Cisco Talos Update for FireSIGHT Management Center

Date: 2018-05-03

This SRU number: 2018-05-03-001
Previous SRU number: 2018-04-30-003

Applies to:

This SEU number: 1845
Previous SEU: 1843

Applies to:

This is the complete list of rules added in SRU 2018-05-03-001 and SEU 1845.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
146469SERVER-WEBAPPPHP unserialize integer overflow attemptoffoffoffdrop
146470SERVER-WEBAPPPHP unserialize integer overflow attemptoffoffoffdrop
146471BROWSER-IEMicrosoft Edge Chakra code execution attemptoffoffoffoff
146472BROWSER-IEMicrosoft Edge Chakra code execution attemptoffoffoffoff
146473SERVER-OTHERSpring Data Commons remote code execution attemptoffdropdropdrop
146474SERVER-OTHERQuest Appliance NetVault Backup buffer overflow attemptoffdropdropdrop
146475MALWARE-CNCWin.Trojan.SquirtDanger get module list outbound requestoffdropdropdrop
146476MALWARE-CNCWin.Trojan.SquirtDanger inbound delivery attemptoffdropdropdrop
146477MALWARE-CNCWin.Trojan.SquirtDanger inbound delivery attemptoffdropdropdrop
146478MALWARE-CNCWin.Trojan.SquirtDanger inbound delivery attemptoffdropdropdrop
146479MALWARE-CNCWin.Trojan.SquirtDanger inbound delivery attemptoffdropdropdrop
146480FILE-MULTIMEDIAApple QuickTime movie file keys atom integer overflow attemptoffoffoffdrop
146481FILE-MULTIMEDIAApple QuickTime movie file keys atom integer overflow attemptoffoffoffdrop
146482MALWARE-CNCInstallation Keylogger Osx.Trojan.Mokes data exfiltrationoffoffoffoff
146483SERVER-WEBAPPWordpress VideoWhisper Live Streaming Integration plugin double extension file upload attemptoffoffoffoff
146484SERVER-MAILMultiple IMAP servers DELETE command buffer overflow attemptoffoffoffoff
146485SERVER-WEBAPPTwonkyMedia server directory listing attemptoffoffoffoff
146486PUA-ADWARESlimware Utilities variant outbound connectionoffdropdropdrop
146487MALWARE-CNCWin.Trojan.Ammy heartbeatoffdropdropdrop
146488MALWARE-CNCWin.Trojan.Ammy download attemptoffdropdropdrop
146489SERVER-WEBAPPQuest NetVault Backup Server NVBUBackup SQL injection attemptoffoffdropdrop
146490FILE-PDFAdobe Flash Player ActionScript setFocus use after free attemptoffdropdropdrop
146491FILE-PDFAdobe Flash Player ActionScript setFocus use after free attemptoffdropdropdrop
346492SERVER-WEBAPPCisco Prime Infrastructure upload servlet directory traversal attemptoffoffdropdrop
346493SERVER-WEBAPPCisco Prime Infrastructure upload servlet directory traversal attemptoffoffdropdrop
346494SERVER-WEBAPPCisco Prime Infrastructure upload servlet directory traversal attemptoffoffdropdrop
346496FILE-OTHERCisco WebEx Recording Player memory corruption attemptoffoffdropdrop
346497FILE-OTHERCisco WebEx Recording Player memory corruption attemptoffoffdropdrop
346498FILE-OTHERCisco WebEx Recording Player memory corruption attemptoffoffdropdrop
346499FILE-OTHERCisco WebEx Recording Player memory corruption attemptoffoffdropdrop
346500POLICY-OTHERDocker API ContainerCreate request detectedoffoffoffoff
146501MALWARE-CNCWin.Trojan.Agent outbound requestoffdropdropdrop
146502MALWARE-CNCWin.Trojan.Agent outbound requestoffdropdropdrop
146503OS-WINDOWSMicrosoft Windows TTF cmap integer overflow attemptoffoffoffdrop
146504OS-WINDOWSMicrosoft Windows TTF cmap integer overflow attemptoffoffoffdrop
146505BROWSER-IEMicrosoft Edge eval heap overflow attemptoffoffoffdrop
146506BROWSER-IEMicrosoft Edge eval heap overflow attemptoffoffoffdrop
146507BROWSER-IEMicrosoft Edge eval heap overflow attemptoffoffoffdrop
146508BROWSER-IEMicrosoft Edge eval heap overflow attemptoffoffoffdrop
146509SERVER-WEBAPPUnitrends Enterprise Backup API command injection attemptoffoffdropdrop
146510SERVER-WEBAPPBelkin N750 F9K1103 wireless router command injection attemptoffoffdropdrop
146511SERVER-WEBAPPBelkin N750 F9K1103 wireless router command injection attemptoffoffdropdrop
146512SERVER-WEBAPPBelkin N750 F9K1103 wireless router command injection attemptoffoffdropdrop
146513SERVER-WEBAPPBelkin N750 F9K1103 wireless router command injection attemptoffoffdropdrop
146514SERVER-WEBAPPBelkin N750 F9K1103 wireless router command injection attemptoffoffdropdrop
146515SERVER-WEBAPPBelkin N750 F9K1103 wireless router command injection attemptoffoffdropdrop
146516SERVER-WEBAPPBelkin N750 F9K1103 wireless router command injection attemptoffoffdropdrop
146517SERVER-WEBAPPBelkin N750 F9K1103 wireless router command injection attemptoffoffdropdrop
146518SERVER-WEBAPPBelkin N750 F9K1103 wireless router remote telnet enable attemptoffoffoffoff
146519SERVER-WEBAPPBelkin N750 F9K1103 wireless router remote telnet enable attemptoffoffoffoff
146520SERVER-WEBAPPWebPort 1.16.2 directory traversal attemptoffoffdropdrop
146521SERVER-WEBAPPWebPort 1.16.2 directory traversal attemptoffoffdropdrop
146522SERVER-WEBAPPWebPort 1.16.2 directory traversal attemptoffoffdropdrop
146524SERVER-WEBAPPOpenEMR 5.0 directory traversal attemptoffoffdropdrop
146525SERVER-WEBAPPOpenEMR 5.0 directory traversal attemptoffoffdropdrop
146526SERVER-WEBAPPOpenEMR 5.0 directory traversal attemptoffoffdropdrop
146527SERVER-WEBAPPLibreEHR 2.0.0 directory traversal attemptoffoffdropdrop
146528SERVER-WEBAPPLibreEHR 2.0.0 directory traversal attemptoffoffdropdrop
146529SERVER-WEBAPPLibreEHR 2.0.0 directory traversal attemptoffoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
146495SERVER-OTHERHTTP request smuggling attemptoffoffoffoff
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
346523SERVER-OTHERmalicious HTML file transfer attemptoffoffoffdrop