Cisco Talos Update for FireSIGHT Management Center

Date: 2019-03-28

This SRU number: 2019-03-27-001
Previous SRU number: 2019-03-25-001

Applies to:

This SEU number: 1993
Previous SEU: 1992

Applies to:

This is the complete list of rules added in SRU 2019-03-27-001 and SEU 1993.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
149573FILE-MULTIMEDIARealNetworks RealPlayer mpeg width integer memory underflow attemptoffoffoffoff
149574FILE-MULTIMEDIARealNetworks RealPlayer mpeg width integer memory underflow attemptoffoffoffoff
149575FILE-IMAGESketchUp BMP RLE8 parsing buffer overflow attemptoffoffoffoff
149576FILE-IMAGESketchUp BMP RLE8 parsing buffer overflow attemptoffoffoffoff
149577SERVER-WEBAPPElectronJS Exodus remote code execution attemptoffoffoffdrop
149578SERVER-WEBAPPElectronJS Exodus remote code execution attemptoffoffoffdrop
149579SERVER-WEBAPPElectronJS Exodus remote code execution attemptoffoffoffdrop
149580SERVER-WEBAPPElectronJS Exodus remote code execution attemptoffoffoffdrop
149581SERVER-WEBAPPElectronJS Exodus remote code execution attemptoffoffoffdrop
149582SERVER-WEBAPPElectronJS Exodus remote code execution attemptoffoffoffdrop
149583FILE-FLASHAdobe Flash Player byteArray inflate information disclosure attemptoffoffoffoff
149584FILE-FLASHAdobe Flash Player byteArray inflate information disclosure attemptoffoffoffoff
149585FILE-FLASHAdobe Flash Player byteArray uncompress information disclosure attemptoffoffoffoff
149586FILE-FLASHAdobe Flash Player byteArray uncompress information disclosure attemptoffoffoffoff
149587SERVER-WEBAPPCMSsite 1.0 SQL injection attemptoffoffdropdrop
349588SERVER-WEBAPPCisco IOS XE webui debugBundle command injection attemptoffoffdropdrop
349589SERVER-WEBAPPCisco IOS XE webui debugBundle command injection attemptoffoffdropdrop
349590SERVER-WEBAPPCisco IOS XE webui debugBundle command injection attemptoffoffdropdrop
349591SERVER-WEBAPPCisco IOS XE webui directory traversal attemptoffoffdropdrop
149592MALWARE-CNCWin.Trojan.SectorA05 outbound connection attemptoffdropdropdrop
149593MALWARE-CNCWin.Trojan.SectorA05 outbound connection attemptoffdropdropdrop
149594MALWARE-CNCWin.Trojan.SectorA05 outbound connection attemptoffdropdropdrop
149595MALWARE-CNCWin.Trojan.SectorA05 outbound connection attemptoffdropdropdrop
149596MALWARE-CNCWin.Trojan.GlobeImposter malicious executable download attemptoffdropdropdrop
149597MALWARE-CNCWin.Trojan.GlobeImposter malicious executable download attemptoffdropdropdrop
149598SERVER-WEBAPPFiberhome AN5506-04-F RP2669 cross site scripting attemptoffoffdropdrop
149599FILE-PDFAdobe Acrobat Reader untrusted pointer dereference attempt detectedoffdropdropdrop
149600FILE-PDFAdobe Acrobat Reader untrusted pointer dereference attempt detectedoffdropdropdrop
149601SERVER-OTHERCentury Star SCADA directory traversal attemptoffoffoffoff
149602SERVER-OTHERCentury Star SCADA directory traversal attemptoffoffoffoff
149603SERVER-WEBAPPTrend Micro Control Manager SQL injection attemptoffoffdropdrop
149604SERVER-WEBAPPTrend Micro Control Manager SQL injection attemptoffoffdropdrop
149605SERVER-WEBAPPTrend Micro Control Manager SQL injection attemptoffoffdropdrop
349608SERVER-WEBAPPCisco IOS XE webui execPython access attemptoffoffdropdrop
349609SERVER-WEBAPPCisco IOS XE webui cdp resource command injection attemptoffoffdropdrop
349610SERVER-WEBAPPCisco IOS XE webui dhcp resource command injection attemptoffoffdropdrop
349612POLICY-OTHERCisco Virtual Switching System standby interested message detectedoffoffoffoff
349613POLICY-OTHERCisco Virtual Switching System master request message detectedoffoffoffoff
349614SERVER-WEBAPPCisco IOS XE webui rathrottler command injection attemptoffdropdropdrop
349615SERVER-WEBAPPCisco IOS XE webui rathrottler command injection attemptoffdropdropdrop
349616SERVER-WEBAPPCisco IOS XE webui rathrottler command injection attemptoffdropdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
349606PROTOCOL-VOIPCisco IOS SIP calling display name denial of service attemptoffoffoffoff
349607PROTOCOL-VOIPCisco IOS SIP calling display name denial of service attemptoffoffoffoff
349611SERVER-WEBAPPCisco IOS XE webui information disclosure attemptoffoffdropdrop

Updated Rules:

Updated rules can be found at this link.