Summary
Digital Vaccine #9415 May 12, 2020
Details
Thank you for subscribing to Digital Vaccine updates brought to you by Trend Micro™ TippingPoint DVLabs. New content is now available at the Threat Management Center (TMC): https://tmc.tippingpoint.com. SMS customers can update the Digital Vaccine through the SMS client. From the top-line menu, you can open the "File > Download Digital Vaccine from TMC" menu item to detect and load the latest update. Note: Customers with TP10 devices should perform a soft reboot of their IPS before installing the new DV to avoid a memory issue during the install. |
System Requirements |
The 3.2.0 DV will run on IPS devices with TOS v3.2.0 and above, all NGFW and all TPS systems. The 4.0.0 DV will only run on the Virtual Threat Protection System (vTPS) appliance. Please note that vTPS does not currently support pre-disclosed ZDI filters. |
Microsoft Security Bulletins This DV includes coverage for the Microsoft vulnerabilities released on or before May 12, 2020. The following table maps TippingPoint filters to the Microsoft CVEs. | ||
CVE-2020-0901 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-0909 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-0963 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-0987 | *37612 | |
CVE-2020-1010 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1021 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1023 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1024 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1028 | *37245 | |
CVE-2020-1035 | 37727 | |
CVE-2020-1037 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1048 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1051 | *37051 | |
CVE-2020-1054 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1055 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1056 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1058 | 37723 | |
CVE-2020-1059 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1060 | 37724 | |
CVE-2020-1061 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1062 | 37725 | |
CVE-2020-1063 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1064 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1065 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1066 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1067 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1068 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1069 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1070 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1071 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1072 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1075 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1076 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1077 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1078 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1079 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1081 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1082 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1084 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1086 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1087 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1088 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1090 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1092 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1093 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1096 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1099 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1100 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1101 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1102 | 37035 | |
CVE-2020-1103 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1104 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1105 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1106 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1107 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1108 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1109 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1110 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1111 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1112 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1113 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1114 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1116 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1117 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1118 | 37751 | |
CVE-2020-1121 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1123 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1124 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1125 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1126 | *37377, *37378 | |
CVE-2020-1131 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1132 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1134 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1135 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1136 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1137 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1138 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1139 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1140 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1141 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1142 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1143 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1144 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1145 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1149 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1150 | *36976 | |
CVE-2020-1151 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1153 | 37728 | |
CVE-2020-1154 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1155 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1156 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1157 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1158 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1161 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1164 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1165 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1166 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1171 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1173 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1174 | *36897 | |
CVE-2020-1175 | *36900 | |
CVE-2020-1176 | *36901 | |
CVE-2020-1179 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1184 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1185 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1186 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1187 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1188 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1189 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1190 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1191 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
CVE-2020-1192 | Vendor Deemed Reproducibility or Exploitation Unlikely | |
Filters marked with * shipped prior to this DV, providing zero-day protection. |
Adobe Security Bulletins This DV includes coverage for the Adobe vulnerabilities released on or before May 12, 2020. The following table maps TippingPoint filters to the Adobe CVEs. | ||
APSB20-24 | CVE-2020-9592 | 37758 |
APSB20-24 | CVE-2020-9593 | 37759 |
APSB20-24 | CVE-2020-9594 | 37760 |
APSB20-24 | CVE-2020-9595 | 37761 |
APSB20-24 | CVE-2020-9596 | 37778 |
APSB20-24 | CVE-2020-9597 | *37334 |
APSB20-24 | CVE-2020-9598 | 37763 |
APSB20-24 | CVE-2020-9599 | 37764 |
APSB20-24 | CVE-2020-9600 | 37765 |
APSB20-24 | CVE-2020-9601 | 37766 |
APSB20-24 | CVE-2020-9602 | 37767 |
APSB20-24 | CVE-2020-9603 | 37768 |
APSB20-24 | CVE-2020-9604 | 37769 |
APSB20-24 | CVE-2020-9605 | 37770 |
APSB20-24 | CVE-2020-9606 | *37422 |
APSB20-24 | CVE-2020-9607 | 37772 |
APSB20-24 | CVE-2020-9608 | 37773 |
APSB20-24 | CVE-2020-9609 | 37774 |
APSB20-24 | CVE-2020-9610 | 37775 |
APSB20-24 | CVE-2020-9611 | 37776 |
APSB20-24 | CVE-2020-9612 | *37595 |
Filters marked with * shipped prior to this DV, providing zero-day protection. |
The Digital Vaccine can be manually downloaded from the following URLs: https://tmc.tippingpoint.com/TMC/ViewPackage?parentFolderId=digital_vaccines&contentId=SIG_3.2.0_9415.pkg https://tmc.tippingpoint.com/TMC/ViewPackage?parentFolderId=vsa_dv&contentId=SIG_VTPS_4.0.0_9415.pkg |
Update Details
Table of Contents
--------------------------
Filters
New Filters - 42
Modified Filters (logic changes) - 39
Modified Filters (metadata changes only) - 2
Removed Filters - 5
Filters
----------------
New Filters:
37035: HTTP: Microsoft SharePoint Shared Forms Security Bypass Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Vulnerabilities - Severity: Critical - Description: This filter detects an attempt to exploit a security bypass vulnerability in Microsoft Sharepoint. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-1102 - Classification: Vulnerability - Input Validation (Command injection, XSS, SQL injection, etc) - Protocol: HTTP - Platform: Windows Server Application or Service 37723: HTTP: Microsoft Internet Explorer Remote Code Execution Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a remote code execution vulnerability in Microsoft Internet Explorer. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-1058 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Windows Client Application 37724: HTTP: Microsoft Internet Explorer Remote Code Execution Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a remote code execution vulnerability in Microsoft Internet Explorer. - Deployments: - Deployment: Default (Block / Notify) - Deployment: Performance-Optimized (Disabled) - References: - Common Vulnerabilities and Exposures: CVE-2020-1060 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Windows Client Application 37725: HTTP: Microsoft Internet Explorer propertyIsEnumerable Use-After-Free Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a use-after-free vulnerability in Microsoft Internet Explorer. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-1062 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Windows Client Application 37727: HTTP: Microsoft Internet Explorer RedimPreserve Use-After-Free Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a use-after-free vulnerability in Microsoft Internet Explorer. - Deployments: - Deployment: Default (Block / Notify) - Deployment: Performance-Optimized (Disabled) - References: - Common Vulnerabilities and Exposures: CVE-2020-1035 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Windows Client Application 37728: HTTP: Microsoft Windows PGlbCounter Font Parsing Out-of-Bounds Write Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit an out-of-bounds write vulnerability in Microsoft Windows. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-1153 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Windows Client Application 37729: LDAP: VMware vCenter Server Suspicious addRequest Detection - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Security Policy - Severity: Moderate - Description: This filter detects a suspicious addRequest in VMware vCenter Server. - Deployment: Not enabled by default in any deployment. - References: - Common Vulnerabilities and Exposures: CVE-2020-3952 - Classification: Security Policy - Forbidden Application Access or Service Request - Protocol: LDAP - Platform: Multi-Platform Server Application or Service 37733: HTTP: Sonatype Nexus Repository Manager Cross-Site Scripting Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Vulnerabilities - Severity: Critical - Description: This filter detects an attempt to exploit a cross-site scripting vulnerability in Sonatype Nexus Repository Manager. - Deployments: - Deployment: Default (Block / Notify) - Deployment: Performance-Optimized (Disabled) - References: - Common Vulnerabilities and Exposures: CVE-2020-10203 CVSS 3.5 - Classification: Vulnerability - Input Validation (Command injection, XSS, SQL injection, etc) - Protocol: HTTP - Platform: Multi-Platform Server Application or Service 37734: LDAP: Suspicious bindRequest - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Security Policy - Severity: Moderate - Description: This filter detects a suspicious LDAP bindRequest. - Deployment: Not enabled by default in any deployment. - References: - Common Vulnerabilities and Exposures: CVE-2020-3952 - Classification: Security Policy - Other - Protocol: LDAP - Platform: Multi-Platform Server Application or Service 37735: ZDI-CAN-10906: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37736: ZDI-CAN-11007: Zero Day Initiative Vulnerability (Microsoft Windows) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Microsoft Windows. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37737: ZDI-CAN-10927: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37738: ZDI-CAN-10928: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37739: ZDI-CAN-11006: Zero Day Initiative Vulnerability (Microsoft Windows) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Microsoft Windows. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37741: ZDI-CAN-10961: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37742: ZDI-CAN-10960: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37743: ZDI-CAN-10959: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37744: HTTP: Apache Dubbo HttpRemoteInvocation Insecure Deserialization Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Vulnerabilities - Severity: Critical - Description: This filter detects an attempt to exploit an insecure deserialization vulnerability in Apache Dubbo. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2019-17564 CVSS 6.8 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Server Application or Service 37745: ZDI-CAN-10956: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37746: ZDI-CAN-10957: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37747: ZDI-CAN-10958: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: Not available. - Requires: N/NX-Platform, NGFW, or TPS devices - Category: Exploits - Severity: Critical - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5. - Deployments: - Deployment: Security-Optimized (Block / Notify / Trace) - Classification: Vulnerability - Other - Protocol: Other Protocol - Platform: Other Server Application or Service 37750: TCP: SaltStack Salt Authentication Bypass Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Vulnerabilities - Severity: Critical - Description: This filter detects an attempt to exploit a security bypass vulnerability in SaltStack Salt. - Deployment: Not enabled by default in any deployment. - References: - Common Vulnerabilities and Exposures: CVE-2020-11651 - Classification: Vulnerability - Input Validation (Command injection, XSS, SQL injection, etc) - Protocol: HTTP - Platform: Multi-Platform Server Application or Service 37751: TLS: Microsoft Windows TLS Key Exchange Denial-of-Service Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Vulnerabilities - Severity: High - Description: This filter detects an attempt to exploit a denial-of-service vulnerability in Microsoft Windows. - Deployment: Not enabled by default in any deployment. - References: - Common Vulnerabilities and Exposures: CVE-2020-1118 - Classification: Vulnerability - Other - Protocol: SSL/TLS - Platform: Windows Server Application or Service 37758: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9592 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37759: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9593 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37760: HTTP: Adobe Acrobat Reader Out-of-Bounds Write Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a out-of-bounds write vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9594 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37761: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9595 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37763: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9598 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37764: HTTP: Adobe Acrobat Reader Out-of-Bounds Read Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: High - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9599 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37765: HTTP: Adobe Acrobat Reader Out-of-Bounds Read Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: High - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9600 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37766: HTTP: Adobe Acrobat Reader Out-of-Bounds Read Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: High - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9601 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37767: HTTP: Adobe Acrobat Reader Out-of-Bounds Read Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: High - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9602 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37768: HTTP: Adobe Acrobat Reader Out-of-Bounds Read Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: High - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9603 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37769: HTTP: Adobe Acrobat Reader Buffer Overflow Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a buffer overflow vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9604 - Classification: Vulnerability - Buffer/Heap Overflow - Protocol: HTTP - Platform: Multi-Platform Client Application 37770: HTTP: Adobe Acrobat Reader Buffer Overflow Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a buffer overflow vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9605 - Classification: Vulnerability - Buffer/Heap Overflow - Protocol: HTTP - Platform: Multi-Platform Client Application 37772: HTTP: Adobe Acrobat Reader Use-After-Free Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a use-after-free vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9607 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37773: HTTP: Adobe Acrobat Reader Out-Of-Bounds Read Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: High - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9608 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37774: HTTP: Adobe Acrobat Reader Out-Of-Bounds Read Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9609 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37775: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9610 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37776: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9611 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37778: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Exploits - Severity: Critical - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader. - Deployments: - Deployment: Security-Optimized (Block / Notify) - References: - Common Vulnerabilities and Exposures: CVE-2020-9596 - Classification: Vulnerability - Other - Protocol: HTTP - Platform: Multi-Platform Client Application 37782: TCP: SaltStack Salt Directory Traversal Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Category: Vulnerabilities - Severity: Critical - Description: This filter detects an attempt to exploit a directory traversal vulnerability in SaltStack Salt. - Deployment: Not enabled by default in any deployment. - References: - Common Vulnerabilities and Exposures: CVE-2020-11652 - Classification: Vulnerability - Input Validation (Command injection, XSS, SQL injection, etc) - Protocol: HTTP - Platform: Multi-Platform Server Application or Service Modified Filters (logic changes): * = Enabled in Default deployments * 34034: HTTP: Adobe Bridge CC PCX File Parsing Heap-based Buffer Overflow Vulnerability (ZDI-19-345) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "34034: ZDI-CAN-7596: Zero Day Initiative Vulnerability (Adobe Bridge)". - Description updated. - Detection logic updated. - Vulnerability references updated. 35098: RPC: Advantech WebAccess viewsrv SQLGetData Untrusted Pointer Dereference Vulnerability (ZDI-19-623) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "35098: ZDI-CAN-8119: Zero Day Initiative Vulnerability (Advantech WebAccess)". - Description updated. - Detection logic updated. - Vulnerability references updated. 35170: HTTP: Fuji Electric Alpha7 PC Loader A7P File Parsing Out-Of-Bounds Read Vulnerability (ZDI-19-517) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "35170: ZDI-CAN-8030: Zero Day Initiative Vulnerability (Fuji Electric Alpha7)". - Severity changed from "Critical" to "High". - Description updated. - Detection logic updated. - Vulnerability references updated. 35400: HTTP: Rockwell Automation Arena Simulation DOE File Parsing Use-After-Free Vulnerability(ZDI-19-696) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "35400: ZDI-CAN-8015: Zero Day Initiative Vulnerability (Rockwell Automation Arena Simulation)". - Description updated. - Detection logic updated. - Vulnerability references updated. 35409: HTTP: Adobe Photoshop PostScript put Buffer Overflow Vulnerability (ZDI-19-736) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "35409: ZDI-CAN-8549: Zero Day Initiative Vulnerability (Adobe Photoshop)". - Description updated. - Detection logic updated. - Vulnerability references updated. 36734: HTTP: Advantech WebAccess/NMS Login SQL Injection Vulnerability (ZDI-20-374, ZDI-20-380) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36734: ZDI-CAN-9567,9573: Zero Day Initiative Vulnerability (Advantech WebAccess/NMS)". - Severity changed from "Critical" to "High". - Description updated. - Detection logic updated. - Vulnerability references updated. 36745: HTTP: Advantech WebAccess/NMS download.jsp Directory Traversal Vulnerability (ZDI-20-384) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36745: ZDI-CAN-9577: Zero Day Initiative Vulnerability (Advantech WebAccess/NMS)". - Severity changed from "Critical" to "High". - Description updated. - Detection logic updated. - Vulnerability references updated. 36748: HTTP: Advantech WebAccess/NMS forcedScanDevice SQL Injection Vulnerability (ZDI-20-393) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36748: ZDI-CAN-9587: Zero Day Initiative Vulnerability (Advantech WebAccess/NMS)". - Severity changed from "Critical" to "High". - Description updated. - Detection logic updated. - Vulnerability references updated. 36749: HTTP: Advantech WebAccess/NMS TopogroupeditAction SQL Injection (ZDI-20-388, ZDI-20-390) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36749: ZDI-CAN-9581,9583: Zero Day Initiative Vulnerability (Advantech WebAccess/NMS)". - Severity changed from "Critical" to "High". - Description updated. - Detection logic updated. - Vulnerability references updated. 36894: HTTP: Cisco UCS Director downloadFile Directory Traversal Vulnerability (ZDI-20-538) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36894: ZDI-CAN-9557: Zero Day Initiative Vulnerability (Cisco UCS)". - Description updated. - Detection logic updated. - Vulnerability references updated. 36897: HTTP: Microsoft Windows JET Database Engine Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36897: ZDI-CAN-10056: Zero Day Initiative Vulnerability (Microsoft JET Database)". - Description updated. - Detection logic updated. - Vulnerability references updated. 36900: HTTP: Microsoft JET Database Engine Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36900: ZDI-CAN-10060: Zero Day Initiative Vulnerability (Microsoft JET Database)". - Description updated. - Detection logic updated. - Vulnerability references updated. 36901: HTTP: Microsoft Windows JET Database Engine Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36901: ZDI-CAN-10064: Zero Day Initiative Vulnerability (Microsoft JET Database)". - Description updated. - Detection logic updated. - Vulnerability references updated. 36934: HTTP: Advantech WebAccess/NMS DBUtil SQL Injection Vulnerability (ZDI-20-394) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36934: ZDI-CAN-9588: Zero Day Initiative Vulnerability (Advantech WebAccess/SCADA)". - Description updated. - Detection logic updated. - Vulnerability references updated. 36935: HTTP: Advantech WebAccess/NMS DBUtil SQL Injection Vulnerability (ZDI-20-395) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36935: ZDI-CAN-9589: Zero Day Initiative Vulnerability (Advantech WebAccess/SCADA)". - Description updated. - Detection logic updated. - Vulnerability references updated. 36939: HTTP: Advantech WebAccess/NMS DBUtil SQL Injection Vulnerability (ZDI-20-396) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36939: ZDI-CAN-9601: Zero Day Initiative Vulnerability (Advantech WebAccess/SCADA)". - Description updated. - Detection logic updated. - Vulnerability references updated. * 36976: HTTP: Microsoft Internet Explorer CWMPErrorDlg Use-After-Free Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "36976: ZDI-CAN-10103: Zero Day Initiative Vulnerability (Microsoft Internet Explorer)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37051: HTTP: Microsoft Windows JET Database Engine Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37051: ZDI-CAN-10039: Zero Day Initiative Vulnerability (Microsoft JET Database)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37245: HTTP: Microsoft Windows Media Player HEVC Stream Parsing Buffer Overflow Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37245: ZDI-CAN-10516: Zero Day Initiative Vulnerability (Microsoft Windows Media Player)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37251: HTTP: Eaton HMiSoft VU3 File Parsing wDescribeLen Out-Of-Bounds Read Vulnerability (ZDI-20-492) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37251: ZDI-CAN-10417: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Severity changed from "Critical" to "High". - Description updated. - Detection logic updated. - Vulnerability references updated. 37255: HTTP: Eaton HMiSoft VU3 File Parsing Buffer Overflow Vulnerability (ZDI-20-489) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37255: ZDI-CAN-10340: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37267: HTTP: Eaton HMiSoft VU3 File Parsing LinkSize Buffer Overflow Vulnerability (ZDI-20-488) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37267: ZDI-CAN-10167: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37281: HTTP: Eaton HMiSoft VU3 File Parsing wTDateLen Buffer Overflow Vulnerability (ZDI-20-478) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37281: ZDI-CAN-10153: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37283: HTTP: Eaton HMiSoft VU3 File Parsing wTextLen Buffer Overflow Vulnerability (ZDI-20-479) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37283: ZDI-CAN-10157: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37287: HTTP: Eaton HMiSoft VU3 File Parsing wMailContentLen Buffer Overflow Vulnerability (ZDI-20-480) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37287: ZDI-CAN-10158: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37288: HTTP: Eaton HMiSoft VU3 File Parsing wMailCopyToLen Buffer Overflow Vulnerability (ZDI-20-481) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37288: ZDI-CAN-10159: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37291: HTTP: Eaton HMiSoft VU3 File Parsing wMailToLen Buffer Overflow Vulnerability (ZDI-20-482) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37291: ZDI-CAN-10160: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37292: HTTP: Eaton HMiSoft VU3 File Parsing wMessageLen Buffer Overflow Vulnerability (ZDI-20-483) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37292: ZDI-CAN-10161: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37293: HTTP: Eaton HMiSoft VU3 File Parsing wMailBlindCopyToLen Buffer Overflow Vulnerability (ZDI-20-484) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37293: ZDI-CAN-10162: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37294: HTTP: Eaton HMiSoft VU3 File Parsing wKPFStringLen Buffer Overflow Vulnerability (ZDI-20-475) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37294: ZDI-CAN-10163: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37295: HTTP: Eaton HMiSoft VU3 File Parsing wTitleTextLen Buffer Overflow Vulnerability (ZDI-20-485) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37295: ZDI-CAN-10164: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37296: HTTP: Eaton HMiSoft VU3 File Parsing GifName Buffer Overflow Vulnerability (ZDI-20-486) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37296: ZDI-CAN-10165: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37297: HTTP: Eaton HMiSoft VU3 File Parsing LinkSize Buffer Overflow Vulnerability (ZDI-20-487) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37297: ZDI-CAN-10166: Zero Day Initiative Vulnerability (Eaton HMiSoft)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37334: HTTP: Adobe Acrobat Reader DC JPEG File Parsing Out-Of-Bounds Write Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37334: ZDI-CAN-10106: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37377: HTTP: Microsoft Windows Media Player HEVC Stream Parsing Out-Of-Bounds Write Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37377: ZDI-CAN-10569: Zero Day Initiative Vulnerability (Microsoft Windows Media Player)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37378: HTTP: Microsoft Windows Media Player HEVC Stream Parsing Out-Of-Bounds Write Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37378: ZDI-CAN-10566: Zero Day Initiative Vulnerability (Microsoft Windows Media Player)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37422: HTTP: Adobe Reader Field Use-After-Free Vulnerability (Pwn2Own) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37422: PWN2OWN ZDI-CAN-10784: Zero Day Initiative Vulnerability (Adobe Reader)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37595: HTTP: Adobe Acrobat Reader DC JPEG2000 Buffer Overflow Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37595: ZDI-CAN-10822: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)". - Description updated. - Detection logic updated. - Vulnerability references updated. 37612: HTTP: Microsoft Windows EMR_SETDIBITSTODEVICE Out-Of-Bounds Read Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "37612: ZDI-CAN-10743: Zero Day Initiative Vulnerability (Microsoft Windows)". - Severity changed from "Critical" to "High". - Description updated. - Detection logic updated. - Vulnerability references updated. Modified Filters (metadata changes only): * = Enabled in Default deployments 33863: HTTP: HPE IMC perfSelectTask Language Injection Vulnerability (ZDI-19-335, ZDI-20-180) - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Name changed from "33863: HTTP: HPE Intelligent Management Center perfSelectTask Language Injection Vulnerability (ZDI-19-335)". - Description updated. - Vulnerability references updated. * 37264: HTTP: Google Chrome JSCreate Memory Corruption Vulnerability - IPS Version: 3.6.2 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Vulnerability references updated. Removed Filters: 4858: Backdoor: C99shell PHP Backdoor Communication - IPS Version: 1.0.0 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. 5086: Backdoor: C99shell PHP Backdoor Communication - IPS Version: 3.0.0 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. 5120: Backdoor: R57shell PHP Backdoor Communication - IPS Version: 1.0.0 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. 12411: Backdoor: Packed Web Shell by Orb (WSO) - IPS Version: 1.0.0 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. 17155: TCP: C99shell PHP Script Transfer - IPS Version: 1.0.0 and after. - NGFW Version: 1.0.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after.Top of the Page