Rule Update
DPIルール他更新情報:19-051(2019年10月15日)
2019年10月15日
概要
* は既存ルールの新バージョンを示します。
DPI(Deep Packet Inspection) ルール:
HP Intelligent Management Center (IMC)
1009947* - HPE Intelligent Management Center Various Expression Language Injection Vulnerabilities
Redisサーバ
1009967 - Redis Unauthenticated Code Execution Vulnerability
SSLクライアント
1010014 - Hola VPN Certificate Exchange Detected
SolarWinds Dameware Mini Remote Control
1009999 - SolarWinds DameWare Mini Remote Control CltDHPubKeyLen Out Of Bounds Read Vulnerability (CVE-2019-3956)
1010005 - SolarWinds DameWare Mini Remote Control RsaSignatureLen Out Of Bounds Read Vulnerability (CVE-2019-3957)
Webアプリケーション 共通
1009531* - Jenkins CI Server Groovy Plugin Sandbox Bypass Multiple Vulnerabilities
Webクライアント 共通
1010007 - LibreOffice Macro Python Code Execution Vulnerability (CVE-2019-9851)
1009987* - Microsoft Jet Database Engine Remote Code Execution Vulnerability (CVE-2019-1249)
1010024 - Microsoft Windows Jet Database Engine Remote Code Execution Vulnerability (CVE-2019-1250)
Webサーバ NAI ePolicy Orchestrator
1002360* - McAfee ePolicy Orchestrator Framework Services HTTP Buffer Overflow
変更監視(Integrity Monitoring)ルール:
1002781* - Microsoft Windows - Attributes of a service modified (ATT&CK T1050, T1036, T1031)
セキュリティログ監視(Log Inspection)ルール:
1008670* - Microsoft Windows Security Events - 3
1009771 - Microsoft Windows Sysmon Events - 1
1009777 - Microsoft Windows Sysmon Events - 2
DPI(Deep Packet Inspection) ルール:
HP Intelligent Management Center (IMC)
1009947* - HPE Intelligent Management Center Various Expression Language Injection Vulnerabilities
Redisサーバ
1009967 - Redis Unauthenticated Code Execution Vulnerability
SSLクライアント
1010014 - Hola VPN Certificate Exchange Detected
SolarWinds Dameware Mini Remote Control
1009999 - SolarWinds DameWare Mini Remote Control CltDHPubKeyLen Out Of Bounds Read Vulnerability (CVE-2019-3956)
1010005 - SolarWinds DameWare Mini Remote Control RsaSignatureLen Out Of Bounds Read Vulnerability (CVE-2019-3957)
Webアプリケーション 共通
1009531* - Jenkins CI Server Groovy Plugin Sandbox Bypass Multiple Vulnerabilities
Webクライアント 共通
1010007 - LibreOffice Macro Python Code Execution Vulnerability (CVE-2019-9851)
1009987* - Microsoft Jet Database Engine Remote Code Execution Vulnerability (CVE-2019-1249)
1010024 - Microsoft Windows Jet Database Engine Remote Code Execution Vulnerability (CVE-2019-1250)
Webサーバ NAI ePolicy Orchestrator
1002360* - McAfee ePolicy Orchestrator Framework Services HTTP Buffer Overflow
変更監視(Integrity Monitoring)ルール:
1002781* - Microsoft Windows - Attributes of a service modified (ATT&CK T1050, T1036, T1031)
セキュリティログ監視(Log Inspection)ルール:
1008670* - Microsoft Windows Security Events - 3
1009771 - Microsoft Windows Sysmon Events - 1
1009777 - Microsoft Windows Sysmon Events - 2