This SRU number: 2019-09-25-001
Previous SRU number: 2019-09-23-001
Applies to:
This SEU number: 2072
Previous SEU: 2071
Applies to:
This is the complete list of rules added in SRU 2019-09-25-001 and SEU 2072.
The format of the file is:
GID - SID - Rule Group - Rule Message - Policy State
The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.
The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.
Note: Unless stated explicitly, the rules are for the series of products listed above.
GID | SID | Rule Group | Rule Message | Policy State | |||
---|---|---|---|---|---|---|---|
Con. | Bal. | Sec. | Max. | ||||
1 | 51620 | SERVER-WEBAPP | vBulletin pre-authenticated command injection attempt | drop | drop | drop | drop |
1 | 51621 | SERVER-WEBAPP | vBulletin pre-authenticated command injection attempt | drop | drop | drop | drop |
3 | 51622 | SERVER-WEBAPP | Cisco IOS XE Software command injection attempt | off | off | drop | drop |
3 | 51623 | SERVER-WEBAPP | Cisco IOS XE Software command injection attempt | off | off | drop | drop |
3 | 51624 | SERVER-WEBAPP | Cisco IOS XE Software command injection attempt | off | off | drop | drop |
3 | 51625 | SERVER-WEBAPP | Cisco IOS XE Software command injection attempt | off | off | drop | drop |
1 | 51629 | SERVER-WEBAPP | Trend Micro Control Manager reporting.aspx SQL injection attempt | off | off | drop | drop |
1 | 51630 | SERVER-WEBAPP | Trend Micro Control Manager reporting.aspx SQL injection attempt | off | off | drop | drop |
1 | 51631 | POLICY-OTHER | Easy Hosting Control Panel command execution attempt | off | off | off | drop |
1 | 51632 | INDICATOR-OBFUSCATION | JavaScript exploit obfuscation attempt | off | off | off | drop |
1 | 51633 | INDICATOR-OBFUSCATION | JavaScript exploit obfuscation attempt | off | off | off | drop |
1 | 51634 | MALWARE-CNC | Win.Trojan.Ordinypt malicious executable download attempt | off | drop | drop | drop |
1 | 51635 | MALWARE-CNC | Win.Trojan.Ordinypt malicious executable download attempt | off | drop | drop | drop |
1 | 51636 | EXPLOIT-KIT | Rig exploit kit outbound connection | off | drop | drop | drop |
1 | 51637 | EXPLOIT-KIT | Rig exploit kit executable download attempt | off | drop | drop | drop |
1 | 51638 | EXPLOIT-KIT | Rig exploit kit executable download attempt | off | drop | drop | drop |
1 | 51639 | SERVER-OTHER | AVEVA InduSoft Web Studio and InTouch Edge HMI buffer overflow attempt | off | off | drop | drop |
1 | 51640 | SERVER-WEBAPP | JavaScript library OpenPGP.js improper signature verification attempt | off | off | drop | drop |
1 | 51641 | SERVER-WEBAPP | JavaScript library OpenPGP.js improper signature verification attempt | off | off | drop | drop |
1 | 51642 | MALWARE-CNC | Osx.Trojan.Gmera variant outbound connection | off | drop | drop | drop |
1 | 51643 | FILE-FLASH | Adobe Flash Player use-after-free attempt | off | off | drop | drop |
1 | 51644 | FILE-FLASH | Adobe Flash Player use-after-free attempt | off | off | drop | drop |
1 | 51647 | SERVER-OTHER | Indusoft Web Studio and Intouch Machine Edition stack buffer overflow attempt | off | off | drop | drop |
1 | 51648 | FILE-FLASH | Adobe Flash Player ActiveX same origin method execution attempt | off | off | drop | drop |
3 | 51650 | POLICY-OTHER | TRUFFLEHUNTER TALOS-2019-0898 attack attempt | off | off | off | off |
3 | 51651 | POLICY-OTHER | TRUFFLEHUNTER TALOS-2019-0896 attack attempt | off | off | off | off |
1 | 51653 | SERVER-WEBAPP | Weblog Expert Web Server Enterprise denial of service attempt | off | off | off | drop |
GID | SID | Rule Group | Rule Message | Policy State | |||
---|---|---|---|---|---|---|---|
Con. | Bal. | Sec. | Max. | ||||
3 | 51626 | PROTOCOL-VOIP | Cisco IOS SIP denial of service attempt | off | off | off | drop |
3 | 51627 | PROTOCOL-VOIP | Cisco IOS SIP denial of service attempt | off | off | off | drop |
3 | 51628 | POLICY-OTHER | Cisco IOS Layer 2 Traceroute vlan enumeration detected | off | off | off | off |
3 | 51645 | SERVER-OTHER | Cisco IOx invalid TLS handshake type denial of service attempt | off | off | off | drop |
3 | 51646 | SERVER-OTHER | Cisco IOS XE FTP Application Layer Gateway denial of service attempt | off | off | off | drop |
3 | 51649 | OS-WINDOWS | TRUFFLEHUNTER TALOS-2019-0901 attack attempt | off | off | drop | drop |
3 | 51652 | SERVER-WEBAPP | TRUFFLEHUNTER TALOS-2019-0894 attack attempt | off | off | drop | drop |