Release notes for update package 1301-5242

This update package improves the detection capabilities of the Forcepoint NGFW system.

RELEASE DATE:    Tuesday December 08, 2020
MD5 CHECKSUM:    5f396247a13cb1f436bcdab2fdb341e0
SHA1 CHECKSUM:    8acee53210d0073815b2011798f424776cf0712c
SHA256 CHECKSUM:    7ea80a709dc3e73147bf1493ae860dec896f1125b10a797328c317e03d87cbb8

UPDATE CRITICALITY:    HIGH

MINIMUM SOFTWARE VERSIONS
- Forcepoint NGFW Security Management Center:    6.5.1.10631
- Forcepoint NGFW:    5.5.1.9848

List of detected attacks in this update package:

Risk levelDescriptionReferenceVulnerability
High     An attempt to exploit a vulnerability in Microsoft Windows detected     CVE-2020-17140     Microsoft-Windows-Vulnerability-CVE-2020-17140

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

TCP SMB Client Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Microsoft-Windows-Vulnerability-CVE-2020-17140 CVE-2020-17140 SMB-TCP_Microsoft-Windows-Vulnerability-CVE-2020-17140 Suspected Compromise

Updated detected attacks:

HTTP Normalized Request-Line

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High TP-Link-Cloud-Cameras-NCXXX-Bonjour-Command-Injection CVE-2020-12109 HTTP_CRL-TP-Link-Cloud-Cameras-NCXXX-Bonjour-Command-Injection Suspected Compromise
Name: HTTP_CS-TP-Link-Cloud-Cameras-NCXXX-Bonjour-Command-Injection->HTTP_CRL-TP-Link-Cloud-Cameras-NCXXX-Bonjour-Command-Injection
Category tag group TCP Correlation Dependency Group removed
Context has changed from HTTP Client Stream to HTTP Normalized Request-Line

LIST OF OTHER CHANGES:

New objects:

TypeName
CategoryMS2020-12
IPListIncapsula
SituationIP_Incapsula

Updated objects:

TypeNameChanges
IPListÅland
IPListBulgaria
IPListMauritius
IPListIceland
IPListIndia
IPListBurkina Faso
IPListGuinea-Bissau
IPListCyprus
IPListPalau
IPListFrance
IPListSint Maarten
IPListGabon
IPListSouth Korea
IPListAmazon AMAZON ap-south-1
IPListCosta Rica
IPListBelgium
IPListNiue
IPListTanzania
IPListLebanon
IPListBotswana
IPListTurkey
IPListHeard Island and McDonald Islands
IPListLiberia
IPListMongolia
IPListAmazon AMAZON us-west-1
IPListRéunion
IPListSlovakia
IPListUkraine
IPListKenya
IPListEthiopia
IPListMorocco
IPListBotnet IP Address List
IPListGuernsey
IPListUnited States
IPListRepublic of Lithuania
IPListBelize
IPListGermany
IPListGambia
IPListEstonia
IPListMarshall Islands
IPListCameroon
IPListBouvet Island
IPListGrenada
IPListCanada
IPListSt Kitts and Nevis
IPListRwanda
IPListEritrea
IPListEquatorial Guinea
IPListNicaragua
IPListBarbados
IPListMadagascar
IPListBolivia
IPListTOR relay nodes IP Address List
IPListSouth Africa
IPListU.S. Virgin Islands
IPListEast Timor
IPListSaint Martin
IPListSri Lanka
IPListCambodia
IPListSaint Helena
IPListCayman Islands
IPListArgentina
IPListPoland
IPListPapua New Guinea
IPListJapan
IPListMexico
IPListBermuda
IPListPortugal
IPListSierra Leone
IPListUganda
IPListParaguay
IPListAmazon EC2
IPListWestern Sahara
IPListFiji
IPListMayotte
IPListAmazon AMAZON cn-north-1
IPListPeru
IPListNorth Korea
IPListTunisia
IPListLatvia
IPListNauru
IPListLuxembourg
IPListVenezuela
IPListGreenland
IPListAkamai Servers
IPListU.S. Minor Outlying Islands
IPListHonduras
IPListSvalbard and Jan Mayen
IPListTokelau
IPListBhutan
IPListIndonesia
IPListUnited Arab Emirates
IPListCuba
IPListSpain
IPListPuerto Rico
IPListMontserrat
IPListGuadeloupe
IPListSouth Sudan
IPListBritish Indian Ocean Territory
IPListNigeria
IPListThailand
IPListMalicious Site IP Address List
IPListLesotho
IPListCuraçao
IPListItaly
IPListNorth Macedonia
IPListEcuador
IPListLibya
IPListGuatemala
IPListMaldives
IPListSudan
IPListSouth Georgia and the South Sandwich Islands
IPListBrazil
IPListDominica
IPListAlbania
IPListAmazon AMAZON eu-central-1
IPListTrinidad and Tobago
IPListEgypt
IPListPanama
IPListIsrael
IPListSomalia
IPListRussia
IPListChile
IPListAustria
IPListMyanmar
IPListAntarctica
IPListAnguilla
IPListHungary
IPListGreece
IPListYemen
IPListHaiti
IPListSerbia
IPListTurkmenistan
IPListGeorgia
IPListNew Caledonia
IPListAlgeria
IPListPakistan
IPListVatican City
IPListSuriname
IPListAngola
IPListKyrgyzstan
IPListFinland
IPListDominican Republic
IPListAmazon AMAZON sa-east-1
IPListCongo Republic
IPListGuyana
IPListSaint Lucia
IPListIran
IPListNiger
IPListCocos [Keeling] Islands
IPListBahamas
IPListBonaire, Sint Eustatius, and Saba
IPListAzerbaijan
IPListSwitzerland
IPListBangladesh
IPListNorfolk Island
IPListCabo Verde
IPListBelarus
IPListOman
IPListIvory Coast
IPListKuwait
IPListVanuatu
IPListSlovenia
IPListEl Salvador
IPListChristmas Island
IPListFrench Southern Territories
IPListKazakhstan
IPListMartinique
IPListSolomon Islands
IPListRomania
IPListSyria
IPListJamaica
IPListFederated States of Micronesia
IPListTOR exit nodes IP Address List
IPListAmazon ROUTE53
IPListFalkland Islands
IPListUzbekistan
IPListHong Kong
IPListCroatia
IPListKosovo
IPListDR Congo
IPListSaint Vincent and the Grenadines
IPListSão Tomé and Príncipe
IPListIraq
IPListSweden
IPListFrench Guiana
IPListUnited Kingdom
IPListMalta
IPListSingapore
IPListBurundi
IPListGhana
IPListMalawi
IPListHashemite Kingdom of Jordan
IPListIreland
IPListNepal
IPListAndorra
IPListMacao
IPListVietnam
IPListJersey
IPListChina
IPListTogo
IPListZimbabwe
IPListAmazon AMAZON
IPListGibraltar
IPListNetherlands
IPListBenin
IPListBosnia and Herzegovina
IPListTaiwan
IPListMozambique
IPListNamibia
IPListFacebook Servers
IPListAustralia
IPListZambia
IPListMauritania
IPListMonaco
IPListComoros
IPListBritish Virgin Islands
IPListSaint Barthélemy
IPListArmenia
IPListSaint Pierre and Miquelon
IPListCentral African Republic
IPListIsle of Man
IPListMali
IPListFaroe Islands
IPListMontenegro
IPListQatar
IPListChad
IPListDenmark
IPListGuinea
IPListColombia
IPListWallis and Futuna
IPListAntigua and Barbuda
IPListNorway
IPListFrench Polynesia
IPListUruguay
IPListKiribati
IPListGuam
IPListTuvalu
IPListNew Zealand
IPListEswatini
IPListMalaysia
IPListRepublic of Moldova
IPListCook Islands
IPListPitcairn Islands
IPListCzechia
IPListAmazon EC2 cn-north-1
IPListSamoa
IPListTurks and Caicos Islands
IPListBrunei
IPListDjibouti
IPListBahrain
IPListAfghanistan
IPListTajikistan
IPListPalestine
IPListPhilippines
IPListAruba
IPListSan Marino
IPListLaos
IPListSenegal
IPListTonga
IPListSeychelles
IPListAmerican Samoa
IPListSaudi Arabia
IPListNorthern Mariana Islands
IPListLiechtenstein

HOW TO IMPORT AND ACTIVATE THE DYNAMIC UPDATE PACKAGE

  1. Download the dynamic update package, then make sure that the checksums for the original files and the files that you have downloaded match.
  2. In the Management Client, select Menu > File > Import > Import Update Packages.
  3. Browse to the file, select it, then click Import.
  4. Select  Configuration, then browse to Administration > Other Elements > Updates.
  5. Right-click the imported dynamic update package, then select Activate.
  6. When the activation is finished, refresh the policy on all NGFW Engines. If your policy uses a custom template, you might need to edit the policy.

DISCLAIMER AND COPYRIGHT

Copyright © 2020 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.