Rule Update
23-022 (May 23, 2023)
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
DNS Client
1011748 - Identified Cobalt Strike DNS Beacon Runtime Detection - 1
1011753 - Identified Cobalt Strike DNS Beacon Runtime Detection - 2
Web Application PHP Based
1011736 - OpenCATS Cross-Site Scripting Vulnerability (CVE-2023-27293)
1011747 - WordPress 'Metform Elementor Contact Form Builder' Plugin Cross-Site Scripting Vulnerability (CVE-2023-0084)
Web Client Common
1011080* - Microsoft Multiple Products Remote Code Execution Vulnerability (CVE-2021-43209 and CVE-2022-44692)
Web Server Apache
1011750 - Apache HTTP Server Request Smuggling Vulnerability (CVE-2023-25690)
Web Server Miscellaneous
1011757 - XWiki Code Injection Vulnerability (CVE-2023-29516)
Web Server SharePoint
1011730 - Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2022-29108)
Zoho ManageEngine ServiceDesk Plus_MSP
1011745 - Zoho ManageEngine ServiceDesk Plus Cross Site Scripting Vulnerability (CVE-2023-23077)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
DNS Client
1011748 - Identified Cobalt Strike DNS Beacon Runtime Detection - 1
1011753 - Identified Cobalt Strike DNS Beacon Runtime Detection - 2
Web Application PHP Based
1011736 - OpenCATS Cross-Site Scripting Vulnerability (CVE-2023-27293)
1011747 - WordPress 'Metform Elementor Contact Form Builder' Plugin Cross-Site Scripting Vulnerability (CVE-2023-0084)
Web Client Common
1011080* - Microsoft Multiple Products Remote Code Execution Vulnerability (CVE-2021-43209 and CVE-2022-44692)
Web Server Apache
1011750 - Apache HTTP Server Request Smuggling Vulnerability (CVE-2023-25690)
Web Server Miscellaneous
1011757 - XWiki Code Injection Vulnerability (CVE-2023-29516)
Web Server SharePoint
1011730 - Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2022-29108)
Zoho ManageEngine ServiceDesk Plus_MSP
1011745 - Zoho ManageEngine ServiceDesk Plus Cross Site Scripting Vulnerability (CVE-2023-23077)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.