Cisco Talos Update for FireSIGHT Management Center

Date: 2018-06-21

This SRU number: 2018-06-20-001
Previous SRU number: 2018-06-18-001

Applies to:

This SEU number: 1866
Previous SEU: 1865

Applies to:

This is the complete list of rules added in SRU 2018-06-20-001 and SEU 1866.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
146990OS-OTHERApple macOS and iOS fgetattrlist kernel heap overflow attemptoffoffdropdrop
146991OS-OTHERApple macOS and iOS fgetattrlist kernel heap overflow attemptoffoffdropdrop
346992SERVER-WEBAPPCisco NX-OS NX-API privilege escalation attemptoffdropdropdrop
346995SERVER-OTHERCisco NX-OS Fabric Services Protocol heap buffer overflow attemptoffoffdropdrop
346996SERVER-OTHERCisco NX-OS Fabric Services Protocol heap buffer overflow attemptoffoffdropdrop
146997SERVER-WEBAPPXiongMai NVR login.htm buffer overflow attemptoffoffdropdrop
146998MALWARE-CNCWin.Trojan.MnuBot variant outbound SQL connectionoffdropdropdrop
146999INDICATOR-COMPROMISESettingContent-ms file type download attemptoffoffoffoff
147000INDICATOR-COMPROMISESettingContent-ms file type download attemptoffoffoffoff
147001INDICATOR-COMPROMISESettingContent-ms file type download attemptoffdropdropdrop
147002INDICATOR-COMPROMISESettingContent-ms file type download attemptoffoffoffoff
347003SERVER-OTHERCisco NX-OS Fabric Services Protocol stack buffer overflow attemptoffoffdropdrop
347004SERVER-OTHERCisco NX-OS Fabric Services Protocol stack buffer overflow attemptoffoffdropdrop
147005MALWARE-CNCWin.Trojan.SocketPlayer outbound connectionoffdropdropdrop
147006MALWARE-CNCWin.Trojan.SocketPlayer outbound connectionoffdropdropdrop
147007SERVER-WEBAPPSpring Web Flow arbitrary code exeuction attemptoffoffoffoff
347008SERVER-WEBAPPCisco NX-OS NX-API ins_api command injection attemptoffoffdropdrop
347009SERVER-WEBAPPCisco NX-OS NX-API cli_ascii command injection attemptoffoffdropdrop
347010SERVER-WEBAPPCisco FX-OS mod_nuova stack buffer overflow attemptoffoffdropdrop
347011SERVER-OTHERCisco NX-OS Fabric Services Protocol TLV out of bounds read attemptoffoffdropdrop
347012SERVER-OTHERCisco NX-OS Fabric Services Protocol TLV out of bounds read attemptoffoffdropdrop
347013SERVER-OTHERCisco NX-OS Fabric Services Protocol TLV integer overflow attemptoffoffdropdrop
347014SERVER-OTHERCisco NX-OS Fabric Services Protocol TLV integer overflow attemptoffoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
346993SERVER-OTHERCisco NX-OS Fabric Services Protocol denial of service attemptoffoffdropdrop
346994SERVER-OTHERCisco NX-OS Fabric Services Protocol denial of service attemptoffoffdropdrop