Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Digital Vaccine #9415

    • Updated:
    • Product/Version:
    • TippingPoint Digital Vaccine
    • Platform:
Summary
Digital Vaccine #9415      May 12, 2020
Details
Public
Thank you for subscribing to Digital Vaccine updates brought to you by Trend Micro™ TippingPoint DVLabs.

New content is now available at the Threat Management Center (TMC): https://tmc.tippingpoint.com.

SMS customers can update the Digital Vaccine through the SMS client. From the top-line menu, you can open the "File > Download Digital Vaccine from TMC" menu item to detect and load the latest update.

Note: Customers with TP10 devices should perform a soft reboot of their IPS before installing the new DV to avoid a memory issue during the install.
 
System Requirements
The 3.2.0 DV will run on IPS devices with TOS v3.2.0 and above,  all NGFW and all TPS systems. The 4.0.0 DV will only run on the Virtual Threat Protection System (vTPS) appliance. Please note that vTPS does not currently support pre-disclosed ZDI filters.
 
Microsoft Security Bulletins
This DV includes coverage for the Microsoft vulnerabilities released on or before May 12, 2020.
The following table maps TippingPoint filters to the Microsoft CVEs.
CVE-2020-0901 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-0909 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-0963 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-0987*37612 
CVE-2020-1010 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1021 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1023 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1024 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1028*37245 
CVE-2020-103537727 
CVE-2020-1037 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1048 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1051*37051 
CVE-2020-1054 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1055 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1056 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-105837723 
CVE-2020-1059 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-106037724 
CVE-2020-1061 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-106237725 
CVE-2020-1063 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1064 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1065 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1066 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1067 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1068 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1069 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1070 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1071 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1072 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1075 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1076 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1077 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1078 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1079 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1081 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1082 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1084 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1086 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1087 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1088 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1090 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1092 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1093 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1096 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1099 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1100 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1101 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-110237035 
CVE-2020-1103 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1104 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1105 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1106 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1107 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1108 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1109 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1110 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1111 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1112 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1113 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1114 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1116 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1117 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-111837751 
CVE-2020-1121 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1123 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1124 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1125 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1126*37377, *37378 
CVE-2020-1131 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1132 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1134 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1135 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1136 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1137 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1138 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1139 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1140 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1141 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1142 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1143 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1144 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1145 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1149 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1150*36976 
CVE-2020-1151 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-115337728 
CVE-2020-1154 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1155 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1156 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1157 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1158 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1161 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1164 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1165 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1166 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1171 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1173 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1174*36897 
CVE-2020-1175*36900 
CVE-2020-1176*36901 
CVE-2020-1179 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1184 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1185 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1186 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1187 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1188 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1189 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1190 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1191 Vendor Deemed Reproducibility or Exploitation Unlikely
CVE-2020-1192 Vendor Deemed Reproducibility or Exploitation Unlikely
Filters marked with * shipped prior to this DV, providing zero-day protection.
 
Adobe Security Bulletins
This DV includes coverage for the Adobe vulnerabilities released on or before May 12, 2020.
The following table maps TippingPoint filters to the Adobe CVEs.
APSB20-24CVE-2020-959237758
APSB20-24CVE-2020-959337759
APSB20-24CVE-2020-959437760
APSB20-24CVE-2020-959537761
APSB20-24CVE-2020-959637778
APSB20-24CVE-2020-9597*37334
APSB20-24CVE-2020-959837763
APSB20-24CVE-2020-959937764
APSB20-24CVE-2020-960037765
APSB20-24CVE-2020-960137766
APSB20-24CVE-2020-960237767
APSB20-24CVE-2020-960337768
APSB20-24CVE-2020-960437769
APSB20-24CVE-2020-960537770
APSB20-24CVE-2020-9606*37422
APSB20-24CVE-2020-960737772
APSB20-24CVE-2020-960837773
APSB20-24CVE-2020-960937774
APSB20-24CVE-2020-961037775
APSB20-24CVE-2020-961137776
APSB20-24CVE-2020-9612*37595
Filters marked with * shipped prior to this DV, providing zero-day protection.
 
The Digital Vaccine can be manually downloaded from the following URLs:
https://tmc.tippingpoint.com/TMC/ViewPackage?parentFolderId=digital_vaccines&contentId=SIG_3.2.0_9415.pkg
https://tmc.tippingpoint.com/TMC/ViewPackage?parentFolderId=vsa_dv&contentId=SIG_VTPS_4.0.0_9415.pkg

Update Details

Table of Contents
--------------------------

Filters
 New Filters - 42
 Modified Filters (logic changes) - 39
 Modified Filters (metadata changes only) - 2
 Removed Filters - 5

Filters
----------------
 New Filters:
    37035: HTTP: Microsoft SharePoint Shared Forms Security Bypass Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Vulnerabilities
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a security bypass vulnerability in Microsoft Sharepoint.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-1102
      - Classification: Vulnerability - Input Validation (Command injection, XSS, SQL injection, etc)
      - Protocol: HTTP
      - Platform: Windows Server Application or Service

    37723: HTTP: Microsoft Internet Explorer Remote Code Execution Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a remote code execution vulnerability in Microsoft Internet Explorer.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-1058
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Windows Client Application

    37724: HTTP: Microsoft Internet Explorer Remote Code Execution Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a remote code execution vulnerability in Microsoft Internet Explorer.
      - Deployments:
        - Deployment: Default (Block / Notify)
        - Deployment: Performance-Optimized (Disabled)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-1060
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Windows Client Application

    37725: HTTP: Microsoft Internet Explorer propertyIsEnumerable Use-After-Free Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a use-after-free vulnerability in Microsoft Internet Explorer.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-1062
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Windows Client Application

    37727: HTTP: Microsoft Internet Explorer RedimPreserve Use-After-Free Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a use-after-free vulnerability in Microsoft Internet Explorer.
      - Deployments:
        - Deployment: Default (Block / Notify)
        - Deployment: Performance-Optimized (Disabled)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-1035
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Windows Client Application

    37728: HTTP: Microsoft Windows PGlbCounter Font Parsing Out-of-Bounds Write Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit an out-of-bounds write vulnerability in Microsoft Windows.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-1153
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Windows Client Application

    37729: LDAP: VMware vCenter Server Suspicious addRequest Detection
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Security Policy
      - Severity: Moderate
      - Description: This filter detects a suspicious addRequest in VMware vCenter Server.
      - Deployment: Not enabled by default in any deployment.
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-3952
      - Classification: Security Policy - Forbidden Application Access or Service Request
      - Protocol: LDAP
      - Platform: Multi-Platform Server Application or Service

    37733: HTTP: Sonatype Nexus Repository Manager Cross-Site Scripting Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Vulnerabilities
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a cross-site scripting vulnerability in Sonatype Nexus Repository Manager.
      - Deployments:
        - Deployment: Default (Block / Notify)
        - Deployment: Performance-Optimized (Disabled)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-10203 CVSS 3.5
      - Classification: Vulnerability - Input Validation (Command injection, XSS, SQL injection, etc)
      - Protocol: HTTP
      - Platform: Multi-Platform Server Application or Service

    37734: LDAP: Suspicious bindRequest
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Security Policy
      - Severity: Moderate
      - Description: This filter detects a suspicious LDAP bindRequest.
      - Deployment: Not enabled by default in any deployment.
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-3952
      - Classification: Security Policy - Other
      - Protocol: LDAP
      - Platform: Multi-Platform Server Application or Service

    37735: ZDI-CAN-10906: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37736: ZDI-CAN-11007: Zero Day Initiative Vulnerability (Microsoft Windows)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Microsoft Windows.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37737: ZDI-CAN-10927: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37738: ZDI-CAN-10928: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37739: ZDI-CAN-11006: Zero Day Initiative Vulnerability (Microsoft Windows)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Microsoft Windows.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37741: ZDI-CAN-10961: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37742: ZDI-CAN-10960: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37743: ZDI-CAN-10959: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37744: HTTP: Apache Dubbo HttpRemoteInvocation Insecure Deserialization Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Vulnerabilities
      - Severity: Critical
      - Description: This filter detects an attempt to exploit an insecure deserialization vulnerability in Apache Dubbo.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2019-17564 CVSS 6.8
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Server Application or Service

    37745: ZDI-CAN-10956: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37746: ZDI-CAN-10957: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37747: ZDI-CAN-10958: Zero Day Initiative Vulnerability (Fuji Electric Tellus Lite V-Simulator 5)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: N/NX-Platform, NGFW, or TPS devices
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Fuji Electric Tellus Lite V-Simulator 5.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify / Trace)
      - Classification: Vulnerability - Other
      - Protocol: Other Protocol
      - Platform: Other Server Application or Service

    37750: TCP: SaltStack Salt Authentication Bypass Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Vulnerabilities
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a security bypass vulnerability in SaltStack Salt.
      - Deployment: Not enabled by default in any deployment.
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-11651
      - Classification: Vulnerability - Input Validation (Command injection, XSS, SQL injection, etc)
      - Protocol: HTTP
      - Platform: Multi-Platform Server Application or Service

    37751: TLS: Microsoft Windows TLS Key Exchange Denial-of-Service Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Vulnerabilities
      - Severity: High
      - Description: This filter detects an attempt to exploit a denial-of-service vulnerability in Microsoft Windows.
      - Deployment: Not enabled by default in any deployment.
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-1118
      - Classification: Vulnerability - Other
      - Protocol: SSL/TLS
      - Platform: Windows Server Application or Service

    37758: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9592
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37759: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9593
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37760: HTTP: Adobe Acrobat Reader Out-of-Bounds Write Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a out-of-bounds write vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9594
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37761: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9595
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37763: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9598
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37764: HTTP: Adobe Acrobat Reader Out-of-Bounds Read Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: High
      - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9599
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37765: HTTP: Adobe Acrobat Reader Out-of-Bounds Read Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: High
      - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9600
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37766: HTTP: Adobe Acrobat Reader Out-of-Bounds Read Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: High
      - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9601
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37767: HTTP: Adobe Acrobat Reader Out-of-Bounds Read Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: High
      - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9602
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37768: HTTP: Adobe Acrobat Reader Out-of-Bounds Read Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: High
      - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9603
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37769: HTTP: Adobe Acrobat Reader Buffer Overflow Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a buffer overflow vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9604
      - Classification: Vulnerability - Buffer/Heap Overflow
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37770: HTTP: Adobe Acrobat Reader Buffer Overflow Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a buffer overflow vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9605
      - Classification: Vulnerability - Buffer/Heap Overflow
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37772: HTTP: Adobe Acrobat Reader Use-After-Free Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a use-after-free vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9607
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37773: HTTP: Adobe Acrobat Reader Out-Of-Bounds Read Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: High
      - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9608
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37774: HTTP: Adobe Acrobat Reader Out-Of-Bounds Read Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit an out-of-bounds read vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9609
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37775: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9610
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37776: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9611
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37778: HTTP: Adobe Acrobat Reader Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a memory corruption vulnerability in Adobe Acrobat Reader.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-9596
      - Classification: Vulnerability - Other
      - Protocol: HTTP
      - Platform: Multi-Platform Client Application

    37782: TCP: SaltStack Salt Directory Traversal Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Vulnerabilities
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a directory traversal vulnerability in SaltStack Salt.
      - Deployment: Not enabled by default in any deployment.
      - References:
        - Common Vulnerabilities and Exposures: CVE-2020-11652
      - Classification: Vulnerability - Input Validation (Command injection, XSS, SQL injection, etc)
      - Protocol: HTTP
      - Platform: Multi-Platform Server Application or Service

  Modified Filters (logic changes):
    * = Enabled in Default deployments

    * 34034: HTTP: Adobe Bridge CC PCX File Parsing Heap-based Buffer Overflow Vulnerability (ZDI-19-345)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "34034: ZDI-CAN-7596: Zero Day Initiative Vulnerability (Adobe Bridge)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    35098: RPC: Advantech WebAccess viewsrv SQLGetData Untrusted Pointer Dereference Vulnerability (ZDI-19-623)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "35098: ZDI-CAN-8119: Zero Day Initiative Vulnerability (Advantech WebAccess)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    35170: HTTP: Fuji Electric Alpha7 PC Loader A7P File Parsing Out-Of-Bounds Read Vulnerability (ZDI-19-517)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "35170: ZDI-CAN-8030: Zero Day Initiative Vulnerability (Fuji Electric Alpha7)".
      - Severity changed from "Critical" to "High".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    35400: HTTP: Rockwell Automation Arena Simulation DOE File Parsing Use-After-Free Vulnerability(ZDI-19-696)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "35400: ZDI-CAN-8015: Zero Day Initiative Vulnerability (Rockwell Automation Arena Simulation)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    35409: HTTP: Adobe Photoshop PostScript put Buffer Overflow Vulnerability (ZDI-19-736)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "35409: ZDI-CAN-8549: Zero Day Initiative Vulnerability (Adobe Photoshop)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36734: HTTP: Advantech WebAccess/NMS Login SQL Injection Vulnerability (ZDI-20-374, ZDI-20-380)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36734: ZDI-CAN-9567,9573: Zero Day Initiative Vulnerability (Advantech WebAccess/NMS)".
      - Severity changed from "Critical" to "High".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36745: HTTP: Advantech WebAccess/NMS download.jsp Directory Traversal Vulnerability (ZDI-20-384)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36745: ZDI-CAN-9577: Zero Day Initiative Vulnerability (Advantech WebAccess/NMS)".
      - Severity changed from "Critical" to "High".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36748: HTTP: Advantech WebAccess/NMS forcedScanDevice SQL Injection Vulnerability (ZDI-20-393)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36748: ZDI-CAN-9587: Zero Day Initiative Vulnerability (Advantech WebAccess/NMS)".
      - Severity changed from "Critical" to "High".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36749: HTTP: Advantech WebAccess/NMS TopogroupeditAction SQL Injection (ZDI-20-388, ZDI-20-390)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36749: ZDI-CAN-9581,9583: Zero Day Initiative Vulnerability (Advantech WebAccess/NMS)".
      - Severity changed from "Critical" to "High".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36894: HTTP: Cisco UCS Director downloadFile Directory Traversal Vulnerability (ZDI-20-538)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36894: ZDI-CAN-9557: Zero Day Initiative Vulnerability (Cisco UCS)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36897: HTTP: Microsoft Windows JET Database Engine Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36897: ZDI-CAN-10056: Zero Day Initiative Vulnerability (Microsoft JET Database)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36900: HTTP: Microsoft JET Database Engine Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36900: ZDI-CAN-10060: Zero Day Initiative Vulnerability (Microsoft JET Database)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36901: HTTP: Microsoft Windows JET Database Engine Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36901: ZDI-CAN-10064: Zero Day Initiative Vulnerability (Microsoft JET Database)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36934: HTTP: Advantech WebAccess/NMS DBUtil SQL Injection Vulnerability (ZDI-20-394)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36934: ZDI-CAN-9588: Zero Day Initiative Vulnerability (Advantech WebAccess/SCADA)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36935: HTTP: Advantech WebAccess/NMS DBUtil SQL Injection Vulnerability (ZDI-20-395)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36935: ZDI-CAN-9589: Zero Day Initiative Vulnerability (Advantech WebAccess/SCADA)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    36939: HTTP: Advantech WebAccess/NMS DBUtil SQL Injection Vulnerability (ZDI-20-396)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36939: ZDI-CAN-9601: Zero Day Initiative Vulnerability (Advantech WebAccess/SCADA)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    * 36976: HTTP: Microsoft Internet Explorer CWMPErrorDlg Use-After-Free Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "36976: ZDI-CAN-10103: Zero Day Initiative Vulnerability (Microsoft Internet Explorer)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37051: HTTP: Microsoft Windows JET Database Engine Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37051: ZDI-CAN-10039: Zero Day Initiative Vulnerability (Microsoft JET Database)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37245: HTTP: Microsoft Windows Media Player HEVC Stream Parsing Buffer Overflow Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37245: ZDI-CAN-10516: Zero Day Initiative Vulnerability (Microsoft Windows Media Player)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37251: HTTP: Eaton HMiSoft VU3 File Parsing wDescribeLen Out-Of-Bounds Read Vulnerability (ZDI-20-492)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37251: ZDI-CAN-10417: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Severity changed from "Critical" to "High".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37255: HTTP: Eaton HMiSoft VU3 File Parsing Buffer Overflow Vulnerability (ZDI-20-489)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37255: ZDI-CAN-10340: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37267: HTTP: Eaton HMiSoft VU3 File Parsing LinkSize Buffer Overflow Vulnerability (ZDI-20-488)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37267: ZDI-CAN-10167: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37281: HTTP: Eaton HMiSoft VU3 File Parsing wTDateLen Buffer Overflow Vulnerability (ZDI-20-478)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37281: ZDI-CAN-10153: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37283: HTTP: Eaton HMiSoft VU3 File Parsing wTextLen Buffer Overflow Vulnerability (ZDI-20-479)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37283: ZDI-CAN-10157: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37287: HTTP: Eaton HMiSoft VU3 File Parsing wMailContentLen Buffer Overflow Vulnerability (ZDI-20-480)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37287: ZDI-CAN-10158: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37288: HTTP: Eaton HMiSoft VU3 File Parsing wMailCopyToLen Buffer Overflow Vulnerability (ZDI-20-481)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37288: ZDI-CAN-10159: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37291: HTTP: Eaton HMiSoft VU3 File Parsing wMailToLen Buffer Overflow Vulnerability (ZDI-20-482)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37291: ZDI-CAN-10160: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37292: HTTP: Eaton HMiSoft VU3 File Parsing wMessageLen Buffer Overflow Vulnerability (ZDI-20-483)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37292: ZDI-CAN-10161: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37293: HTTP: Eaton HMiSoft VU3 File Parsing wMailBlindCopyToLen Buffer Overflow Vulnerability (ZDI-20-484)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37293: ZDI-CAN-10162: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37294: HTTP: Eaton HMiSoft VU3 File Parsing wKPFStringLen Buffer Overflow Vulnerability (ZDI-20-475)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37294: ZDI-CAN-10163: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37295: HTTP: Eaton HMiSoft VU3 File Parsing wTitleTextLen Buffer Overflow Vulnerability (ZDI-20-485)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37295: ZDI-CAN-10164: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37296: HTTP: Eaton HMiSoft VU3 File Parsing GifName Buffer Overflow Vulnerability (ZDI-20-486)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37296: ZDI-CAN-10165: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37297: HTTP: Eaton HMiSoft VU3 File Parsing LinkSize Buffer Overflow Vulnerability (ZDI-20-487)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37297: ZDI-CAN-10166: Zero Day Initiative Vulnerability (Eaton HMiSoft)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37334: HTTP: Adobe Acrobat Reader DC JPEG File Parsing Out-Of-Bounds Write Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37334: ZDI-CAN-10106: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37377: HTTP: Microsoft Windows Media Player HEVC Stream Parsing Out-Of-Bounds Write Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37377: ZDI-CAN-10569: Zero Day Initiative Vulnerability (Microsoft Windows Media Player)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37378: HTTP: Microsoft Windows Media Player HEVC Stream Parsing Out-Of-Bounds Write Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37378: ZDI-CAN-10566: Zero Day Initiative Vulnerability (Microsoft Windows Media Player)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37422: HTTP: Adobe Reader Field Use-After-Free Vulnerability (Pwn2Own)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37422: PWN2OWN ZDI-CAN-10784: Zero Day Initiative Vulnerability (Adobe Reader)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37595: HTTP: Adobe Acrobat Reader DC JPEG2000 Buffer Overflow Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37595: ZDI-CAN-10822: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    37612: HTTP: Microsoft Windows EMR_SETDIBITSTODEVICE Out-Of-Bounds Read Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "37612: ZDI-CAN-10743: Zero Day Initiative Vulnerability (Microsoft Windows)".
      - Severity changed from "Critical" to "High".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

  Modified Filters (metadata changes only):
    * = Enabled in Default deployments

    33863: HTTP: HPE IMC perfSelectTask Language Injection Vulnerability (ZDI-19-335, ZDI-20-180)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "33863: HTTP: HPE Intelligent Management Center perfSelectTask Language Injection Vulnerability (ZDI-19-335)".
      - Description updated.
      - Vulnerability references updated.

    * 37264: HTTP: Google Chrome JSCreate Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Vulnerability references updated.

  Removed Filters:

    4858: Backdoor: C99shell PHP Backdoor Communication
      - IPS Version: 1.0.0 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    5086: Backdoor: C99shell PHP Backdoor Communication
      - IPS Version: 3.0.0 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    5120: Backdoor: R57shell PHP Backdoor Communication
      - IPS Version: 1.0.0 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    12411: Backdoor: Packed Web Shell by Orb (WSO)
      - IPS Version: 1.0.0 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    17155: TCP: C99shell PHP Script Transfer
      - IPS Version: 1.0.0 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
  
Top of the Page
Premium
Internal
Partner
Rating:
Category:
Configure; Troubleshoot; Deploy
Solution Id:
TP000253106
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.