Release notes for update package 1437-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Monday February 21, 2022
MD5 CHECKSUM:     c605b0b4222b4b2d967582fa65a63e4c
SHA1 CHECKSUM:     37fc394f78317a014f138361ecf332408132f756
SHA256 CHECKSUM:     ecf661bc136e03d012e69706d3c4a988b352d473a435854bdda46b4c21276694

UPDATE CRITICALITY:    HIGH

List of detected attacks in this update package:

Risk level Description Reference Vulnerability
High     An attempt to exploit a vulnerability in Ignition Laravel detected.     CVE-2021-3129     Unauthenticated-Remote-Code-Execution-In-Ignition
High     An attempt to exploit a vulnerability in PHPUnit detected     CVE-2017-9841     PHPUnit-Remote-Code-Execution-CVE-2017-9841
High     An attempt to exploit a vulnerability in the Wordpress Popular Posts Plugin detected.     CVE-2021-42362     Wordpress-Popular-Posts-Authenticated-RCE
High     An attempt to exploit a vulnerability in Nagios XI detected.     CVE-2021-37343     Nagios-XI-Autodiscovery-WebShell-Upload
High     An attempt to exploit a vulnerability in H2 Database Project H2 Database detected     CVE-2022-23221     H2-Database-JDBC-URL-Arbitrary-Code-Execution
High     An attempt to exploit a vulnerability in Advantech WebAccess detected     CVE-2021-38389     Advantech-WebAccess-IOCTL-0x1138b-Stack-Based-Buffer-Overflow
High     An attempt to exploit a vulnerability in Wecon LeviStudioU detected     CVE-2021-23138     Wecon-LeviStudioU-Address-Mapping-Plcaddr-And-Dstaddr-Stack-Buffer-Overflow

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

HTTP Client Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Unauthenticated-Remote-Code-Execution-In-Ignition CVE-2021-3129 HTTP_CS-Unauthenticated-Remote-Code-Execution-In-Ignition Suspected Compromise

HTTP Request URI

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High PHPUnit-Remote-Code-Execution-CVE-2017-9841 CVE-2017-9841 HTTP_CSU-PHPUnit-Remote-Code-Execution-CVE-2017-9841 Suspected Compromise

MSRPC Client Payload Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Advantech-WebAccess-IOCTL-0x1138b-Stack-Based-Buffer-Overflow CVE-2021-38389 MSRPC-TCP_CPS-Advantech-WebAccess-IOCTL-0x1138b-Stack-Based-Buffer-Overflow Suspected Compromise

HTTP Normalized Request-Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Wordpress-Popular-Posts-Authenticated-RCE CVE-2021-42362 HTTP_CRL-Wordpress-Popular-Posts-Authenticated-RCE Suspected Compromise
High Nagios-XI-Autodiscovery-WebShell-Upload CVE-2021-37343 HTTP_CRL-Nagios-XI-Autodiscovery-WebShell-Upload Suspected Compromise
High H2-Database-JDBC-URL-Arbitrary-Code-Execution CVE-2022-23221 HTTP_CRL-H2-Database-JDBC-URL-Arbitrary-Code-Execution Suspected Compromise

Identified Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Wecon-LeviStudioU-Address-Mapping-Plcaddr-And-Dstaddr-Stack-Buffer-Overflow CVE-2021-23138 File-TextId_Wecon-LeviStudioU-Address-Mapping-Plcaddr-And-Dstaddr-Stack-Buffer-Overflow Suspected Compromise

Updated detected attacks:

Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Linux-Kernel-Netfilter-Iptables-Restore-Stack-Based-Buffer-Overflow CVE-2019-11360 File-Text_Linux-Kernel-Netfilter-Iptables-Restore-Stack-Based-Buffer-Overflow Suspected Compromise
Detection mechanism updated
High Microsoft-Internet-Explorer-ASLR-Bypass-CVE-2015-2421 CVE-2015-2421 File-Text_Microsoft-Internet-Explorer-ALSR-Bypass-CVE-2015-2421 Suspected Compromise
Detection mechanism updated

Identified Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
Low File-Type-Identification No CVE/CAN File-TextId_Office-Open-XML-Workbook Possibly Unwanted Content
Fingerprint regexp changed

LIST OF OTHER CHANGES:

New objects:

Type Name
Category Wordpress Popular Posts Plugin
Category Ignition Laravel
Category PHPUnit
Situation Context TCP Client SYN Header Fingerprinting Stream
Situation Context TCP Server SYN Header Fingerprinting Stream
Situation Context TCP Unsupported Options Stream

Updated objects:

Type Name Changes
IPList TOR exit nodes IP Address List
IPList Amazon AMAZON
IPList Amazon S3
IPList Amazon EC2
IPList Google Servers
IPList Akamai Servers
IPList Microsoft Azure datacenter for australiaeast
IPList Microsoft Azure datacenter for brazilsouth
IPList Microsoft Azure datacenter for canadacentral
IPList TOR relay nodes IP Address List
IPList Microsoft Azure datacenter for centralindia
IPList Microsoft Azure datacenter for centralus
IPList Microsoft Azure datacenter for eastasia
IPList Microsoft Azure datacenter for eastus2euap
IPList Microsoft Azure datacenter for eastus2
IPList Microsoft Azure datacenter for eastus
IPList Microsoft Azure datacenter for japaneast
IPList Microsoft Azure datacenter for northeurope
IPList Microsoft Azure datacenter for southcentralus
IPList Microsoft Azure datacenter for southeastasia
IPList Microsoft Azure datacenter for uksouth
IPList Microsoft Azure datacenter for westeurope
IPList Microsoft Azure datacenter for westus2
IPList Microsoft Azure datacenter for westus
IPList Microsoft Azure datacenter
IPList Amazon AMAZON il-central-1
IPList Amazon S3 il-central-1
IPList Amazon EC2 il-central-1
IPList Botnet IP Address List
IPList Malicious Site IP Address List
IPList Amazon AMAZON ap-south-1
IPList Amazon AMAZON ap-southeast-1
IPList Amazon AMAZON us-east-1
IPList Microsoft Azure service for ActionGroup
IPList Microsoft Azure service for ApiManagement
IPList Microsoft Azure service for AppConfiguration
IPList Microsoft Azure service for AppService
IPList Microsoft Azure service for AppServiceManagement
IPList Microsoft Azure service for AzureAdvancedThreatProtection
IPList Microsoft Azure service for AzureBackup
IPList Microsoft Azure service for AzureBotService
IPList Microsoft Azure service for AzureCloud
IPList Microsoft Azure service for AzureCognitiveSearch
IPList Microsoft Azure service for AzureConnectors
IPList Microsoft Azure service for AzureContainerRegistry
IPList Microsoft Azure service for AzureCosmosDB
IPList Microsoft Azure service for AzureDatabricks
IPList Microsoft Azure service for AzureDataExplorerManagement
IPList Microsoft Azure service for AzureDigitalTwins
IPList Microsoft Azure service for AzureEventGrid
IPList Microsoft Azure service for AzureFrontDoor_Backend
IPList Microsoft Azure service for AzureFrontDoor_Frontend
IPList Microsoft Azure service for AzureIoTHub
IPList Microsoft Azure service for AzureKeyVault
IPList Microsoft Azure service for AzureMachineLearning
IPList Microsoft Azure service for AzureMonitor
IPList Microsoft Azure service for AzureMonitor_Core
IPList Microsoft Azure service for AzurePortal
IPList Microsoft Azure service for AzureResourceManager
IPList Microsoft Azure service for AzureSiteRecovery
IPList Microsoft Azure service for BatchNodeManagement
IPList Microsoft Azure service for CognitiveServicesManagement
IPList Microsoft Azure service for DataFactory
IPList Microsoft Azure service for DataFactoryManagement
IPList Microsoft Azure service for EventHub
IPList Microsoft Azure service for GatewayManager
IPList Microsoft Azure service for GuestAndHybridManagement
IPList Microsoft Azure service for HDInsight
IPList Microsoft Azure service for LogicApps
IPList Microsoft Azure service for LogicAppsManagement
IPList Microsoft Azure service for MicrosoftContainerRegistry
IPList Microsoft Azure service for PowerBI
IPList Microsoft Azure service for PowerQueryOnline
IPList Microsoft Azure service for ServiceBus
IPList Microsoft Azure service for ServiceFabric
IPList Microsoft Azure service for Sql
IPList Microsoft Azure service for SqlManagement
IPList Microsoft Azure service for Storage
IPList Microsoft Azure service for StorageSyncService
IPList Microsoft Azure datacenter for usstagee
IPList Microsoft Azure datacenter for swedensouth
IPList Microsoft Azure service for AzureAttestation
IPList Microsoft Azure datacenter for taiwannorth
IPList Microsoft Azure datacenter for taiwannorthwest
IPList Microsoft Azure service for WindowsAdminCenter
Situation TCP_Option-Unsupported
Description has changed
Situation TCP_Option-Unhandled
Description has changed
Situation Context Group TCP

DISCLAIMER AND COPYRIGHT

Copyright © 2022 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.