Rule Update

23-011 (March 14, 2023)


  DESCRIPTION

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DNS Client
1010740* - DNSmasq DNSSEC Heap Based Buffer Overflow Vulnerability (CVE-2020-25681)


Intel Data Center Manager
1011672* - Intel Data Center Manager SQL Injection Vulnerability (CVE-2022-21225)


Mail Server Common
1011691 - Identified Email with Attachment or a Link


Microsoft Office
1011701 - Microsoft Word Remote Code Execution Vulnerability (CVE-2023-21716)


OpenTSDB
1011696 - OpenTSDB Command Injection Vulnerability (CVE-2020-35476)


Redis Server
1011681* - Redis Integer Overflow Vulnerability (CVE-2022-35977)


SAP NetWeaver Java Application Server
1011664* - SAP NetWeaver Unrestricted File Upload Vulnerability (CVE-2021-38163)


Suspicious Client Application Activity
1011693 - Identified File Upload Activity Over HTTP


Web Application PHP Based
1011697 - WordPress 'Zephyr Project Manager' Plugin SQL Injection Vulnerability (CVE-2022-2840)


Web Application Ruby Based
1011289* - Grafana Directory Traversal Vulnerability (CVE-2021-43813)


Web Server Common
1011331* - Apache APISIX 'batch-requests' Plugin Remote Code Execution Vulnerability (CVE-2022-24112)


Web Server HTTPS
1011699 - GitLab Remote Code Execution Vulnerability (CVE-2022-2884)
1011684 - GitLab Remote Code Execution Vulnerability (CVE-2022-2992)


Web Server Miscellaneous
1011568* - Vm2 Sandbox Remote Code Execution Vulnerability (CVE-2022-36067)
1011661* - XWiki Code Injection Vulnerability (CVE-2022-36098)


Windows SMB Server
1011671 - Identified Possible Ransomware File Extension Rename Activity Over Network Share - 1
1011680* - Microsoft Windows NEGOEX Remote Code Execution Vulnerability (CVE-2022-37958)


Zoho ManageEngine
1011662* - Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability (CVE-2022-47966)
1011674* - Zoho ManageEngine Multiple Products SQL Injection Vulnerability (CVE-2022-43672)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

1003802* - Directory Server - Microsoft Windows Active Directory