Cisco Talos Update for FireSIGHT Management Center

Date: 2019-12-19

This SRU number: 2019-12-18-001
Previous SRU number: 2019-12-17-001

Applies to:

This SEU number: 2104
Previous SEU: 2103

Applies to:

This is the complete list of rules modified in SRU 2019-12-18-001 and SEU 2104.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
137328DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137330DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137333DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137334DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137335DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137336DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137337DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137338DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137339DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137340DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137341DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
137342DELETEDFILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attemptoffoffoffoff
150276MALWARE-BACKDOORWin.Backdoor.Chopper webshell inbound request attemptoffdropdropdrop
150277MALWARE-BACKDOORWin.Backdoor.Chopper webshell inbound request attemptoffdropdropdrop
150860SERVER-WEBAPPPalo Alto GlobalProtect SSL VPN buffer overflow attemptoffoffdropdrop
152449POLICY-OTHERPotential phishing domain ddns.net outbound connection detectedoffoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
120341PROTOCOL-VOIPTo header unquoted tokens in field attemptoffoffoffdrop
139946PROTOCOL-DNSPowerDNS TKEY query denial of service attemptoffoffdropdrop
139947PROTOCOL-DNSPowerDNS TKEY query denial of service attemptoffoffdropdrop
139948PROTOCOL-DNSPowerDNS TCP TKEY query denial of service attemptoffoffdropdrop
139949PROTOCOL-DNSPowerDNS TCP TKEY query denial of service attemptoffoffdropdrop
139950PROTOCOL-DNSPowerDNS TCP TSIG query denial of service attemptoffoffdropdrop
139951PROTOCOL-DNSPowerDNS TCP TSIG query denial of service attemptoffoffdropdrop
139952PROTOCOL-DNSPowerDNS TSIG query denial of service attemptoffoffdropdrop
139953PROTOCOL-DNSPowerDNS TSIG query denial of service attemptoffoffdropdrop
147881PROTOCOL-DNSdnsmasq add_pseudoheader memory leak attemptoffoffdropdrop