Release notes for update package 1784-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Thursday October 03, 2024
MD5 CHECKSUM:     85d837247affe36379b3f2893492ed6e
SHA1 CHECKSUM:     8d17d6bc61f9fa9f6538f378fe5e181f91032d51
SHA256 CHECKSUM:     3e65ec37b64343b5dd9fb400b55dc5efe628f5ad6aab1cd79edf56a859a7882d


UPDATE CRITICALITY:    HIGH

List of detected attacks in this update package:

Risk level Description Reference Vulnerability
High     An attempt to exploit a vulnerability in Veeam Backup and Replication detected     CVE-2024-40711     Veeam-Backup-And-Replication-Insecure-Deserialization-CVE-2024-40711
High     A suspicious Git packfile detected     CVE-2024-32002     Git-Source-Code-Management-Clone_submodule-Link-Following
High     An attempt to exploit a vulnerability in Ivanti Endpoint Manager detected     CVE-2024-29827     Ivanti-Endpoint-Manager-Vulcore.asmx-Getdbpatchproducts-SQL-Injection
High     An attempt to exploit a vulnerability in VMWare Spring Cloud Data Flow detected     CVE-2024-22263     VMware-Spring-Cloud-Data-Flow-Skipper-Server-Directory-Traversal
High     An attempt to exploit a vulnerability in Kingsoft WPS Office detected     CVE-2024-7262     Kingsoft-WPS-Office-Path-Traversal-CVE-2024-7262
High     An attempt to exploit a vulnerability in Kingsoft WPS Office detected     CVE-2024-7262     Kingsoft-WPS-Office-Path-Traversal-CVE-2024-7262
High     An attempt to exploit a vulnerability in LAquis SCADA detected     CVE-2024-5040     Laquis-Scada-LGX-Report-Table-Save-Arbitrary-File-Write
High     An attempt to exploit a vulnerability in DrayTek Vigor detected     CVE-2021-20124     DrayTek-Vigor-Local-File-Inclusion-CVE-2021-20124

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

TCP Client Stream Unknown

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Veeam-Backup-And-Replication-Insecure-Deserialization-CVE-2024-40711 CVE-2024-40711 Generic_CS-Veeam-Backup-And-Replication-Insecure-Deserialization-CVE-2024-40711 Suspected Compromise

TCP Server Stream Unknown

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Git-Source-Code-Management-Clone_submodule-Link-Following CVE-2024-32002 Generic_SS-Suspicious-Git-Packfile-In-Server-Response Suspected Compromise

HTTP Request URI

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High DrayTek-Vigor-Local-File-Inclusion-CVE-2021-20124 CVE-2021-20124 HTTP_CSU-DrayTek-Vigor-Local-File-Inclusion-CVE-2021-20124 Suspected Compromise

HTTP Normalized Request-Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High VMware-Spring-Cloud-Data-Flow-Skipper-Server-Directory-Traversal CVE-2024-22263 HTTP_CRL-VMware-Spring-Cloud-Data-Flow-Skipper-Server-Directory-Traversal Suspected Compromise

Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Kingsoft-WPS-Office-Path-Traversal-CVE-2024-7262 CVE-2024-7262 File-Text_Kingsoft-WPS-Office-Path-Traversal-CVE-2024-7262 Suspected Compromise

Other Binary File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Laquis-Scada-LGX-Report-Table-Save-Arbitrary-File-Write CVE-2024-5040 File-Binary_Laquis-Scada-LGX-Report-Table-Save-Arbitrary-File-Write Suspected Compromise

Identified Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Ivanti-Endpoint-Manager-Vulcore.asmx-Getdbpatchproducts-SQL-Injection CVE-2024-29827 File-TextId_Ivanti-Endpoint-Manager-Vulcore.asmx-Getdbpatchproducts-SQL-Injection Suspected Compromise
High Kingsoft-WPS-Office-Path-Traversal-CVE-2024-7262 CVE-2024-7262 File-TextId_Kingsoft-WPS-Office-Path-Traversal-CVE-2024-7262 Suspected Compromise

Updated detected attacks:

HTTP Client Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High LANDesk-ThinkManagement-Suite-SetTaskLogByFile-Arbitrary-File-Deletion CVE-2012-1196 HTTP_CS-LANDesk-ThinkManagement-Suite-SetTaskLogByFile-Arbitrary-File-Deletion Suspected Compromise
Fingerprint regexp changed
High Artica-Proxy-Squid.conf-Authentication-Bypass CVE-2024-2056 HTTP_CS-Artica-Proxy-Squid.conf-Authentication-Bypass Suspected Compromise
Name: HTTP8080_CS-Artica-Proxy-Squid.conf-Authentication-Bypass->HTTP_CS-Artica-Proxy-Squid.conf-Authentication-Bypass
Category tag group HTTP Correlation Dependency Group added
Context has changed from HTTP Proxy Client Stream to HTTP Client Stream

HTTP Request URI

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
Low Oracle-HTTP-Server-Mod-Access-Restriction-Bypass CVE-2005-1383 HTTP_CSU-Oracle-HTTP-Server-Mod-Access-Restriction-Bypass Potential Disclosure
Fingerprint regexp changed
High Oracle-Application-Server-9i-WebCache-File-Corruption CVE-2005-1382 HTTP_CSU-Oracle-Application-Server-9i-WebCache-File-Corruption Suspected Compromise
Fingerprint regexp changed
High ZeroShell-Local-File-Disclosure No CVE/CAN HTTP_CSU-ZeroShell-Local-File-Disclosure Suspected Compromise
Detection mechanism updated
High Danmec No CVE/CAN HTTP_CSU-Danmec-Trojan-SQL-Injection-Attack Botnet
Detection mechanism updated
Low Oracle-HTTP-Server-Mod-Access-Restriction-Bypass CVE-2005-1383 HTTP_CSU-Oracle-Potential-Vulnerability-Probe-Request Potential Probe
Name: HTTP_CSU-Oracle-Suspecious-Request->HTTP_CSU-Oracle-Potential-Vulnerability-Probe-Request
Comment has changed
Description has changed
Category tag group CVE2005 added
Low HTTP-Domino-Access No CVE/CAN HTTP_CSU-IBM-Domino-Access Potential Probe
Detection mechanism updated

HTTP Request Header Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Apache-Shiro-Remote-Code-Execution CVE-2016-4437 HTTP_CSH-Apache-Shiro-Remote-Code-Execution Suspected Compromise
Description has changed
Category tag situation Suspected Compromise added
Category tag situation Potential Compromise removed
Fingerprint regexp changed

Other Binary File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High CUPS-Remote-Command-Execution-Via-FoomaticRIPCommandLine-CVE-2024-47177 CVE-2024-47177 File-Binary_CUPS-Remote-Command-Execution-Via-FoomaticRIPCommandLine-CVE-2024-47177 Suspected Compromise
Fingerprint regexp changed

Identified Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Ivanti-Endpoint-Manager-Vulcore-Getdbvulnerabilities-SQL-Injection CVE-2024-29823 File-TextId_Ivanti-Endpoint-Manager-Vulcore-Getdbvulnerabilities-SQL-Injection Suspected Compromise
Fingerprint regexp changed

LIST OF OTHER CHANGES:

New objects:

Type Name
Category Kingsoft WPS Office
Category VMWare Spring Cloud Data Flow
IPList Amazon AMAZON ap-east-2
IPList Amazon AMAZON mx-central-1
IPList Amazon AMAZON ap-southeast-7
IPList Amazon S3 ap-east-2
IPList Amazon S3 ap-southeast-7
IPList Amazon S3 mx-central-1
IPList Amazon EC2 ap-southeast-7
IPList Amazon EC2 mx-central-1
IPList Amazon EC2 ap-east-2
IPList Amazon ROUTE53_HEALTHCHECKS_PUBLISHING mx-central-1
IPList Amazon ROUTE53_HEALTHCHECKS_PUBLISHING ap-east-2
IPList Amazon ROUTE53_HEALTHCHECKS_PUBLISHING ap-southeast-7
IPList Amazon DYNAMODB ap-southeast-7
IPList Amazon DYNAMODB ap-east-2
IPList Amazon DYNAMODB mx-central-1

Updated objects:

Type Name Changes
Appliance Information sg-61-0-C1.svg
Situation URL_List-DNS-Over-HTTPS
Detection mechanism updated
IPList Iraq
IPList Saudi Arabia
IPList Iran
IPList Cyprus
IPList Tanzania
IPList Syria
IPList Armenia
IPList Kenya
IPList DR Congo
IPList Uganda
IPList Seychelles
IPList Jordan
IPList Lebanon
IPList Kuwait
IPList Oman
IPList Qatar
IPList Bahrain
IPList United Arab Emirates
IPList Israel
IPList Türkiye
IPList Egypt
IPList Sudan
IPList Greece
IPList Estonia
IPList Latvia
IPList Lithuania
IPList Georgia
IPList Moldova
IPList Belarus
IPList Finland
IPList Ukraine
IPList Hungary
IPList Bulgaria
IPList Albania
IPList Poland
IPList Romania
IPList Comoros
IPList Malawi
IPList Lesotho
IPList Botswana
IPList Mauritius
IPList Réunion
IPList South Africa
IPList Mozambique
IPList Afghanistan
IPList Pakistan
IPList Bangladesh
IPList Turkmenistan
IPList Tajikistan
IPList Sri Lanka
IPList India
IPList Nepal
IPList Myanmar
IPList Uzbekistan
IPList Kazakhstan
IPList Kyrgyzstan
IPList Vietnam
IPList Thailand
IPList Indonesia
IPList Laos
IPList Taiwan
IPList Philippines
IPList Malaysia
IPList China
IPList Hong Kong
IPList Macao
IPList Cambodia
IPList South Korea
IPList Japan
IPList Singapore
IPList Russia
IPList Mongolia
IPList Australia
IPList Federated States of Micronesia
IPList Tuvalu
IPList Vanuatu
IPList New Caledonia
IPList New Zealand
IPList Portugal
IPList Liberia
IPList Ghana
IPList Nigeria
IPList Gibraltar
IPList Mali
IPList Tunisia
IPList Spain
IPList Malta
IPList Algeria
IPList Denmark
IPList Iceland
IPList United Kingdom
IPList Switzerland
IPList Sweden
IPList The Netherlands
IPList Austria
IPList Belgium
IPList Germany
IPList Luxembourg
IPList Ireland
IPList Monaco
IPList France
IPList Liechtenstein
IPList Slovakia
IPList Czechia
IPList Norway
IPList Italy
IPList Slovenia
IPList Montenegro
IPList Croatia
IPList Angola
IPList Namibia
IPList Barbados
IPList French Guiana
IPList Paraguay
IPList Brazil
IPList Jamaica
IPList Dominican Republic
IPList Cuba
IPList Martinique
IPList Bahamas
IPList Anguilla
IPList Trinidad and Tobago
IPList St Kitts and Nevis
IPList Dominica
IPList Saint Lucia
IPList Turks and Caicos Islands
IPList British Virgin Islands
IPList Guadeloupe
IPList Belize
IPList El Salvador
IPList Guatemala
IPList Honduras
IPList Costa Rica
IPList Venezuela
IPList Ecuador
IPList Colombia
IPList Panama
IPList Argentina
IPList Chile
IPList Peru
IPList Mexico
IPList French Polynesia
IPList Niue
IPList Northern Mariana Islands
IPList Guam
IPList Puerto Rico
IPList U.S. Virgin Islands
IPList American Samoa
IPList Canada
IPList United States
IPList Serbia
IPList Antarctica
IPList Sint Maarten
IPList Curaçao
IPList TOR exit nodes IP Address List
IPList Amazon AMAZON
IPList Amazon S3
IPList Amazon EC2
IPList Microsoft Azure datacenter for australiaeast
IPList Microsoft Azure datacenter for canadacentral
IPList TOR relay nodes IP Address List
IPList Microsoft Azure datacenter for centralindia
IPList Microsoft Azure datacenter for centralus
IPList Microsoft Azure datacenter for eastus2euap
IPList Microsoft Azure datacenter for eastus2
IPList Microsoft Azure datacenter for eastus
IPList Microsoft Azure datacenter for centralfrance
IPList Microsoft Azure datacenter for japaneast
IPList Microsoft Azure datacenter for northcentralus
IPList Microsoft Azure datacenter for southcentralus
IPList Microsoft Azure datacenter for uksouth
IPList Microsoft Azure datacenter for westeurope
IPList Microsoft Azure datacenter for westus2
IPList Microsoft Azure service for AzureActiveDirectory
IPList Microsoft Azure datacenter
IPList Amazon ROUTE53_HEALTHCHECKS_PUBLISHING
IPList Amazon DYNAMODB
IPList Microsoft Azure service for AzureHealthcareAPIs
IPList Botnet IP Address List
IPList Malicious Site IP Address List
IPList Microsoft Azure datacenter for malaysiasouth
IPList Microsoft Azure service for Dynamics365BusinessCentral
IPList NordVPN Servers IP Address List
IPList Microsoft Azure service for AzureSpringCloud
IPList Microsoft Azure service for CognitiveServicesFrontend
IPList Microsoft Azure service for KustoAnalytics
IPList Microsoft Azure service for AzureMachineLearningInference
IPList Microsoft Azure service for VideoIndexer
IPList Forcepoint Drop IP Address List
IPList Microsoft Azure service for Scuba
IPList Microsoft Azure datacenter for germanywc
IPList Microsoft Azure datacenter for switzerlandn
IPList Microsoft Azure service for ActionGroup
IPList Microsoft Azure service for ApiManagement
IPList Microsoft Azure service for AppConfiguration
IPList Microsoft Azure service for AppService
IPList Microsoft Azure service for AppServiceManagement
IPList Microsoft Azure service for AzureAdvancedThreatProtection
IPList Microsoft Azure service for AzureArcInfrastructure
IPList Microsoft Azure service for AzureBackup
IPList Microsoft Azure service for AzureBotService
IPList Microsoft Azure service for AzureCloud
IPList Microsoft Azure service for AzureCognitiveSearch
IPList Microsoft Azure service for AzureConnectors
IPList Microsoft Azure service for AzureContainerRegistry
IPList Microsoft Azure service for AzureCosmosDB
IPList Microsoft Azure service for AzureDatabricks
IPList Microsoft Azure service for AzureDataExplorerManagement
IPList Microsoft Azure service for AzureDigitalTwins
IPList Microsoft Azure service for AzureEventGrid
IPList Microsoft Azure service for AzureKeyVault
IPList Microsoft Azure service for AzureMachineLearning
IPList Microsoft Azure service for AzureMonitor
IPList Microsoft Azure service for AzureMonitor_Core
IPList Microsoft Azure service for AzurePortal
IPList Microsoft Azure service for AzureResourceManager
IPList Microsoft Azure service for AzureSiteRecovery
IPList Microsoft Azure service for BatchNodeManagement
IPList Microsoft Azure service for CognitiveServicesManagement
IPList Microsoft Azure service for DataFactory
IPList Microsoft Azure service for DataFactoryManagement
IPList Microsoft Azure service for EventHub
IPList Microsoft Azure service for GatewayManager
IPList Microsoft Azure service for GuestAndHybridManagement
IPList Microsoft Azure service for HDInsight
IPList Microsoft Azure service for LogicApps
IPList Microsoft Azure service for LogicAppsManagement
IPList Microsoft Azure service for MicrosoftContainerRegistry
IPList Microsoft Azure service for PowerBI
IPList Microsoft Azure service for PowerQueryOnline
IPList Microsoft Azure service for ServiceBus
IPList Microsoft Azure service for ServiceFabric
IPList Microsoft Azure service for Sql
IPList Microsoft Azure service for SqlManagement
IPList Microsoft Azure service for Storage
IPList Microsoft Azure service for StorageSyncService
IPList Microsoft Azure datacenter for westus3
IPList Microsoft Azure service for AzureAttestation
IPList Microsoft Azure datacenter for israelcentral
IPList Microsoft Azure datacenter for italynorth
IPList Microsoft Azure datacenter for mexicocentral
IPList Microsoft Azure datacenter for newzealandnorth
IPList Microsoft Azure datacenter for polandcentral
IPList Microsoft Azure datacenter for spaincentral
IPList Microsoft Azure datacenter for taiwannorth
IPList Microsoft Azure datacenter for taiwannorthwest
IPList Microsoft Azure service for WindowsAdminCenter
IPList Microsoft Azure service for AzureSentinel
Situation HTTP_CSU-Shared-Variables
Application TOR
Application DNS-Over-HTTPS
Application NordVPN

DISCLAIMER AND COPYRIGHT

Copyright © 2024 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.