Rule Update
23-035 (August 15, 2023)
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Database PostgreSQL
1009865* - PostgreSQL Database Password Change Stack Buffer Overflow Vulnerability (CVE-2019-10164)
HP Intelligent Management Center (IMC)
1009951* - HPE Intelligent Management Center TopoMsgServlet 'className' Expression Language Injection Vulnerability (CVE-2019-11942)
HP Intelligent Management Center Dbman
1009959* - HPE Intelligent Management Center 'dbman' Opcode Denial Of Service Vulnerability (CVE-2018-7123)
1009637* - HPE Intelligent Management Center 'dbman' Stack Buffer Overflow Vulnerability (CVE-2018-7115)
MinIO Server
1011830 - MinIO Information Disclosure Vulnerability (CVE-2023-28432)
Splunk Enterprise
1011817 - Splunk 'Lookup File Editing' App Directory Traversal Vulnerability (CVE-2023-32714)
Telnet Server
1002414* - Telnet Server Possible Brute Force Attempt (ATT&CK T1110)
Web Application Common
1011790* - Open Web Analytics Remote Code Execution Vulnerability (CVE-2022-24637)
1011839 - Progress MOVEit Transfer SQL Injection Vulnerability (CVE-2023-36932) - 2
Web Server Common
1011787* - JetBrains TeamCity Cross-Site Scripting Vulnerability (CVE-2023-34229)
Web Server HTTPS
1011823 - Contec CONPROSYS HMI System Cross-Site Scripting Vulnerability (CVE-2023-28651)
Web Server Miscellaneous
1011778* - Jenkins 'Sidebar Link' Plugin Directory Traversal Vulnerability (CVE-2023-32985)
Webmin
1009948* - Webmin Remote Command Execution Vulnerability (CVE-2019-9624)
Windows Remote Management
1009894* - Powershell Remote Command Execution Via WinRM - HTTP (Request) (ATT&CK T1021.006, T1059.001)
Zoho ManageEngine ADAuditPlus
1011785* - Zoho ManageEngine ADAudit Plus Arbitrary File Write Vulnerability (CVE-2021-42847)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Database PostgreSQL
1009865* - PostgreSQL Database Password Change Stack Buffer Overflow Vulnerability (CVE-2019-10164)
HP Intelligent Management Center (IMC)
1009951* - HPE Intelligent Management Center TopoMsgServlet 'className' Expression Language Injection Vulnerability (CVE-2019-11942)
HP Intelligent Management Center Dbman
1009959* - HPE Intelligent Management Center 'dbman' Opcode Denial Of Service Vulnerability (CVE-2018-7123)
1009637* - HPE Intelligent Management Center 'dbman' Stack Buffer Overflow Vulnerability (CVE-2018-7115)
MinIO Server
1011830 - MinIO Information Disclosure Vulnerability (CVE-2023-28432)
Splunk Enterprise
1011817 - Splunk 'Lookup File Editing' App Directory Traversal Vulnerability (CVE-2023-32714)
Telnet Server
1002414* - Telnet Server Possible Brute Force Attempt (ATT&CK T1110)
Web Application Common
1011790* - Open Web Analytics Remote Code Execution Vulnerability (CVE-2022-24637)
1011839 - Progress MOVEit Transfer SQL Injection Vulnerability (CVE-2023-36932) - 2
Web Server Common
1011787* - JetBrains TeamCity Cross-Site Scripting Vulnerability (CVE-2023-34229)
Web Server HTTPS
1011823 - Contec CONPROSYS HMI System Cross-Site Scripting Vulnerability (CVE-2023-28651)
Web Server Miscellaneous
1011778* - Jenkins 'Sidebar Link' Plugin Directory Traversal Vulnerability (CVE-2023-32985)
Webmin
1009948* - Webmin Remote Command Execution Vulnerability (CVE-2019-9624)
Windows Remote Management
1009894* - Powershell Remote Command Execution Via WinRM - HTTP (Request) (ATT&CK T1021.006, T1059.001)
Zoho ManageEngine ADAuditPlus
1011785* - Zoho ManageEngine ADAudit Plus Arbitrary File Write Vulnerability (CVE-2021-42847)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.