Cisco Talos Update for FireSIGHT Management Center

Date: 2019-08-22

This SRU number: 2019-08-21-001
Previous SRU number: 2019-08-19-001

Applies to:

This SEU number: 2056
Previous SEU: 2055

Applies to:

This is the complete list of rules added in SRU 2019-08-21-001 and SEU 2056.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
350903SERVER-WEBAPPCisco UCS Director command injection attemptoffoffdropdrop
151138SERVER-WEBAPPPHP phpinfo function cross site scripting attemptoffoffoffdrop
151139SERVER-WEBAPPPHP phpinfo function cross site scripting attemptoffoffoffdrop
151141SERVER-OTHEROracle Tuxedo Jolt server heap overflow attemptoffoffoffdrop
151142SERVER-WEBAPPMoodle 3.x PHP code injection attemptoffoffdropdrop
151143SERVER-WEBAPPMoodle 3.x PHP code injection attemptoffoffdropdrop
151145SERVER-OTHERHPE Intelligent Management Center 10001 buffer overflow attemptoffoffoffdrop
151146SERVER-WEBAPPFasterXML Jackson Databind unsafe deserialization attemptoffoffoffdrop
151148SERVER-WEBAPPManageEngine Desktop Central cross site scripting attemptoffoffoffdrop
151149SERVER-WEBAPPManageEngine Desktop Central cross site scripting attemptoffoffoffdrop
151150SERVER-OTHERDEWESoft X3 RunExeFile.exe unauthenticated remote code execution attemptoffoffoffdrop
151151SERVER-OTHERDEWESoft X3 RunExeFile.exe unauthenticated remote code execution attemptoffoffoffdrop
151152SERVER-OTHERDEWESoft X3 RunExeFile.exe unauthenticated remote code execution attemptoffoffoffdrop
151153SERVER-OTHERDEWESoft X3 RunExeFile.exe unauthenticated remote code execution attemptoffoffoffdrop
151154SERVER-OTHERDEWESoft X3 RunExeFile.exe unauthenticated remote code execution attemptoffoffoffdrop
151155SERVER-OTHERDEWESoft X3 RunExeFile.exe unauthenticated remote code execution attemptoffoffoffdrop
151156SERVER-OTHERDEWESoft X3 RunExeFile.exe unauthenticated remote code execution attemptoffoffoffdrop
151157SERVER-OTHERDEWESoft X3 RunExeFile.exe unauthenticated remote code execution attemptoffoffoffdrop
151158SERVER-OTHERDEWESoft X3 RunExeFile.exe unauthenticated remote code execution attemptoffoffoffdrop
151159OS-WINDOWSMicrosoft Windows DHCP client Domain Search response memory corruption attemptoffoffoffdrop
151160FILE-IMAGEMicrosoft GDI crafted EMF file information disclosure attemptoffoffoffdrop
151161FILE-IMAGEMicrosoft GDI crafted EMF file information disclosure attemptoffoffoffdrop
351164SERVER-WEBAPPCisco Integrated Management Controller Redfish API command injection attemptoffoffdropdrop
151165FILE-OFFICEMicrosoft Office Excel SxView heap overflow attemptoffoffoffdrop
151166FILE-OFFICEMicrosoft Office Excel SxView heap overflow attemptoffoffoffdrop
151167FILE-OFFICEMicrosoft Office Excel SxView heap overflow attemptoffoffoffdrop
151168FILE-OFFICEMicrosoft Office Excel SxView heap overflow attemptoffoffoffdrop
151169FILE-OFFICEMicrosoft Office Excel SxView heap overflow attemptoffoffoffdrop
151170FILE-OFFICEMicrosoft Office Excel SxView heap overflow attemptoffoffoffdrop
151171FILE-OFFICEMicrosoft Office Excel SxView heap overflow attemptoffoffoffdrop
151172FILE-OFFICEMicrosoft Office Excel SxView heap overflow attemptoffoffoffdrop
351173SERVER-WEBAPPCisco UCS Director authentication bypass attemptoffoffdropdrop
151174SERVER-WEBAPPvCard Create Card cross site scripting attemptoffoffoffdrop
151175SERVER-WEBAPPvCard Create Card cross site scripting attemptoffoffoffdrop
151176SERVER-WEBAPPvCard Toprated cross site scripting attemptoffoffoffdrop
151177SERVER-WEBAPPvCard Toprated cross site scripting attemptoffoffoffdrop
151178SERVER-WEBAPPvCard New Card cross site scripting attemptoffoffoffdrop
151179SERVER-WEBAPPvCard New Card cross site scripting attemptoffoffoffdrop
351180SERVER-OTHERCisco Integrated Management Controller IPMI command injection attemptoffoffdropdrop
151181SERVER-OTHERNTPsec 1.1.2 ntp_control out-of-bounds read attemptoffoffoffdrop
151182FILE-OFFICEMicrosoft Excel Jet Database Engine code execution attemptoffoffoffdrop
151183FILE-OFFICEMicrosoft Excel Jet Database Engine code execution attemptoffoffoffdrop
151184SERVER-WEBAPPXalan-Java secure processing bypass attemptoffoffoffdrop
351187SERVER-WEBAPPCisco Integrated Management Controller buffer overflow attemptoffoffdropdrop
351188SERVER-WEBAPPCisco Integrated Management Controller command injection attemptoffoffdropdrop
351189SERVER-WEBAPPCisco Integrated Management Controller command injection attemptoffoffdropdrop
151190SERVER-WEBAPPNovell iManager buffer overflow attemptoffoffoffdrop
151191FILE-OTHEROMRON CX-One MCI file stack buffer overflow attemptoffoffoffdrop
151192FILE-OTHEROMRON CX-One MCI file stack buffer overflow attemptoffoffoffdrop
351193SERVER-WEBAPPCisco Integrated Management Controller command injection attemptoffoffdropdrop
351194SERVER-WEBAPPCisco Integrated Management Controller command injection attemptoffoffdropdrop
351195SERVER-WEBAPPCisco Integrated Management Controller command injection attemptoffoffdropdrop
151196SERVER-WEBAPPFLIR AX8 Camera arbitrary file download attemptoffoffoffdrop
151197SERVER-WEBAPPFLIR AX8 Camera arbitrary file download attemptoffoffoffdrop
351200POLICY-OTHERCisco UCS Director Intersight API unauthenticated request detectedoffoffoffoff
351201SERVER-WEBAPPCisco Integrated Management Controller authentication bypass attemptoffoffdropdrop
151202INDICATOR-COMPROMISEDana IRC stack buffer overflow attemptoffoffoffdrop
151203FILE-IMAGEMicrosoft Office PNG tEXt chunk buffer overflow attemptoffoffoffdrop
151204FILE-IMAGEMicrosoft Office PNG tEXt chunk buffer overflow attemptoffoffoffdrop
151205FILE-IMAGEMicrosoft Office PNG tEXt chunk buffer overflow attemptoffoffoffdrop
151206FILE-IMAGEMicrosoft Office PNG tEXt chunk buffer overflow attemptoffoffoffdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
151140SERVER-OTHERSplashtop Streamer Personal random data stream denial of service attemptoffoffoffdrop
151144SERVER-OTHERISC BIND multiple ENDS Key Tag options denial of service attemptoffoffoffdrop
151147FILE-OTHERWorld of Warcraft local denial of service attemptoffoffoffdrop
151185SERVER-OTHERMemcached lru temp_ttl NULL dereference attemptoffoffoffdrop
151186SERVER-OTHERMemcached lru mode NULL dereference attemptoffoffoffdrop
351198SERVER-WEBAPPCisco Integrated Management Controller denial of service attemptoffoffdropdrop
351199SERVER-WEBAPPCisco Integrated Management Controller denial of service attemptoffoffdropdrop
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
151162FILE-PDFAdobe Acrobat Reader RGB color table out of bounds read attemptoffoffoffdrop
151163FILE-PDFAdobe Acrobat Reader RGB color table out of bounds read attemptoffoffoffdrop