This update package improves the detection capabilities of the Forcepoint NGFW system.
Risk | Vulnerability/Situation | References | Related Fingerprint | Situation Type | Change Description |
High |
Apache-Mod-Imagemap-Module-Cross-Site-Scripting |
CVE-2007-5000 |
HTTP_CSU-Script-Tag-In-URI |
Potential Compromise |
Description has changed |
Attacker: none->connection_destination |
Victim: none->connection_source |
Category tag group CVE2007 added |
|
High |
HP-Intelligent-Management-Center-Reporting-Information-Disclosure |
No CVE/CAN |
HTTP_CSU-HP-IMC-Uam-Acmservletdownload-Information-Disclosure |
Suspected Compromise |
Description has changed |
Category tag group CVE2018 added |
Category tag group CVE2019 added |
|
Low |
HTTP-Domino-Access |
No CVE/CAN |
HTTP_CSU-IBM-Domino-Access |
Potential Probe |
Detection mechanism updated |
|
High |
VBulletin-Routestring-Unauthenticated-Remote-Code-Execution |
No CVE/CAN |
HTTP_CSU-VBulletin-Routestring-Unauthenticated-Remote-Code-Execution |
Potential Compromise |
Fingerprint regexp changed |
|
High |
Jenkins-Plugin-Resources-Directory-Traversal |
CVE-2018-6356 |
HTTP_CSU-Jenkins-Plugin-Resources-Directory-Traversal |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
Dell-EMC-Storage-Manager-EMConfigmigration-Servlet-Directory-Traversal |
CVE-2017-14384 |
HTTP_CSU-Dell-EMC-Storage-Manager-EMConfigmigration-Servlet-Directory-Traversal |
Suspected Compromise |
Fingerprint regexp changed |
|
Critical |
Pulse-Secure-SSL-VPN-Pre-Auth-Arbitrary-File-Reading |
CVE-2019-11510 |
HTTP_CSU-Pulse-Secure-SSL-VPN-Pre-Auth-Arbitrary-File-Reading |
Compromise |
Fingerprint regexp changed |
|
High |
Openemr-C_document.class.php-Patient_Id-Cross-Site-Scripting |
CVE-2019-3963 |
HTTP_CSU-Openemr-C_document.class.php-View_Action-Doc_Id-Cross-Site-Scripting |
Suspected Compromise |
Description has changed |
Fingerprint regexp changed |
|
High |
Zoho-Manageengine-Opmanager-Fluidicv2-UI-Directory-Traversal |
CVE-2020-12116 |
HTTP_CSU-Zoho-Manageengine-Opmanager-Fluidicv2-UI-Directory-Traversal |
Suspected Compromise |
Description has changed |
Fingerprint regexp changed |
|
Low |
HTTP-ColdFusion-Exprcalc-File-Disclosure |
CVE-1999-0455 |
HTTP_CSU-ColdFusion-Path-Information-Disclosure |
Potential Disclosure |
Description has changed |
Category tag group CVE1999 added |
|
High |
Keysight-N6854a-And-N6841a-RF-Sensor-Directory-Traversal |
CVE-2022-1661 |
HTTP_CSU-Keysight-N6854a-And-N6841a-RF-Sensor-Directory-Traversal |
Suspected Compromise |
Fingerprint regexp changed |
|
Low |
Gogs-Git-Endpoints-Directory-Traversal |
CVE-2022-1993 |
HTTP_CSU-Gogs-Git-Endpoints-Directory-Traversal |
Potential Disclosure |
Fingerprint regexp changed |
|
High |
Ivanti-Avalanche-Smartdeviceserver-Uploadfile-Directory-Traversal |
CVE-2022-36981 |
HTTP_CSU-Ivanti-Avalanche-Smartdeviceserver-Uploadfile-Directory-Traversal |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
D-Link-DSL-2750B-Command-Injection |
CVE-2016-20017 |
HTTP_CSU-D-Link-DSL-2750B-Command-Injection |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
Confluence-Access-Control-Vulnerability-CVE-2023-22515 |
CVE-2023-22515 |
HTTP_CSU-Confluence-Access-Control-Vulnerability-CVE-2023-22515 |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
HTTP-WebConnect-Wcp-User-Directory-Traversal |
CVE-2004-0465 |
HTTP_CSU-WebConnect-Wcp-User-Directory-Traversal |
Potential Compromise |
Fingerprint regexp changed |
|
Risk | Vulnerability/Situation | References | Related Fingerprint | Situation Type | Change Description |
High |
Novell-Remote-Manager-Off-By-One-Denial-Of-Service |
No CVE/CAN |
HTTP_CSH-Novell-Remote-Manager-Off-By-One-Denial-Of-Service |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
Netgate-Pfsense-Pfblockerng-Host-Command-Injection |
CVE-2022-31814 |
HTTP_CSH-Netgate-Pfsense-Pfblockerng-Host-Command-Injection |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
SaveNow-Software |
No CVE/CAN |
HTTP_CSH-SaveNow-Activity |
Spyware, Malware and Adware |
Fingerprint regexp changed |
|
High |
HTTP-Apache-Host-Header-Default-Error-Page-XSS |
CVE-2002-0840 |
HTTP_CSH-Apache-Host-Header-Default-Error-Page-XSS |
Suspected Disclosure |
Fingerprint regexp changed |
|
High |
HTTP-Apache-Host-Header-Default-Error-Page-XSS |
CVE-2002-0840 |
HTTP_CSH-Script-In-Host-Header |
Attack Related Anomalies |
Fingerprint regexp changed |
|
Low |
HTTP-Novell-eDirectory-HTTP-Server-Redirection-Buffer-Overflow |
CVE-2006-5478 |
HTTP_CSH-Overly-Long-Host-Header-Field |
Potential Compromise |
Fingerprint regexp changed |
|
Low |
IP-Address-As-HTTP-Host |
No CVE/CAN |
HTTP_CSH-IP-Address-As-HTTP-Host |
Protocol Information |
Fingerprint regexp changed |
|
High |
HTTP-Apache-Portable-Runtime-Apr-Psprintf-Long-String-Vulnerability |
CVE-2003-0245 |
HTTP_CSH-Oversized-Host-Header-Field |
Attack Related Anomalies |
Fingerprint regexp changed |
|
Low |
UUSee-Streaming-Media |
No CVE/CAN |
HTTP_CSH-UUSee-Activity |
Streaming Protocols |
Fingerprint regexp changed |
|
High |
Squid-HTTP-Host-Header-Port-Handling-Denial-Of-Service |
CVE-2013-4123 |
HTTP_CSH-Squid-HTTP-Host-Header-Port-Handling-Denial-Of-Service |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
Lighttpd-Host-Header-Mod_mysql_vhost-SQL-Injection |
CVE-2014-2323 |
HTTP_CSH-Lighttpd-Host-Header-Multiple-Vulnerabilities |
Suspected Compromise |
Fingerprint regexp changed |
|
Critical |
Furtims-Parent-Nullptr-Host-Field |
No CVE/CAN |
HTTP_CSH-Furtims-Parent-Nullptr-Host-Field |
Successful Attacks |
Fingerprint regexp changed |
|
High |
CMS-Made-Simple-Cache-Poisoning |
CVE-2016-2784 |
HTTP_CSH-CMS-Made-Simple-Cache-Poisoning |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
Felismus-Malware |
No CVE/CAN |
HTTP_CSH-Felismus-Malware-Request |
Botnet |
Fingerprint regexp changed |
|
High |
Squid-Proxy-HTTP-Request-Processing-Buffer-Overflow |
CVE-2020-8450 |
HTTP_CRH-Squid-Proxy-HTTP-Request-Processing-Buffer-Overflow |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
Solarwinds-SunBurst-Traffic |
No CVE/CAN |
HTTP_CSH-SunBurst-Backdoor-Traffic |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
SNIProxy-New_address-Stack-Buffer-Overflow |
CVE-2023-25076 |
HTTP_CSH-SNIProxy-New_address-Stack-Buffer-Overflow |
Suspected Compromise |
Fingerprint regexp changed |
|
Risk | Vulnerability/Situation | References | Related Fingerprint | Situation Type | Change Description |
High |
Geutebruck-Multiple-RCE-CVE-2021-335xx |
CVE-2021-33543 |
HTTP_CRL-Geutebruck-Multiple-RCE-CVE-2021-335xx |
Suspected Compromise |
Name: HTTP_CS-Geutebruck-Multiple-RCE-CVE-2021-335xx->HTTP_CRL-Geutebruck-Multiple-RCE-CVE-2021-335xx |
Category tag group TCP Correlation Dependency Group removed |
Context has changed from HTTP Client Stream to HTTP Normalized Request-Line |
|
High |
Netis-WF2419-Remote-Code-Execution-CVE-2019-19356 |
CVE-2019-19356 |
HTTP_CRL-Netis-WF2419-Remote-Code-Execution-CVE-2019-19356 |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
Papercut-Improper-Access-Control-Vulnerability-CVE-2023-27350 |
CVE-2023-27350 |
HTTP_CRL-Papercut-Improper-Access-Control-Vulnerability-CVE-2023-27350 |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
TP-Link-Archer-AX21-Command-Injection-CVE-2023-1389 |
CVE-2023-1389 |
HTTP_CRL-TP-Link-Archer-AX21-Command-Injection-CVE-2023-1389 |
Suspected Compromise |
Fingerprint regexp changed |
|
Type | Name | Changes |
Situation | NTLM IWA Support User-Agent |
Application detection context content changed |
|
Situation | HTTP_CSU-Shared-Variables |
|
Situation | HTTP_CSU-Windows-Base64-Decode-Command-In-URI |
|
Situation | HTTP_CSU-Responsive-Filemanager-Ajax_calls.php-Information-Disclosure |
Description has changed |
Attacker: connection_source->none |
Victim: connection_destination->none |
Category tag situation Obsolete added |
Category tag os Any Operating System removed |
Category tag hardware Any Hardware removed |
Category tag application Responsive File Manager removed |
Category tag group CVE2018 removed |
Category tag os_not_specific Any Operating System not specific removed |
Category tag situation Suspected Compromise removed |
Category tag group HTTP Correlation Dependency Group removed |
Category tag group TCP Correlation Dependency Group removed |
Category tag group HTTP URI Correlation Dependency Group removed |
Category tag group Severity over 4 Correlation Dependency Group removed |
Category tag group TCP Client Traffic removed |
|
Situation | HTTP_CSU-Openemr-Ajax_Download.php-Directory-Traversal |
Description has changed |
Attacker: connection_source->none |
Victim: connection_destination->none |
Category tag situation Obsolete added |
Category tag os Any Operating System removed |
Category tag hardware Any Hardware removed |
Category tag application OpenEMR Development Team OpenEMR removed |
Category tag group CVE2019 removed |
Category tag os_not_specific Any Operating System not specific removed |
Category tag situation Suspected Compromise removed |
Category tag group HTTP Correlation Dependency Group removed |
Category tag group TCP Correlation Dependency Group removed |
Category tag group HTTP URI Correlation Dependency Group removed |
Category tag group Severity over 4 Correlation Dependency Group removed |
Category tag group TCP Client Traffic removed |
|
Situation | HTTP_CSU-Openemr-C_document.class.php-Patient_Id-Cross-Site-Scripting |
Description has changed |
Attacker: connection_destination->none |
Victim: connection_source->none |
Category tag situation Obsolete added |
Category tag os Any Operating System removed |
Category tag hardware Any Hardware removed |
Category tag application OpenEMR Development Team OpenEMR removed |
Category tag group CVE2019 removed |
Category tag os_not_specific Any Operating System not specific removed |
Category tag situation Suspected Compromise removed |
Category tag group HTTP Correlation Dependency Group removed |
Category tag group TCP Correlation Dependency Group removed |
Category tag group HTTP URI Correlation Dependency Group removed |
Category tag group Severity over 4 Correlation Dependency Group removed |
Category tag group TCP Client Traffic removed |
|
Situation | HTTP_CSU-Pulse-Secure-VPN-Arbitrary-File-Disclosure |
Description has changed |
Attacker: connection_source->none |
Victim: connection_destination->none |
Category tag situation Obsolete added |
Category tag os Unix removed |
Category tag os Linux removed |
Category tag hardware Any Hardware removed |
Category tag application Pulse Secure VPN removed |
Category tag group CVE2019 removed |
Category tag os_not_specific Unix not specific removed |
Category tag os_not_specific Linux not specific removed |
Category tag situation Suspected Compromise removed |
Category tag group HTTP Correlation Dependency Group removed |
Category tag group TCP Correlation Dependency Group removed |
Category tag group HTTP URI Correlation Dependency Group removed |
Category tag group Severity over 4 Correlation Dependency Group removed |
Category tag group TCP Client Traffic removed |
Fingerprint regexp changed |
|
Situation | HTTP_CSU-Zoho-Manageengine-Opmanager-Cachestart-Directory-Traversal |
Description has changed |
Attacker: connection_source->none |
Victim: connection_destination->none |
Category tag situation Obsolete added |
Category tag os Any Operating System removed |
Category tag hardware Any Hardware removed |
Category tag application Zoho Corporation ManageEngine OpManager removed |
Category tag group CVE2020 removed |
Category tag os_not_specific Any Operating System not specific removed |
Category tag situation Suspected Compromise removed |
Category tag group HTTP Correlation Dependency Group removed |
Category tag group TCP Correlation Dependency Group removed |
Category tag group HTTP URI Correlation Dependency Group removed |
Category tag group Severity over 4 Correlation Dependency Group removed |
Category tag group TCP Client Traffic removed |
|
Situation | HTTP_CSH-Shared-Variables |
Fingerprint regexp changed |
|
Situation | HTTP_CSH-Empty-Host-Header |
Fingerprint regexp changed |
|
Situation | HTTP_CSU-Apache-Mod-Imagemap-Module-Cross-Site-Scripting |
Description has changed |
Attacker: connection_destination->none |
Victim: connection_source->none |
Category tag situation Obsolete added |
Category tag os Any Operating System removed |
Category tag hardware Any Hardware removed |
Category tag application Apache removed |
Category tag group CVE2007 removed |
Category tag os_not_specific Any Operating System not specific removed |
Category tag application_not_specific Apache not specific removed |
Category tag situation Potential Compromise removed |
Category tag group HTTP Correlation Dependency Group removed |
Category tag group TCP Correlation Dependency Group removed |
Category tag group HTTP URI Correlation Dependency Group removed |
Category tag group Severity over 4 Correlation Dependency Group removed |
Category tag group TCP Client Traffic removed |
|
Situation | HTTP_CS-Shared-Variables-For-Client-Stream-Context |
Fingerprint regexp changed |
|
Situation | HTTP_CSU-Apache-Tomcat-Servlet-Engine-Directory-Traversal |
Description has changed |
Attacker: connection_source->none |
Victim: connection_destination->none |
Category tag situation Obsolete added |
Category tag os Any Operating System removed |
Category tag hardware Any Hardware removed |
Category tag application Apache Tomcat removed |
Category tag group CVE2007 removed |
Category tag os_not_specific Any Operating System not specific removed |
Category tag situation Potential Disclosure removed |
Category tag group TCP Client Traffic removed |
|
Situation | HTTP_CSH-Suspicious-Host-Header |
Fingerprint regexp changed |
|
Application | ILoveIM |
|
Application | SopCast |
|
Application | Baidu-Hi |
|
Application | Nbc.com-Streaming |
|
Application | Rubicon-Project |
|
Application | TOR |
|
Application | NordVPN |
|
IPList | Yemen |
|
IPList | Iraq |
|
IPList | Saudi Arabia |
|
IPList | Iran |
|
IPList | Cyprus |
|
IPList | Syria |
|
IPList | Armenia |
|
IPList | DR Congo |
|
IPList | Uganda |
|
IPList | Seychelles |
|
IPList | Jordan |
|
IPList | Lebanon |
|
IPList | United Arab Emirates |
|
IPList | Israel |
|
IPList | Turkey |
|
IPList | Egypt |
|
IPList | Greece |
|
IPList | Estonia |
|
IPList | Latvia |
|
IPList | Lithuania |
|
IPList | Moldova |
|
IPList | Belarus |
|
IPList | Finland |
|
IPList | Åland Islands |
|
IPList | Ukraine |
|
IPList | Hungary |
|
IPList | Bulgaria |
|
IPList | Poland |
|
IPList | Romania |
|
IPList | Zimbabwe |
|
IPList | Zambia |
|
IPList | Mauritius |
|
IPList | Eswatini |
|
IPList | South Africa |
|
IPList | Mayotte |
|
IPList | Afghanistan |
|
IPList | Pakistan |
|
IPList | Bangladesh |
|
IPList | Sri Lanka |
|
IPList | Bhutan |
|
IPList | India |
|
IPList | British Indian Ocean Territory |
|
IPList | Nepal |
|
IPList | Myanmar |
|
IPList | Kazakhstan |
|
IPList | Vietnam |
|
IPList | Thailand |
|
IPList | Indonesia |
|
IPList | Taiwan |
|
IPList | Philippines |
|
IPList | Malaysia |
|
IPList | China |
|
IPList | Hong Kong |
|
IPList | Cambodia |
|
IPList | South Korea |
|
IPList | Japan |
|
IPList | Singapore |
|
IPList | Russia |
|
IPList | Mongolia |
|
IPList | Australia |
|
IPList | Federated States of Micronesia |
|
IPList | Papua New Guinea |
|
IPList | Tuvalu |
|
IPList | Nauru |
|
IPList | Vanuatu |
|
IPList | Norfolk Island |
|
IPList | New Zealand |
|
IPList | Portugal |
|
IPList | Liberia |
|
IPList | Ivory Coast |
|
IPList | Nigeria |
|
IPList | Guinea-Bissau |
|
IPList | Mauritania |
|
IPList | Gibraltar |
|
IPList | Gambia |
|
IPList | Niger |
|
IPList | Tunisia |
|
IPList | Spain |
|
IPList | Morocco |
|
IPList | Algeria |
|
IPList | Denmark |
|
IPList | Iceland |
|
IPList | United Kingdom |
|
IPList | Switzerland |
|
IPList | Sweden |
|
IPList | Netherlands |
|
IPList | Austria |
|
IPList | Belgium |
|
IPList | Germany |
|
IPList | Luxembourg |
|
IPList | Ireland |
|
IPList | France |
|
IPList | Liechtenstein |
|
IPList | Guernsey |
|
IPList | Slovakia |
|
IPList | Czechia |
|
IPList | Norway |
|
IPList | Vatican City |
|
IPList | Italy |
|
IPList | Croatia |
|
IPList | Namibia |
|
IPList | Saint Pierre and Miquelon |
|
IPList | Greenland |
|
IPList | Brazil |
|
IPList | Falkland Islands |
|
IPList | Dominican Republic |
|
IPList | Martinique |
|
IPList | Anguilla |
|
IPList | Saint Lucia |
|
IPList | British Virgin Islands |
|
IPList | Montserrat |
|
IPList | Saint Martin |
|
IPList | Saint Barthélemy |
|
IPList | Guadeloupe |
|
IPList | Guatemala |
|
IPList | Honduras |
|
IPList | Nicaragua |
|
IPList | Costa Rica |
|
IPList | Venezuela |
|
IPList | Ecuador |
|
IPList | Colombia |
|
IPList | Panama |
|
IPList | Argentina |
|
IPList | Chile |
|
IPList | Bolivia |
|
IPList | Peru |
|
IPList | Mexico |
|
IPList | French Polynesia |
|
IPList | Kiribati |
|
IPList | Tokelau |
|
IPList | Wallis and Futuna |
|
IPList | Samoa |
|
IPList | Northern Mariana Islands |
|
IPList | Guam |
|
IPList | U.S. Virgin Islands |
|
IPList | Canada |
|
IPList | United States |
|
IPList | Palestine |
|
IPList | Serbia |
|
IPList | Antarctica |
|
IPList | Sint Maarten |
|
IPList | Curaçao |
|
IPList | Bonaire, Sint Eustatius, and Saba |
|
IPList | TOR exit nodes IP Address List |
|
IPList | Amazon AMAZON |
|
IPList | Amazon EC2 |
|
IPList | TOR relay nodes IP Address List |
|
IPList | Amazon AMAZON il-central-1 |
|
IPList | Botnet IP Address List |
|
IPList | Malicious Site IP Address List |
|
IPList | NordVPN Servers IP Address List |
|
IPList | Amazon AMAZON eu-central-1 |
|
IPList | Amazon MEDIA_PACKAGE_V2 |
|
IPList | Amazon AMAZON eu-west-1 |
|
IPList | Amazon AMAZON eu-west-3 |
|
IPList | Amazon EC2 eu-west-3 |
|
IPList | Amazon AMAZON us-east-1 |
|