemptoffoffoffoff
346128SERVER-OTHERCisco IOS XE IGMP denial of service attemptoffoffoffoff
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
146121PROTOCOL-OTHERuse of undocumented ScMM test interface in Cisco small business devices detectedoffoffoffoff
146122PROTOCOL-OTHERuse of undocumented ScMM test interface in Cisco small business devices detectedoffoffoffoff
146123PROTOCOL-OTHERuse of undocumented ScMM test interface in Cisco small business devices detectedoffoffoffoff
146124PROTOCOL-OTHERuse of undocumented ScMM test interface in Cisco small business devices detectedoffoffoffoff