Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-03-07

This SRU number: 2017-03-07-001
Previous SRU number: 2017-03-06-001

Applies to:

This SEU number: 1625
Previous SEU: 1624

Applies to:

This is the complete list of rules added in SRU 2017-03-07-001 and SEU 1625.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
141817SERVER-WEBAPPgeneric SQL select statement possible sql injectionoffoffdrop
141818SERVER-APACHEApache Struts remote code execution attemptoffdropdrop
141819SERVER-APACHEApache Struts remote code execution attemptoffdropdrop
141820SERVER-WEBAPPBorland AccuRev Reprise License Server diagnostics_doit outputfile parameter directory traversal attemptoffoffoff
141821SERVER-WEBAPPBorland AccuRev Reprise License Server diagnostics_doit outputfile parameter directory traversal attemptoffoffoff
141822SERVER-WEBAPPBorland AccuRev Reprise License Server diagnostics_doit outputfile parameter directory traversal attemptoffoffoff
141823SERVER-OTHERNagios Core privilege escalation attemptoffoffoff
141824SERVER-OTHERNagios Core privilege escalation attemptoffoffoff
141825SERVER-WEBAPPWordPress Plugins Simple Ads Manager information disclosure attemptoffoffoff
141826SERVER-WEBAPPWordPress Plugins Simple Ads Manager information disclosure attemptoffoffoff
141827BROWSER-PLUGINSWebGate eDVR Manager WESPPlayback access attemptoffoffoff
141828BROWSER-PLUGINSWebGate eDVR Manager WESPPlayback access attemptoffoffoff
141829BROWSER-PLUGINSWebGate eDVR Manager WESPPlayback access attemptoffoffoff
141830BROWSER-PLUGINSWebGate eDVR Manager WESPPlayback access attemptoffoffoff
141831BROWSER-PLUGINSWebGate eDVR Manager WESPPTZ access attemptoffoffoff
141832BROWSER-PLUGINSWebGate eDVR Manager WESPPTZ access attemptoffoffoff
141833BROWSER-PLUGINSWebGate eDVR Manager WESPPTZ access attemptoffoffoff
141834BROWSER-PLUGINSWebGate eDVR Manager WESPPTZ access attemptoffoffoff
141835BROWSER-PLUGINSWebGate eDVR Manager WESPEvent access attemptoffoffoff
141836BROWSER-PLUGINSWebGate eDVR Manager WESPEvent access attemptoffoffoff
141837BROWSER-PLUGINSWebGate eDVR Manager WESPEvent access attemptoffoffoff
141838BROWSER-PLUGINSWebGate eDVR Manager WESPEvent access attemptoffoffoff

Updated Rules:

Updated rules can be found at this link.