This SRU number: 2019-02-28-001
Previous SRU number: 2019-02-26-001
Applies to:
This SEU number: 1981
Previous SEU: 1979
Applies to:
This is the complete list of rules added in SRU 2019-02-28-001 and SEU 1981.
The format of the file is:
GID - SID - Rule Group - Rule Message - Policy State
The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.
The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.
Note: Unless stated explicitly, the rules are for the series of products listed above.
GID | SID | Rule Group | Rule Message | Policy State | |||
---|---|---|---|---|---|---|---|
Con. | Bal. | Sec. | Max. | ||||
3 | 49293 | NETBIOS | Cisco WebEx WebExService.exe remote code execution attempt | off | drop | drop | drop |
1 | 49294 | FILE-PDF | Adobe Acrobat out of bounds read attempt | off | drop | drop | drop |
1 | 49295 | FILE-PDF | Adobe Acrobat out of bounds read attempt | off | drop | drop | drop |
3 | 49296 | SERVER-WEBAPP | Cisco RV Series Routers stack buffer overflow attempt | off | off | drop | drop |
1 | 49297 | FILE-OTHER | IBM Lotus Notes LZH Attachment Viewer buffer overflow attempt | off | off | off | off |
1 | 49298 | SERVER-WEBAPP | NoneCms V1.3 PHP code execution attempt | off | off | drop | drop |
1 | 49299 | FILE-OFFICE | Microsoft Access arbitrary code execution attempt | off | off | off | off |
1 | 49300 | FILE-OFFICE | Microsoft Access arbitrary code execution attempt | off | off | off | off |
1 | 49301 | SERVER-WEBAPP | Trend Micro Smart Protection Server SQL injection attempt | off | off | drop | drop |
1 | 49302 | SERVER-WEBAPP | Trend Micro Smart Protection Server SQL injection attempt | off | off | drop | drop |
1 | 49303 | SERVER-WEBAPP | Trend Micro Smart Protection Server SQL injection attempt | off | off | drop | drop |
1 | 49304 | SERVER-OTHER | Google Golang GET command injection attempt | off | off | drop | drop |
1 | 49305 | FILE-PDF | Adobe Acrobat Reader PostScript file out of bounds read attempt | off | drop | drop | drop |
1 | 49306 | FILE-PDF | Adobe Acrobat Reader PostScript file out of bounds read attempt | off | drop | drop | drop |
1 | 49307 | FILE-PDF | Adobe Acrobat malformed PDF out of bounds read attempt | off | drop | drop | drop |
1 | 49308 | FILE-PDF | Adobe Acrobat malformed PDF out of bounds read attempt | off | drop | drop | drop |
1 | 49309 | FILE-PDF | Adobe Acrobat malformed PDF objects use after free attempt | off | drop | drop | drop |
1 | 49310 | FILE-PDF | Adobe Acrobat malformed PDF objects use after free attempt | off | drop | drop | drop |
1 | 49311 | FILE-FLASH | Adobe Flash Player writeExternal type confusion attempt | off | drop | drop | drop |
1 | 49312 | FILE-FLASH | Adobe Flash Player writeExternal type confusion attempt | off | drop | drop | drop |
1 | 49313 | FILE-PDF | Adobe Acrobat XFA JavaScript manipulation out of bounds read attempt | off | drop | drop | drop |
1 | 49314 | FILE-PDF | Adobe Acrobat XFA JavaScript manipulation out of bounds read attempt | off | drop | drop | drop |
1 | 49315 | FILE-PDF | Adobe Acrobat out of bounds read attempt | off | drop | drop | drop |
1 | 49316 | FILE-PDF | Adobe Acrobat out of bounds read attempt | off | drop | drop | drop |
1 | 49317 | FILE-PDF | Adobe Acrobat out of bounds read attempt | off | drop | drop | drop |
1 | 49318 | FILE-PDF | Adobe Acrobat out of bounds read attempt | off | drop | drop | drop |
1 | 49319 | SERVER-WEBAPP | CentOS Web Panel persistent cross site scripting attempt | off | off | off | off |
1 | 49320 | SERVER-WEBAPP | CentOS Web Panel persistent cross site scripting attempt | off | off | off | off |
1 | 49321 | SERVER-WEBAPP | CentOS Web Panel persistent cross site scripting attempt | off | off | off | off |
1 | 49322 | SERVER-WEBAPP | CentOS Web Panel persistent cross site scripting attempt | off | off | off | off |
1 | 49323 | FILE-OFFICE | Microsoft Office Excel Lel record memory corruption attempt | off | off | off | off |
1 | 49324 | FILE-OFFICE | Microsoft Office Excel Lel record memory corruption attempt | off | off | off | off |
1 | 49325 | FILE-OTHER | Microsoft Windows Avast Anti-Virus local credentials disclosure attempt | off | off | off | off |
Updated rules can be found at this link.