Rule Update

23-011 (March 14, 2023)


* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DNS Client
1010740* - DNSmasq DNSSEC Heap Based Buffer Overflow Vulnerability (CVE-2020-25681)

Intel Data Center Manager
1011672* - Intel Data Center Manager SQL Injection Vulnerability (CVE-2022-21225)

Mail Server Common
1011691 - Identified Email with Attachment or a Link

Microsoft Office
1011701 - Microsoft Word Remote Code Execution Vulnerability (CVE-2023-21716)

1011696 - OpenTSDB Command Injection Vulnerability (CVE-2020-35476)

Redis Server
1011681* - Redis Integer Overflow Vulnerability (CVE-2022-35977)

SAP NetWeaver Java Application Server
1011664* - SAP NetWeaver Unrestricted File Upload Vulnerability (CVE-2021-38163)

Suspicious Client Application Activity
1011693 - Identified File Upload Activity Over HTTP

Web Application PHP Based
1011697 - WordPress 'Zephyr Project Manager' Plugin SQL Injection Vulnerability (CVE-2022-2840)

Web Application Ruby Based
1011289* - Grafana Directory Traversal Vulnerability (CVE-2021-43813)

Web Server Common
1011331* - Apache APISIX 'batch-requests' Plugin Remote Code Execution Vulnerability (CVE-2022-24112)

Web Server HTTPS
1011699 - GitLab Remote Code Execution Vulnerability (CVE-2022-2884)
1011684 - GitLab Remote Code Execution Vulnerability (CVE-2022-2992)

Web Server Miscellaneous
1011568* - Vm2 Sandbox Remote Code Execution Vulnerability (CVE-2022-36067)
1011661* - XWiki Code Injection Vulnerability (CVE-2022-36098)

Windows SMB Server
1011671 - Identified Possible Ransomware File Extension Rename Activity Over Network Share - 1
1011680* - Microsoft Windows NEGOEX Remote Code Execution Vulnerability (CVE-2022-37958)

Zoho ManageEngine
1011662* - Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability (CVE-2022-47966)
1011674* - Zoho ManageEngine Multiple Products SQL Injection Vulnerability (CVE-2022-43672)

Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.

Log Inspection Rules:

1003802* - Directory Server - Microsoft Windows Active Directory