Cisco Talos Update for FireSIGHT Management Center

Date: 2020-04-16

This SRU number: 2020-04-15-001
Previous SRU number: 2020-04-13-001

Applies to:

This SEU number: 2153
Previous SEU: 2152

Applies to:

This is the complete list of rules added in SRU 2020-04-15-001 and SEU 2153.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
353660FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
353661FILE-OTHERCisco Webex Network Recording Player memory corruption attemptoffoffdropdrop
153662MALWARE-OTHERWin.Trojan.MedusaLocker malicious executable download attemptoffoffoffdrop
153663MALWARE-OTHERWin.Trojan.MedusaLocker malicious executable download attemptoffoffdropdrop
153664MALWARE-OTHERWin.Trojan.MedusaLocker malicious executable download attemptoffoffdropdrop
153665MALWARE-OTHERWin.Trojan.MedusaLocker malicious executable download attemptoffoffdropdrop
353666SERVER-OTHERCisco Wireless Lan Controller CAPWAP out of bounds access attemptoffoffdropdrop
353667POLICY-OTHERCisco Unified Communications Manager TAPS RMI method lookup detectedoffoffoffoff
353669SERVER-WEBAPPCisco IP Phone libHTTPService.so stack buffer overflow attemptoffoffdropdrop
353670SERVER-WEBAPPCisco IP Phone libHTTPService.so stack buffer overflow attemptoffoffdropdrop
353671SERVER-WEBAPPCisco UCS Director authentication bypass attemptoffdropdropdrop
353672SERVER-WEBAPPCisco UCS Director REST API directory traversal attemptoffdropdropdrop
353673SERVER-WEBAPPCisco UCS Director REST API directory traversal attemptoffdropdropdrop
353674SERVER-WEBAPPCisco UCS Director REST API directory traversal attemptoffdropdropdrop
353675SERVER-WEBAPPCisco UCS Director LargeFileUploadServlet directory traversal attemptoffdropdropdrop
353676SERVER-WEBAPPCisco UCS Director LargeFileUploadServlet directory traversal attemptoffdropdropdrop
353677SERVER-WEBAPPCisco UCS Director ClientServlet directory traversal attemptoffdropdropdrop
353678SERVER-WEBAPPCisco UCS Director ClientServlet directory traversal attemptoffdropdropdrop
353679SERVER-WEBAPPCisco UCS Director ClientServlet directory traversal attemptoffdropdropdrop
353680SERVER-WEBAPPCisco UCS Director filename directory traversal attemptoffdropdropdrop
353681SERVER-WEBAPPCisco UCS Director arbitrary JSP file upload attemptoffdropdropdrop
353682SERVER-WEBAPPCisco Mobility Express cross site request forgery attemptoffoffdropdrop
353683SERVER-WEBAPPCisco Mobility Express cross site request forgery attemptoffoffdropdrop
353684FILE-OTHERTRUFFLEHUNTER TALOS-2020-1047 attack attemptoffoffdropdrop
353685FILE-OTHERTRUFFLEHUNTER TALOS-2020-1047 attack attemptoffoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
353668SERVER-OTHERCisco Unified Communications Manager TAPS RMI directory traversal attemptoffdropdropdrop