Cisco Talos Update for FireSIGHT Management Center

Date: 2020-07-16

This SRU number: 2020-07-15-001
Previous SRU number: 2020-07-13-001

Applies to:

This SEU number: 2186
Previous SEU: 2185

Applies to:

This is the complete list of rules added in SRU 2020-07-15-001 and SEU 2186.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
154536MALWARE-OTHERWin.Malware.Netwire-8821558-0 download attemptoffoffoffdrop
154537MALWARE-OTHERWin.Malware.Netwire-8821558-0 download attemptoffoffoffdrop
354538SERVER-WEBAPPCisco RV Series Routers command injection attemptoffoffdropdrop
354539SERVER-WEBAPPCisco RV Series Routers command injection attemptoffoffdropdrop
354540SERVER-WEBAPPCisco RV Series Routers command injection attemptoffoffdropdrop
354541SERVER-WEBAPPCisco RV Series Routers command injection attemptoffoffdropdrop
354542SERVER-WEBAPPCisco RV Series Routers heap buffer overflow attemptoffoffdropdrop
354543SERVER-WEBAPPCisco RV Series Routers heap buffer overflow attemptoffoffdropdrop
354544POLICY-OTHERCisco RV110W Router default credential login detectedoffoffoffoff
354545SERVER-WEBAPPCisco SD-WAN vManage arbitrary Java object deserialization attemptoffoffdropdrop
354546SERVER-WEBAPPCisco SD-WAN vManage cypher query language injection attemptoffoffdropdrop
354547SERVER-WEBAPPCisco SD-WAN vManage cypher query language injection attemptoffoffdropdrop
354548SERVER-WEBAPPCisco RV Series Routers stack buffer overflow attemptoffoffdropdrop
354549SERVER-WEBAPPCisco RV Series Routers stack buffer overflow attemptoffoffdropdrop
354550SERVER-WEBAPPCisco RV Series Routers stack buffer overflow attemptoffoffdropdrop
354551SERVER-WEBAPPCisco RV Series Routers stack buffer overflow attemptoffoffdropdrop
354553POLICY-OTHERCisco SD-WAN vManage file upload detectedoffoffoffoff
154554MALWARE-CNCWin.Trojan.Ursnif variant payload download attemptoffoffdropdrop
154555MALWARE-CNCWin.Trojan.Ursnif variant payload download attemptoffoffdropdrop
354557SERVER-WEBAPPCisco RV Series Routers authentication bypass attemptoffoffdropdrop
154558SERVER-WEBAPPPark Ticketing Management System SQL injection attemptoffdropdropdrop
154559SERVER-WEBAPPPark Ticketing Management System SQL injection attemptoffdropdropdrop
354560SERVER-WEBAPPCisco RV Series Routers stack buffer overflow attemptoffoffdropdrop
354561SERVER-WEBAPPCisco RV Series Routers stack buffer overflow attemptoffoffdropdrop
354562SERVER-WEBAPPCisco RV Series Routers stack buffer overflow attemptoffoffdropdrop
354563SERVER-WEBAPPCisco RV Series Routers stack buffer overflow attemptoffoffdropdrop
354564POLICY-OTHERCisco RV Series Routers configuration download detectedoffoffoffoff
154565SERVER-WEBAPPPark Ticketing Management System SQL injection attemptoffdropdropdrop
154566SERVER-WEBAPPPark Ticketing Management System SQL injection attemptoffdropdropdrop
154567SERVER-WEBAPPPark Ticketing Management System SQL injection attemptoffdropdropdrop
354568POLICY-OTHERCisco Prime License Manager password reset detectedoffoffoffoff
154569SERVER-WEBAPPBarangay Management System SQL injection attemptoffdropdropdrop
154570SERVER-WEBAPPBarangay Management System SQL injection attemptoffdropdropdrop
154571SERVER-WEBAPPSAP NetWeaver AS LM Configuration Wizard directory traversal attemptoffdropdropdrop
154572SERVER-WEBAPPSAP NetWeaver AS LM Configuration Wizard directory traversal attemptoffdropdropdrop
154573POLICY-OTHERSAP NetWeaver AS LM Configuration Wizard access detectedoffoffdropdrop
154574POLICY-OTHERSAP NetWeaver AS LM Configuration Wizard access detectedoffoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
354552SERVER-WEBAPPCisco RV Series Routers null pointer dereference attemptoffoffdropdrop
154556SERVER-WEBAPPBSA Radar local file inclusion attemptoffdropdropdrop