Cisco Talos Update for FireSIGHT Management Center

Date: 2019-11-07

This SRU number: 2019-11-06-001
Previous SRU number: 2019-11-04-001

Applies to:

This SEU number: 2091
Previous SEU: 2090

Applies to:

This is the complete list of rules added in SRU 2019-11-06-001 and SEU 2091.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
152099SERVER-WEBAPPJenkins SCM Git Client plugin command injection attemptoffoffdropdrop
152100OS-MOBILEAndroid Stagefright MP4 buffer overflow attemptoffoffoffdrop
152101OS-MOBILEAndroid Stagefright MP4 buffer overflow attemptoffoffoffdrop
352102FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
352103FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
352104FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
352105FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
352106FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
352107FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
352108FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
352109FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
352110FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
352111FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
152112SERVER-WEBAPPGit client path validation command execution attemptoffoffoffdrop
152113FILE-OTHEROracle Outside-In library CorelDRAW parsing integer overflow attemptoffoffoffdrop
152114FILE-OTHEROracle Outside-In library CorelDRAW parsing integer overflow attemptoffoffoffdrop
152115INDICATOR-COMPROMISEXml.Downloader.PowMet fileless malware variant download attemptoffdropdropdrop
152116INDICATOR-COMPROMISEWin.Downloader.PowMet powershell script download attemptoffdropdropdrop
152117INDICATOR-COMPROMISEXml.Downloader.PowMet fileless malware variant download attemptoffdropdropdrop
152118INDICATOR-COMPROMISEWin.Downloader.PowMet powershell script download attemptoffdropdropdrop
352119SERVER-WEBAPPCisco RV Series Routers command injection attemptoffoffdropdrop
352120SERVER-WEBAPPCisco RV Series Routers command injection attemptoffoffdropdrop
352121SERVER-WEBAPPCisco RV Series Routers command injection attemptoffoffdropdrop
352122SERVER-WEBAPPCisco RV Series Routers command injection attemptoffoffdropdrop
152123SERVER-WEBAPPPHP FPM env_path_info buffer underflow attemptoffoffdropdrop
152124FILE-PDFAdobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attemptoffdropdropdrop
152125FILE-PDFAdobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attemptoffdropdropdrop
352127POLICY-OTHERCisco Web Security Appliance system setup wizard access detectedoffoffoffoff
352128POLICY-OTHERCisco Web Security Appliance system setup wizard access detectedoffoffoffoff
352129SERVER-WEBAPPCisco Prime Infrastructure directory traversal attemptoffoffdropdrop
152130SERVER-WEBAPPApache Struts OGNL expression injection attemptoffdropdropdrop
352131SERVER-OTHERTRUFFLEHUNTER TALOS-2019-0948 attack attemptoffoffdropdrop
152132FILE-OTHERLibmspack cabd_sys_read_block off-by-one heap overflow attemptoffoffoffdrop
152133FILE-OTHERLibmspack cabd_sys_read_block off-by-one heap overflow attemptoffoffoffdrop
152134MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152135MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152136MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152137MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152138MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152139MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152140MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152141MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152142MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152143MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152144MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152145MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152146MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152147MALWARE-OTHERWin.Trojan.Agent variant download attemptoffdropdropdrop
152148MALWARE-CNCWin.Trojan.Agent variant outbound connection offdropdropdrop
152149MALWARE-CNCWin.Trojan.Agent variant outbound connectionoffdropdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
352126SERVER-WEBAPPCisco Wireless LAN Controller denial of service attemptoffoffdropdrop