Rule Update
20-035 (July 28, 2020)
Publish date: July 28, 2020
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
DCERPC Services - Client
1010394* - Microsoft Windows LNK Remote Code Execution Vulnerability Over SMB (CVE-2020-1421)
DNS Client
1010406* - Microsoft Windows DNS Server Remote Code Execution Vulnerability (CVE-2020-1350) - Client
DNS Server
1010293* - ISC BIND TSIG Denial-of-Service Vulnerability (CVE-2020-8617)
1010401* - Microsoft Windows DNS Server Remote Code Execution Vulnerability (CVE-2020-1350) - Server
Directory Server LDAP
1010321* - OpenLDAP slapd Nested Filter Stack Overflow Vulnerability (CVE-2020-12243)
MQTT Server
1010357* - Eclipse Mosquitto Improper Authentication Vulnerability (CVE-2017-7650)
Oracle E-Business Suite Web Interface
1010360* - Oracle E-Business Suite Advanced Outbound Telephony Cross Site Scripting Vulnerability (CVE-2020-2871)
1010367* - Oracle E-Business Suite Advanced Outbound Telephony Cross-Site Scripting Vulnerability (CVE-2020-2854)
1010383* - Oracle E-Business Suite Advanced Outbound Telephony Cross-Site Scripting Vulnerability (CVE-2020-2856)
SAP NetWeaver Java Application Server
1010409* - Identified SAP NetWeaver AS JAVA Authentication Attempt
1010417 - SAP NetWeaver AS JAVA Authentication Bypass Vulnerability (CVE-2020-6287)
1010413* - SAP NetWeaver AS JAVA Directory Traversal Vulnerability (CVE-2020-6286)
SSL Client
1010410 - OpenSSL Large DH Parameter Denial Of Service Vulnerability (CVE-2018-0732)
Web Application Common
1010377* - Centreon 'RRDdatabase_status_path' Command Injection Vulnerability (CVE-2020-13252)
1010345 - Kentico CMS Staging SyncServer Unserialize Remote Command Execution Vulnerability (CVE-2019-10068)
1010372* - Opmantek Open-AudIT Cross Site Scripting Vulnerability (CVE-2020-12261)
1010354* - Pandora FMS Ping Authenticated Remote Code Execution Vulnerability
1010423 - Primetek Primefaces Remote Code Execution Vulnerability (CVE-2017-1000486)
1010252* - Sonatype Nexus Repository Manager Stored Cross-Site Scripting Vulnerability (CVE-2020-10203)
Web Application PHP Based
1010359* - WordPress 'bbPress' Plugin Unauthenticated Privilege Escalation Vulnerability (CVE-2020-13693)
1010341* - Wordpress Drag and Drop Multi File Uploader Remote Code Execution Vulnerability (CVE-2020-12800)
Web Application Ruby Based
1010384* - Lodash Node Module Modification Of Assumed-Immutable Data (MAID) Vulnerability (CVE-2018-3721)
Web Client Common
1010261* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB20-24) - 1
1010420 - Microsoft .NET And Visual Studio Remote Code Execution Vulnerability (CVE-2020-1147)
1010424 - Microsoft Windows LNK Remote Code Execution Vulnerability Over HTTP (CVE-2020-1421)
1010395* - Microsoft Windows LNK Remote Code Execution Vulnerability Over WebDAV (CVE-2020-1421)
1010414 - Oracle Java Runtime Environment HTML Rendering Out-Of-Bounds Write Vulnerability (CVE-2020-14664)
1010419 - Oracle Java SE Ligature Substitution Glyph Storage Out Of Bounds Memory Access (CVE-2015-0469)
Web Server Common
1010374* - Cayin CMS NTP Server Remote Code Execution Vulnerability (CVE-2020-7357)
1010175* - Cross-Site Scripting (XSS) Decoder
1010388* - F5 BIG-IP TMUI Remote Code Execution Vulnerability (CVE-2020-5902)
1010418 - Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2020-1147)
1010376* - Opmantek Open-AudIT Command Injection Vulnerability (CVE-2020-11941)
1010362* - VMware Cloud Director Code Injection Vulnerability (CVE-2020-3956)
1010342* - Zoho ManageEngine OpManager Cachestart Directory Traversal Vulnerability (CVE-2020-13818)
1010387* - rConfig Network Device Configuration Tool SQL Injection Vulnerability (CVE-2020-10547)
1010386* - rConfig Network Device Configuration Tool SQL Injection Vulnerability (CVE-2020-10549)
1010378* - rConfig SQL Injection Vulnerability (CVE-2020-10546)
1010366* - vBulletin 'widgetConfig' Unauthenticated Remote Code Execution Vulnerability (CVE-2019-16759)
Web Server Oracle
1010415 - Oracle WebLogic Server T3 Protocol Insecure Deserialization Vulnerability (CVE-2020-14625)
Web Server SharePoint
1010398* - Microsoft SharePoint Scorecards Remote Code Execution Vulnerability (CVE-2020-1439)
Integrity Monitoring Rules:
1003020* - Trend Micro Deep Security Manager
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
DCERPC Services - Client
1010394* - Microsoft Windows LNK Remote Code Execution Vulnerability Over SMB (CVE-2020-1421)
DNS Client
1010406* - Microsoft Windows DNS Server Remote Code Execution Vulnerability (CVE-2020-1350) - Client
DNS Server
1010293* - ISC BIND TSIG Denial-of-Service Vulnerability (CVE-2020-8617)
1010401* - Microsoft Windows DNS Server Remote Code Execution Vulnerability (CVE-2020-1350) - Server
Directory Server LDAP
1010321* - OpenLDAP slapd Nested Filter Stack Overflow Vulnerability (CVE-2020-12243)
MQTT Server
1010357* - Eclipse Mosquitto Improper Authentication Vulnerability (CVE-2017-7650)
Oracle E-Business Suite Web Interface
1010360* - Oracle E-Business Suite Advanced Outbound Telephony Cross Site Scripting Vulnerability (CVE-2020-2871)
1010367* - Oracle E-Business Suite Advanced Outbound Telephony Cross-Site Scripting Vulnerability (CVE-2020-2854)
1010383* - Oracle E-Business Suite Advanced Outbound Telephony Cross-Site Scripting Vulnerability (CVE-2020-2856)
SAP NetWeaver Java Application Server
1010409* - Identified SAP NetWeaver AS JAVA Authentication Attempt
1010417 - SAP NetWeaver AS JAVA Authentication Bypass Vulnerability (CVE-2020-6287)
1010413* - SAP NetWeaver AS JAVA Directory Traversal Vulnerability (CVE-2020-6286)
SSL Client
1010410 - OpenSSL Large DH Parameter Denial Of Service Vulnerability (CVE-2018-0732)
Web Application Common
1010377* - Centreon 'RRDdatabase_status_path' Command Injection Vulnerability (CVE-2020-13252)
1010345 - Kentico CMS Staging SyncServer Unserialize Remote Command Execution Vulnerability (CVE-2019-10068)
1010372* - Opmantek Open-AudIT Cross Site Scripting Vulnerability (CVE-2020-12261)
1010354* - Pandora FMS Ping Authenticated Remote Code Execution Vulnerability
1010423 - Primetek Primefaces Remote Code Execution Vulnerability (CVE-2017-1000486)
1010252* - Sonatype Nexus Repository Manager Stored Cross-Site Scripting Vulnerability (CVE-2020-10203)
Web Application PHP Based
1010359* - WordPress 'bbPress' Plugin Unauthenticated Privilege Escalation Vulnerability (CVE-2020-13693)
1010341* - Wordpress Drag and Drop Multi File Uploader Remote Code Execution Vulnerability (CVE-2020-12800)
Web Application Ruby Based
1010384* - Lodash Node Module Modification Of Assumed-Immutable Data (MAID) Vulnerability (CVE-2018-3721)
Web Client Common
1010261* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB20-24) - 1
1010420 - Microsoft .NET And Visual Studio Remote Code Execution Vulnerability (CVE-2020-1147)
1010424 - Microsoft Windows LNK Remote Code Execution Vulnerability Over HTTP (CVE-2020-1421)
1010395* - Microsoft Windows LNK Remote Code Execution Vulnerability Over WebDAV (CVE-2020-1421)
1010414 - Oracle Java Runtime Environment HTML Rendering Out-Of-Bounds Write Vulnerability (CVE-2020-14664)
1010419 - Oracle Java SE Ligature Substitution Glyph Storage Out Of Bounds Memory Access (CVE-2015-0469)
Web Server Common
1010374* - Cayin CMS NTP Server Remote Code Execution Vulnerability (CVE-2020-7357)
1010175* - Cross-Site Scripting (XSS) Decoder
1010388* - F5 BIG-IP TMUI Remote Code Execution Vulnerability (CVE-2020-5902)
1010418 - Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2020-1147)
1010376* - Opmantek Open-AudIT Command Injection Vulnerability (CVE-2020-11941)
1010362* - VMware Cloud Director Code Injection Vulnerability (CVE-2020-3956)
1010342* - Zoho ManageEngine OpManager Cachestart Directory Traversal Vulnerability (CVE-2020-13818)
1010387* - rConfig Network Device Configuration Tool SQL Injection Vulnerability (CVE-2020-10547)
1010386* - rConfig Network Device Configuration Tool SQL Injection Vulnerability (CVE-2020-10549)
1010378* - rConfig SQL Injection Vulnerability (CVE-2020-10546)
1010366* - vBulletin 'widgetConfig' Unauthenticated Remote Code Execution Vulnerability (CVE-2019-16759)
Web Server Oracle
1010415 - Oracle WebLogic Server T3 Protocol Insecure Deserialization Vulnerability (CVE-2020-14625)
Web Server SharePoint
1010398* - Microsoft SharePoint Scorecards Remote Code Execution Vulnerability (CVE-2020-1439)
Integrity Monitoring Rules:
1003020* - Trend Micro Deep Security Manager
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Featured Stories
- Unveiling AI Agent Vulnerabilities Part V: Securing LLM ServicesTo conclude our series on agentic AI, this article examines emerging vulnerabilities that threaten AI agents, focusing on providing proactive security recommendations on areas such as code execution, data exfiltration, and database access.Read more
- Unveiling AI Agent Vulnerabilities Part IV: Database Access VulnerabilitiesHow can attackers exploit weaknesses in database-enabled AI agents? This research explores how SQL generation vulnerabilities, stored prompt injection, and vector store poisoning can be weaponized by attackers for fraudulent activities.Read more
- The Mirage of AI Programming: Hallucinations and Code IntegrityThe adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.Read more
- Open RAN: Attack of the xAppsThis article discusses two O-RAN vulnerabilities that attackers can exploit. One vulnerability stems from insufficient access control, and the other arises from faulty message handlingRead more