Rule Update
23-049 (07 November 2023)
Publish Date: 07 November 2023
Beschreibung
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Ivanti Avalanche Remote Control Server
1011864* - Ivanti Avalanche Directory Traversal Vulnerability (CVE-2023-32563)
Mail Server Exim
1011874* - Exim Remote Code Execution Vulnerability (CVE-2023-42117)
Parse Server
1011868* - Parse Server Remote Code Execution Vulnerability (CVE-2023-36475)
SolarWinds Access Rights Manager
1011890 - SolarWinds Access Rights Manager Directory Traversal Vulnerability (CVE-2023-35185)
1011891 - SolarWinds Access Rights Manager Directory Traversal Vulnerability (CVE-2023-35187)
Web Server Common
1011887 - Control Web Panel Command Injection Remote Code Execution Vulnerability (CVE-2023-42123)
Web Server HTTPS
1011888 - Cacti SQL Injection Vulnerability (CVE-2023-39365)
1011889 - SolarWinds Access Rights Manager Insecure Deserialization Vulnerability (CVE-2023-35186)
Web Server Miscellaneous
1011858* - XWiki Code Injection Vulnerability (CVE-2023-35166)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Ivanti Avalanche Remote Control Server
1011864* - Ivanti Avalanche Directory Traversal Vulnerability (CVE-2023-32563)
Mail Server Exim
1011874* - Exim Remote Code Execution Vulnerability (CVE-2023-42117)
Parse Server
1011868* - Parse Server Remote Code Execution Vulnerability (CVE-2023-36475)
SolarWinds Access Rights Manager
1011890 - SolarWinds Access Rights Manager Directory Traversal Vulnerability (CVE-2023-35185)
1011891 - SolarWinds Access Rights Manager Directory Traversal Vulnerability (CVE-2023-35187)
Web Server Common
1011887 - Control Web Panel Command Injection Remote Code Execution Vulnerability (CVE-2023-42123)
Web Server HTTPS
1011888 - Cacti SQL Injection Vulnerability (CVE-2023-39365)
1011889 - SolarWinds Access Rights Manager Insecure Deserialization Vulnerability (CVE-2023-35186)
Web Server Miscellaneous
1011858* - XWiki Code Injection Vulnerability (CVE-2023-35166)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.