Cisco Talos Update for FireSIGHT Management Center

Date: 2019-10-17

This SRU number: 2019-10-17-001
Previous SRU number: 2019-10-14-001

Applies to:

This SEU number: 2083
Previous SEU: 2081

Applies to:

This is the complete list of rules added in SRU 2019-10-17-001 and SEU 2083.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
351890SERVER-WEBAPPCisco SPA100 Series analog telephone adapters buffer overflow attemptoffoffdropdrop
351891SERVER-WEBAPPCisco SPA100 Series analog telephone adapters buffer overflow attemptoffoffdropdrop
351892SERVER-WEBAPPCisco SPA100 Series analog telephone adapters buffer overflow attemptoffoffdropdrop
351893SERVER-WEBAPPCisco SPA100 Series analog telephone adapters buffer overflow attemptoffoffdropdrop
351894SERVER-WEBAPPCisco SPA100 Series analog telephone adapters buffer overflow attemptoffoffdropdrop
351895SERVER-WEBAPPCisco SPA100 Series analog telephone adapters buffer overflow attemptoffoffdropdrop
151896BROWSER-IEMicrosoft ChakraCore scripting engine memory corruption attemptoffoffoffdrop
151897BROWSER-IEMicrosoft ChakraCore scripting engine memory corruption attemptoffoffoffdrop
151898OS-OTHERCisco Nexus OS software command injection attemptoffoffoffdrop
151899SERVER-WEBAPPAdminer port scan server side request forgery attemptoffoffdropdrop
351900SERVER-WEBAPPCisco Small Business Switches cross site scripting attemptoffoffdropdrop
351902SERVER-WEBAPPCisco Small Business Switches cross site scripting attemptoffoffdropdrop
351903SERVER-WEBAPPCisco Small Business Switches cross site scripting attemptoffoffdropdrop
351904SERVER-WEBAPPCisco Small Business Switches cross site scripting attemptoffoffdropdrop
351905SERVER-WEBAPPCisco Small Business Switches cross site scripting attemptoffoffdropdrop
351906SERVER-WEBAPPCisco Small Business Switches cross site scripting attemptoffoffdropdrop
351907SERVER-WEBAPPCisco Small Business Switches cross site scripting attemptoffoffdropdrop
151908MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151909MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151910MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151911MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffoffoffoff
151912MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151913MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151914MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151915MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151916MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151917MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151918MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151919MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151920MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151921MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151922MALWARE-CNCAndr.Trojan.Gustuff variant outbound cnc connectionoffdropdropdrop
151923INDICATOR-OBFUSCATIONPossible PHP eval backdoor upload attemptoffoffoffdrop
351924SERVER-WEBAPPTRUFFLEHUNTER TALOS-2019-0917 attack attemptoffoffdropdrop
351925SERVER-WEBAPPTRUFFLEHUNTER TALOS-2019-0917 attack attemptoffoffdropdrop
351926SERVER-WEBAPPTRUFFLEHUNTER TALOS-2019-0917 attack attemptoffoffdropdrop
351927SERVER-WEBAPPTRUFFLEHUNTER TALOS-2019-0917 attack attemptoffoffdropdrop
351928SERVER-WEBAPPTRUFFLEHUNTER TALOS-2019-0917 attack attemptoffoffdropdrop
351929SERVER-WEBAPPTRUFFLEHUNTER TALOS-2019-0919 attack attemptoffoffdropdrop
151930SERVER-WEBAPPPHP tag depth heap memory corruption attemptoffoffoffdrop
351931FILE-IMAGETRUFFLEHUNTER TALOS-2019-0916 attack attemptoffoffdropdrop
351932FILE-IMAGETRUFFLEHUNTER TALOS-2019-0916 attack attemptoffoffdropdrop
351933FILE-IMAGETRUFFLEHUNTER TALOS-2019-0916 attack attemptoffoffdropdrop
351934FILE-IMAGETRUFFLEHUNTER TALOS-2019-0916 attack attemptoffoffdropdrop
351935FILE-IMAGETRUFFLEHUNTER TALOS-2019-0916 attack attemptoffoffdropdrop
351936FILE-IMAGETRUFFLEHUNTER TALOS-2019-0916 attack attemptoffoffdropdrop
351937FILE-IMAGETRUFFLEHUNTER TALOS-2019-0916 attack attemptoffoffdropdrop
351938FILE-IMAGETRUFFLEHUNTER TALOS-2019-0916 attack attemptoffoffdropdrop
151943BROWSER-IEMicrosoft Internet Explorer ActiveX type confusion attemptoffdropdropdrop
151944BROWSER-IEMicrosoft Internet Explorer ActiveX type confusion attemptoffdropdropdrop
151945FILE-OTHERGhostscript -dSAFER sandbox bypass attemptoffoffoffdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
351901SERVER-WEBAPPCisco Small Business Switches denial of service attemptoffoffdropdrop
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
151939DELETEDrrAZPB2CvyvtAXaAY74gTWUfLivviq78offoffoffoff
151940DELETED0JUXKKbXzfsKZNPwGqmwIGI2W07OoiTaoffoffoffoff
151941DELETEDE24EkHCWEpvJkLXVf4tUOY5QoxjutKqqoffoffoffoff
151942DELETEDQ1HY8vF1W2bsP5zH2Q2W7eK4Lyz9HZORoffoffoffoff