Cisco Talos Update for FireSIGHT Management Center

Date: 2020-01-03

This SRU number: 2020-01-02-001
Previous SRU number: 2019-12-24-001

Applies to:

This SEU number: 2107
Previous SEU: 2106

Applies to:

This is the complete list of rules added in SRU 2020-01-02-001 and SEU 2107.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
152514SERVER-WEBAPPChimera Web Portal System cross site scripting attemptoffoffoffdrop
152515SERVER-WEBAPPChimera Web Portal System cross site scripting attemptoffoffoffdrop
152516INDICATOR-COMPROMISEWin.Trojan.ReverseTcpPowershell connection attemptoffoffdropdrop
152517INDICATOR-COMPROMISEWin.Trojan.ReverseTcpPowershell connection attemptoffoffdropdrop
152518MALWARE-TOOLSWin.Trojan.ReverseTcpPowershell download attemptoffdropdropdrop
152519MALWARE-TOOLSWin.Trojan.ReverseTcpPowershell download attemptoffdropdropdrop
152520BROWSER-IEMicrosoft Edge Chakra ProcessLinkFailedAsmJsModule type confusion attemptoffoffoffdrop
152521BROWSER-IEMicrosoft Edge Chakra ProcessLinkFailedAsmJsModule type confusion attemptoffoffoffdrop
152522BROWSER-IEMicrosoft Edge Chakra ProcessLinkFailedAsmJsModule type confusion attemptoffoffoffdrop
152523BROWSER-IEMicrosoft Edge Chakra ProcessLinkFailedAsmJsModule type confusion attemptoffoffoffdrop
352525SERVER-WEBAPPCisco Data Center Network Manager XML external entity injection attemptoffoffdropdrop
352526SERVER-WEBAPPCisco Data Center Network Manager XML external entity injection attemptoffoffdropdrop
352527SERVER-WEBAPPCisco Data Center Network Manager XML external entity injection attemptoffoffdropdrop
352528SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352529SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352530SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352531SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352532SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352533SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352534SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352535SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352536SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352537SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352538SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352539SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352540SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352541SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352542SERVER-WEBAPPCisco Data Center Network Manager displayServerInfos information disclosure attemptoffoffdropdrop
352543SERVER-WEBAPPCisco Data Center Network Manager SQL injection attemptoffoffdropdrop
352544SERVER-WEBAPPCisco Data Center Network Manager SQL injection attemptoffoffdropdrop
352545SERVER-WEBAPPCisco Data Center Network Manager directory traversal attemptoffoffdropdrop
352546SERVER-WEBAPPCisco Data Center Network Manager LanFabricImpl createLanFabric command injection attemptoffoffdropdrop
352547SERVER-WEBAPPCisco Data Center Network Manager SanWS importTS arbitrary file upload attemptoffoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
152524PROTOCOL-DNSdnsmasq crafted OPT record denial of service attemptoffoffoffdrop