Cisco Talos Update for FireSIGHT Management Center

Date: 2019-06-06

This SRU number: 2019-06-05-003
Previous SRU number: 2019-06-03-001

Applies to:

This SEU number: 2028
Previous SEU: 2025

Applies to:

This is the complete list of rules added in SRU 2019-06-05-003 and SEU 2028.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
150300MALWARE-CNCWin.Trojan.TRITON attack tool outbound connectionoffdropdropdrop
150301MALWARE-CNCWin.Trojan.TRITON attack tool outbound connectionoffdropdropdrop
150302MALWARE-CNCWin.Trojan.TRITON attack tool outbound connectionoffdropdropdrop
150303MALWARE-CNCWin.Trojan.TRITON attack tool outbound connectionoffdropdropdrop
150304SERVER-WEBAPPOpenDreamBox 2.0.0 Plugin WebAdmin command injection attemptoffoffdropdrop
150305SERVER-WEBAPPOpenDreamBox 2.0.0 Plugin WebAdmin command injection attemptoffoffdropdrop
150306SERVER-WEBAPPOpenDreamBox 2.0.0 Plugin WebAdmin command injection attemptoffoffoffoff
150307SERVER-WEBAPPOpenDreamBox 2.0.0 Plugin WebAdmin command injection attemptoffoffdropdrop
150308SERVER-WEBAPPDell KACE K1000 command injection attemptoffoffdropdrop
150309SERVER-WEBAPPDell KACE K1000 command injection attemptoffoffdropdrop
150310SERVER-WEBAPPDell KACE K1000 command injection attemptoffoffdropdrop
150311SERVER-WEBAPPDell KACE K1000 command injection attemptoffoffdropdrop
150312SERVER-WEBAPPHooToo tripMate protocol.csp mac parameter command injection attemptoffoffdropdrop
150313SERVER-WEBAPPHooToo tripMate protocol.csp mac parameter command injection attemptoffoffdropdrop
150314SERVER-WEBAPPHooToo tripMate protocol.csp mac parameter command injection attemptoffoffdropdrop
150315SERVER-WEBAPPHooToo tripMate protocol.csp mac parameter command injection attemptoffoffdropdrop
150316SERVER-WEBAPPAsus DSL-N12E_C1 1.1.2.3_345 command injection attemptoffoffdropdrop
150317SERVER-WEBAPPAsus DSL-N12E_C1 1.1.2.3_345 command injection attemptoffoffdropdrop
150318SERVER-WEBAPPAsus DSL-N12E_C1 1.1.2.3_345 command injection attemptoffoffdropdrop
150319SERVER-WEBAPPAsus DSL-N12E_C1 1.1.2.3_345 command injection attemptoffoffdropdrop
150321SERVER-WEBAPPMiCasaVerde VeraLite remote code execution attemptoffoffdropdrop
150322SERVER-WEBAPPMiCasaVerde VeraLite remote code execution attemptoffoffdropdrop
150323SERVER-WEBAPPCrestron AM platform command injection attemptoffoffdropdrop
150324SERVER-WEBAPPCrestron AM platform command injection attemptoffoffdropdrop
150325SERVER-WEBAPPCrestron AM platform command injection attemptoffoffdropdrop
150326SERVER-WEBAPPCrestron AM platform command injection attemptoffoffdropdrop
150327SERVER-WEBAPPLG SuperSignEz CMS command injection attemptoffoffdropdrop
150328SERVER-WEBAPPLG SuperSignEz CMS command injection attemptoffoffdropdrop
150329SERVER-WEBAPPLG SuperSignEz CMS command injection attemptoffoffdropdrop
150330SERVER-WEBAPPLG SuperSignEz CMS command injection attemptoffoffdropdrop
150331SERVER-WEBAPPAsustor ADM command injection attemptoffoffdropdrop
150332SERVER-WEBAPPAsustor ADM command injection attemptoffoffdropdrop
150333SERVER-WEBAPPAsustor ADM command injection attemptoffoffdropdrop
150334SERVER-WEBAPPAsustor ADM command injection attemptoffoffdropdrop
350335SERVER-WEBAPPCisco Industrial Network Director remote code execution attemptoffoffdropdrop
150336SERVER-WEBAPPGoAhead IP Camera set_ftp.cgi command injection attemptoffdropdropdrop
150337SERVER-WEBAPPGoAhead IP Camera set_ftp.cgi command injection attemptoffdropdropdrop
150338SERVER-WEBAPPGoAhead IP Camera set_ftp.cgi command injection attemptoffdropdropdrop
150339SERVER-WEBAPPGoAhead IP Camera set_ftp.cgi command injection attemptoffdropdropdrop
150340SERVER-WEBAPPSchneider Electric U.Motion Builder command injection attemptoffoffdropdrop
150341SERVER-WEBAPPSchneider Electric U.Motion Builder command injection attemptoffoffdropdrop
150342SERVER-WEBAPPSchneider Electric U.Motion Builder command injection attemptoffoffdropdrop
150343SERVER-WEBAPPSchneider Electric U.Motion Builder command injection attemptoffoffdropdrop
150344SERVER-WEBAPPVMWare NSX SD-WAN Edge command injection attemptoffdropdropdrop
150345SERVER-WEBAPPVMWare NSX SD-WAN Edge command injection attemptoffdropdropdrop
150346SERVER-WEBAPPVMWare NSX SD-WAN Edge command injection attemptoffdropdropdrop
150347SERVER-WEBAPPVMWare NSX SD-WAN Edge command injection attemptoffdropdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
350320SERVER-OTHERCisco Unified Communications Manager denial of service attemptoffoffdropdrop