Release notes for update package 1645-5242

This update package improves the detection capabilities of the Forcepoint NGFW system.

RELEASE DATE:    Monday October 30, 2023
MD5 CHECKSUM:    ca4d9f7f55c5b4c4ba746185be3b183c
SHA1 CHECKSUM:    d227b3dfabe2ca46e543dbbd69185e3816788415
SHA256 CHECKSUM:    1e0828762e39c708a9ae3a4bf3b4ab59344dd5b1e46b8aaf5c3f6aad1f3d6b0d

UPDATE CRITICALITY:    HIGH

MINIMUM SOFTWARE VERSIONS
- Forcepoint NGFW Security Management Center:    6.5.1.10631
- Forcepoint NGFW:    6.5.1.21108

List of detected attacks in this update package:

Risk levelDescriptionReferenceVulnerability
High     Attempt to exploit directory traversal vulnerability in Apache Tomcat detected     CVE-2007-0450     Apache-Tomcat-Servlet-Engine-Directory-Traversal
High     An attempt to exploit a vulnerability in Cisco SA520W detected     No CVE/CAN Cisco-SA520W-Security-Appliance-Directory-Traversal
High     An attempt to exploit a vulnerability in a D-Link DIR-2640 device detected     CVE-2023-32153     D-Link-DIR-2640-HNAP-EmailFrom-Command-Injection-Vulnerability
High     An overly long RTSP Host header detected     No CVE/CAN Overly-Long-RTSP-Host-Header
High     An attempt to exploit a vulnerability in Microsoft Windows detected     CVE-2023-28250     Microsoft-Windows-PGM-Handling-Remote-Code-Execution
High     An attempt to exploit a vulnerability in Microsoft Windows detected     CVE-2023-24940     Microsoft-Windows-Pragmatic-General-Multicast-Packet-Length-Integer-Underflow
High     An attempt to exploit a vulnerability in Tomcat AJP detected     CVE-2022-26377     TomcatAJP-Request-Smuggling-CVE-2022-26377

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

TCP Client Stream Unknown

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Overly-Long-RTSP-Host-Header No CVE/CAN Generic_CS-Overly-Long-RTSP-Host-Header Potential Compromise

HTTP Request URI

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Apache-Tomcat-Servlet-Engine-Directory-Traversal CVE-2007-0450 HTTP_CSU-Apache-Tomcat-Servlet-Engine-Directory-Traversal-2 Suspected Disclosure

HTTP Normalized Request-Line

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Cisco-SA520W-Security-Appliance-Directory-Traversal No CVE/CAN HTTP_CRL-Cisco-SA520W-Security-Appliance-Directory-Traversal Suspected Compromise
High D-Link-DIR-2640-HNAP-EmailFrom-Command-Injection-Vulnerability CVE-2023-32153 HTTP_CRL-D-Link-DIR-2640-HNAP-EmailFrom-Command-Injection-Vulnerability Suspected Compromise

Other Binary File Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High TomcatAJP-Request-Smuggling-CVE-2022-26377 CVE-2022-26377 File-Binary_TomcatAJP-Request-Smuggling Suspected Compromise

Generic IP Fingerprinting Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Microsoft-Windows-PGM-Handling-Remote-Code-Execution CVE-2023-28250 IPv4_Microsoft-Windows-PGM-Handling-Remote-Code-Execution Suspected Compromise
High Microsoft-Windows-Pragmatic-General-Multicast-Packet-Length-Integer-Underflow CVE-2023-24940 IPv4_Microsoft-Windows-Pragmatic-General-Multicast-Packet-Length-Integer-Underflow Suspected Denial of Service

Updated detected attacks:

HTTP Client Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High Cisco-Prime-Data-Center-Network-Manager-Fileupload-Arbitrary-File-Upload CVE-2019-1620 HTTP_CS-Cisco-Prime-Data-Center-Network-Manager-Fileupload-Arbitrary-File-Upload Suspected Compromise
Fingerprint regexp changed

TCP Client Stream Unknown

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High RealNetworks-Helix-Server-RTSP-Set-Parameters-Request-DoS CVE-2009-2533 Generic_CS-RealNetworks-Helix-Server-RTSP-Set-Parameters-Request-DoS Potential Compromise
Fingerprint regexp changed

TCP Server Stream Unknown

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High Novell-Groupwise-Messenger-HTTP-Response-Handling-Stack-Overflow CVE-2008-2703 Generic_SS-Novell-Groupwise-Messenger-HTTP-Response-Handling-Stack-Overflow Suspected Compromise
Severity: 2->7
Category tag situation Suspected Compromise added
Category tag group TCP Correlation Dependency Group added
Category tag group Severity over 4 Correlation Dependency Group added
Category tag situation Possibly Unwanted Content removed
Fingerprint regexp changed

HTTP Request URI

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High Generic-HTTP-Exploit No CVE/CAN HTTP_CSU-Suspicious-Request Suspected Compromise
Detection mechanism updated
High Directory-Traversal No CVE/CAN HTTP_CSU-Potential-Dot-Dot-Slash-Directory-Traversal Potential Compromise
Fingerprint regexp changed

HTTP Request Header Line

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
Low HTTP-Apache-Chunked-Encoding-BOF CVE-2002-0392 HTTP_CSH-Transfer-Encoding-Chunked Protocol Information
Fingerprint regexp changed

HTTP Normalized Request-Line

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
Low HTTP-Novell-Groupwise-Messenger-HTTP-POST-Request-Invalid-Memory-Access CVE-2006-4511 HTTP_CRL-Novell-Groupwise-Messenger-HTTP-POST-Request-Memory-Access-Violation Potential Denial of Service
Description has changed
Low HTTP-Novell-Groupwise-Messenger-HTTP-POST-Request-Invalid-Memory-Access CVE-2006-4511 HTTP_CRL-Novell-Groupwise-Messenger-HTTP-POST-Request-Invalid-Memory-Access Potential Denial of Service
Description has changed
High PhpFileManager-Cmd-Parameter-Command-Execution No CVE/CAN HTTP_CRL-PhpFileManager-Cmd-Parameter-Command-Execution Suspected Compromise
Fingerprint regexp changed
High JetBrains-TeamCity-Avatar-Stored-Cross-Site-Scripting CVE-2022-48343 HTTP_CRL-JetBrains-TeamCity-Avatar-Stored-Cross-Site-Scripting Suspected Compromise
Fingerprint regexp changed

Text File Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High JetBrains-TeamCity-Avatar-Stored-Cross-Site-Scripting CVE-2022-48343 File-Text_JetBrains-TeamCity-Avatar-Stored-Cross-Site-Scripting Suspected Compromise
Fingerprint regexp changed

Other Binary File Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High Winace-Rar-And-Tar-Directory-Traversal-Vulnerability CVE-2006-0981 File-Binary_Path-Traversal-Via-Tar-Archive Suspected Compromise
Description has changed

LIST OF OTHER CHANGES:

Updated objects:

TypeNameChanges
Appliance Informationsg-3501-0-C1.svg
Appliance Informationsg-3505-0-C1.svg
Appliance Informationsg-3510-0-C1.svg
SituationURL_List-DNS-Over-HTTPS
Detection mechanism updated
IPListTOR exit nodes IP Address List
IPListAmazon AMAZON
IPListAmazon S3
IPListAmazon EC2
IPListTOR relay nodes IP Address List
IPListAmazon AMAZON ap-northeast-1
IPListAmazon EC2 ap-northeast-1
IPListBotnet IP Address List
IPListMalicious Site IP Address List
IPListNordVPN Servers IP Address List
IPListAmazon AMAZON ca-central-1
IPListAmazon S3 cn-north-1
IPListAmazon S3 cn-northwest-1
IPListAmazon AMAZON eu-north-1
IPListAmazon EC2 eu-north-1
IPListGoogle Common Services IP Address List
SituationHTTP_CS-Cisco-Data-Center-Network-Manager-RCE
Description has changed
Attacker: connection_source->none
Victim: connection_destination->none
Category tag situation Obsolete added
Category tag os Any Operating System removed
Category tag hardware Any Hardware removed
Category tag application Cisco Systems Prime Data Center Network Manager removed
Category tag group CVE2019 removed
Category tag os_not_specific Any Operating System not specific removed
Category tag situation Suspected Compromise removed
Category tag group HTTP Correlation Dependency Group removed
Category tag group TCP Correlation Dependency Group removed
Category tag group Severity over 4 Correlation Dependency Group removed
Category tag group TCP Client Traffic removed
SituationHTTP_CS-Cisco-Prime-Infrastructure-TarArchive-Directory-Traversal
Description has changed
Attacker: connection_source->none
Victim: connection_destination->none
Category tag situation Obsolete added
Category tag os Any Operating System removed
Category tag hardware Any Hardware removed
Category tag application Cisco Systems Prime Infrastructure removed
Category tag group CVE2019 removed
Category tag os_not_specific Any Operating System not specific removed
Category tag situation Suspected Compromise removed
Category tag group HTTP Correlation Dependency Group removed
Category tag group TCP Correlation Dependency Group removed
Category tag group Severity over 4 Correlation Dependency Group removed
Category tag group TCP Client Traffic removed
SituationHTTP_CSU-Shared-Variables
SituationHTTP_CSH-Shared-Variables
Fingerprint regexp changed
SituationHTTP_CRL-Shared-Variables
SituationGeneric_Novell-Groupwise-Messenger-HTTP-POST-Request-Invalid-Memory-Access
Description has changed
SituationGeneric_Novell-Groupwise-Messenger-HTTP-POST-Request-Memory-Access-Violation
Description has changed
SituationGeneric_CS-Shared-Variable-Fingerprints
Fingerprint regexp changed
SituationFile-Text_Suspicious-HTML-File
ApplicationLinkedIn
ApplicationTOR
ApplicationDNS-Over-HTTPS
ApplicationNordVPN

HOW TO IMPORT AND ACTIVATE THE DYNAMIC UPDATE PACKAGE

  1. Download the dynamic update package, then make sure that the checksums for the original files and the files that you have downloaded match.
  2. In the Management Client, select Menu > File > Import > Import Update Packages.
  3. Browse to the file, select it, then click Import.
  4. Select  Configuration, then browse to Administration > Other Elements > Updates.
  5. Right-click the imported dynamic update package, then select Activate.
  6. When the activation is finished, refresh the policy on all NGFW Engines. If your policy uses a custom template, you might need to edit the policy.

DISCLAIMER AND COPYRIGHT

Copyright © 2023 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.