Rule Update

23-049 (November 7, 2023)


  DESCRIPTION

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Ivanti Avalanche Remote Control Server
1011864* - Ivanti Avalanche Directory Traversal Vulnerability (CVE-2023-32563)


Mail Server Exim
1011874* - Exim Remote Code Execution Vulnerability (CVE-2023-42117)


Parse Server
1011868* - Parse Server Remote Code Execution Vulnerability (CVE-2023-36475)


SolarWinds Access Rights Manager
1011890 - SolarWinds Access Rights Manager Directory Traversal Vulnerability (CVE-2023-35185)
1011891 - SolarWinds Access Rights Manager Directory Traversal Vulnerability (CVE-2023-35187)


Web Server Common
1011887 - Control Web Panel Command Injection Remote Code Execution Vulnerability (CVE-2023-42123)


Web Server HTTPS
1011888 - Cacti SQL Injection Vulnerability (CVE-2023-39365)
1011889 - SolarWinds Access Rights Manager Insecure Deserialization Vulnerability (CVE-2023-35186)


Web Server Miscellaneous
1011858* - XWiki Code Injection Vulnerability (CVE-2023-35166)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.