Release notes for update package 1815-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Monday December 23, 2024
MD5 CHECKSUM:     22ab0c5fdb1e566625caeab6867097bc
SHA1 CHECKSUM:     f3ff3a69428e413a21ee404995880303acb9720e
SHA256 CHECKSUM:     6f97623268ed97d7a697eb68b6a0e5bc39f7e0156c0736087697150c9b15a3f8


UPDATE CRITICALITY:    HIGH

List of detected attacks in this update package:

Risk level Description Reference Vulnerability
High     An attempt to exploit a vulnerability in Jenkins Simple Queue Plugin     CVE-2024-54003     Jenkins-Simple-Queue-Plugin-Stored-Cross-Site-Scripting
High     An attempt to exploit a vulnerability in Fortinet FortiOS detected     CVE-2024-23113     Fortinet-FortiOS-Format-String-CVE-2024-23113
High     An attempt to exploit a vulnerability in Clinic's Patient Management System     CVE-2022-40471     Clinics-Patient-Management-System-PHP-File-Upload
High     An attempt to exploit a vulnerability in D-Link detected     CVE-2020-25078     D-Link-DCS-2530L-DCS-2670L-Password-Disclosure-CVE-2020-25078
High     An attempt to exploit a vulnerability in RichFaces framework detected     CVE-2018-14667     RichFaces-Framework-Expression-Language-Injection-CVE-2018-14667
High     An attempt to exploit a vulnerability in TBK DVR4104 and DVR4216 detected     CVE-2018-9995     TBK-DVR4104-And-DVR4216-Authentication-Bypass-CVE-2018-9995
High     An attempt to install malware via fake CAPTCHA detected     No CVE/CAN Information-Stealer-Using-Fake-Captcha
High     HiatusRAT malware activity detected     No CVE/CAN HiatusRAT-Malware-C2-Traffic
Low     RichFaces framework DATA URL segment followed by compressed content     CVE-2018-14667     RichFaces-Framework-Expression-Language-Injection-CVE-2018-14667

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

HTTP Client Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Clinics-Patient-Management-System-PHP-File-Upload CVE-2022-40471 HTTP_CS-Clinics-Patient-Management-System-PHP-File-Upload Potential Compromise

TCP Client Stream Unknown

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Fortinet-FortiOS-Format-String-CVE-2024-23113 CVE-2024-23113 Generic_CS-Fortinet-FortiOS-Format-String-CVE-2024-23113 Suspected Compromise

HTTP Request URI

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High D-Link-DCS-2530L-DCS-2670L-Password-Disclosure-CVE-2020-25078 CVE-2020-25078 HTTP_CSU-D-Link-DCS-2530L-DCS-2670L-Password-Disclosure-CVE-2020-25078 Potential Compromise
Low RichFaces-Framework-Expression-Language-Injection-CVE-2018-14667 CVE-2018-14667 HTTP_CSU-RichFaces-Framework-DATA-URL-Segment-With-Compressed-Content Possibly Unwanted Content
High RichFaces-Framework-Expression-Language-Injection-CVE-2018-14667 CVE-2018-14667 HTTP_CSU-RichFaces-Framework-Expression-Language-Injection-Known-Payload Suspected Compromise
High HiatusRAT-Malware-C2-Traffic No CVE/CAN HTTP_CSU-HiatusRAT-Malware-C2-Traffic Suspected Compromise

HTTP Request Header Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High TBK-DVR4104-And-DVR4216-Authentication-Bypass-CVE-2018-9995 CVE-2018-9995 HTTP_CSH-TBK-DVR4104-And-DVR4216-Authentication-Bypass-CVE-2018-9995 Suspected Compromise

HTTP Normalized Request-Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Jenkins-Simple-Queue-Plugin-Stored-Cross-Site-Scripting CVE-2024-54003 HTTP_CRL-Jenkins-Simple-Queue-Plugin-Stored-Cross-Site-Scripting Suspected Compromise

Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Information-Stealer-Using-Fake-Captcha No CVE/CAN File-Text_Information-Stealer-Using-Fake-Captcha Potential Compromise

Updated detected attacks:

HTTP Client Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Apache-Struts-File-Upload-Vulnerability-CVE-2023-50164 CVE-2023-50164 HTTP_CS-Apache-Struts-File-Upload-Vulnerability-CVE-2023-50164 Suspected Compromise
Fingerprint regexp changed

HTTP Normalized Request-Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Nuuo-NVRmini-Upgrade_handle.php-Remote-Command-Execution CVE-2018-14933 HTTP_CRL-Nuuo-NVRmini-Upgrade_handle.php-Remote-Command-Execution Suspected Compromise
Fingerprint regexp changed

Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Suspicious-Jsp-File-Upload No CVE/CAN File-Text_Suspicious-Jsp-File-Content-Upload Suspected Compromise
Fingerprint regexp changed
High Microsoft_Office_Directory_Traversal_Vulnerability_CVE-2019-0801 CVE-2019-0801 File-Text_Microsoft_Office_Directory_Traversal_Vulnerability_CVE-2019-0801 Suspected Compromise
Detection mechanism updated

LIST OF OTHER CHANGES:

New objects:

Type Name
Category Clinic's Patient Management System
Category TBK DVR
Category HiatusRAT
Category RichFaces framework
Application Temu

Updated objects:

Type Name Changes
Certificate Authority vTrus DV SSL CA G1
Marked for removal
Certificate Authority vTrus OV SSL CA G1
Marked for removal
Situation URL_List-DNS-Over-HTTPS
Detection mechanism updated
IPList Rwanda
IPList Somalia
IPList Yemen
IPList Iraq
IPList Saudi Arabia
IPList Iran
IPList Cyprus
IPList Tanzania
IPList Syria
IPList Armenia
IPList Kenya
IPList DR Congo
IPList Djibouti
IPList Uganda
IPList Central African Republic
IPList Seychelles
IPList Jordan
IPList Lebanon
IPList Kuwait
IPList Oman
IPList Qatar
IPList Bahrain
IPList United Arab Emirates
IPList Israel
IPList Türkiye
IPList Ethiopia
IPList Eritrea
IPList Egypt
IPList Sudan
IPList Greece
IPList Burundi
IPList Estonia
IPList Latvia
IPList Azerbaijan
IPList Lithuania
IPList Svalbard and Jan Mayen
IPList Georgia
IPList Moldova
IPList Belarus
IPList Finland
IPList Ukraine
IPList North Macedonia
IPList Hungary
IPList Bulgaria
IPList Albania
IPList Poland
IPList Romania
IPList Zimbabwe
IPList Zambia
IPList Comoros
IPList Malawi
IPList Lesotho
IPList Botswana
IPList Mauritius
IPList South Africa
IPList Mozambique
IPList Madagascar
IPList Afghanistan
IPList Pakistan
IPList Bangladesh
IPList Turkmenistan
IPList Tajikistan
IPList Sri Lanka
IPList Bhutan
IPList India
IPList Maldives
IPList Nepal
IPList Myanmar
IPList Uzbekistan
IPList Kazakhstan
IPList Kyrgyzstan
IPList Vietnam
IPList Thailand
IPList Indonesia
IPList Laos
IPList Taiwan
IPList Philippines
IPList Malaysia
IPList China
IPList Hong Kong
IPList Cambodia
IPList South Korea
IPList Japan
IPList North Korea
IPList Singapore
IPList Timor-Leste
IPList Russia
IPList Mongolia
IPList Australia
IPList Papua New Guinea
IPList Solomon Islands
IPList Norfolk Island
IPList New Zealand
IPList Libya
IPList Cameroon
IPList Senegal
IPList Congo Republic
IPList Portugal
IPList Liberia
IPList Ivory Coast
IPList Ghana
IPList Equatorial Guinea
IPList Nigeria
IPList Burkina Faso
IPList Togo
IPList Guinea-Bissau
IPList Mauritania
IPList Benin
IPList Gabon
IPList Sierra Leone
IPList Gambia
IPList Guinea
IPList Mali
IPList Tunisia
IPList Spain
IPList Morocco
IPList Malta
IPList Algeria
IPList Denmark
IPList Iceland
IPList United Kingdom
IPList Switzerland
IPList Sweden
IPList The Netherlands
IPList Austria
IPList Belgium
IPList Germany
IPList Luxembourg
IPList Ireland
IPList Monaco
IPList France
IPList Andorra
IPList Liechtenstein
IPList Jersey
IPList Isle of Man
IPList Guernsey
IPList Slovakia
IPList Czechia
IPList Norway
IPList San Marino
IPList Italy
IPList Slovenia
IPList Montenegro
IPList Croatia
IPList Bosnia and Herzegovina
IPList Angola
IPList Saint Helena
IPList Cabo Verde
IPList Suriname
IPList Paraguay
IPList Brazil
IPList Jamaica
IPList Dominican Republic
IPList Cuba
IPList Bahamas
IPList Trinidad and Tobago
IPList Aruba
IPList British Virgin Islands
IPList Saint Martin
IPList Saint Barthélemy
IPList Guadeloupe
IPList Cayman Islands
IPList El Salvador
IPList Guatemala
IPList Honduras
IPList Nicaragua
IPList Costa Rica
IPList Venezuela
IPList Ecuador
IPList Colombia
IPList Panama
IPList Haiti
IPList Argentina
IPList Chile
IPList Bolivia
IPList Peru
IPList Mexico
IPList Puerto Rico
IPList U.S. Outlying Islands
IPList American Samoa
IPList Canada
IPList United States
IPList Palestine
IPList Serbia
IPList Antarctica
IPList South Sudan
IPList TOR exit nodes IP Address List
IPList Amazon AMAZON
IPList Amazon EC2
IPList Amazon CLOUDFRONT
IPList Akamai Servers
IPList TOR relay nodes IP Address List
IPList Amazon AMAZON af-south-1
IPList Zscaler IP Address List
IPList Amazon EC2 af-south-1
IPList Amazon AMAZON ap-east-1
IPList Amazon EC2 ap-east-1
IPList Amazon AMAZON ap-south-2
IPList Amazon EC2 ap-south-2
IPList Amazon AMAZON ap-northeast-1
IPList Amazon EC2 me-central-1
IPList Amazon AMAZON me-central-1
IPList Amazon EC2 ap-northeast-1
IPList Amazon AMAZON eu-south-2
IPList Amazon EC2 eu-south-2
IPList Amazon AMAZON eu-central-2
IPList Amazon EC2 eu-central-2
IPList Amazon AMAZON il-central-1
IPList Amazon AMAZON ap-northeast-2
IPList Amazon EC2 ap-northeast-2
IPList Amazon EC2 il-central-1
IPList Amazon AMAZON ap-northeast-3
IPList Amazon EC2 ap-northeast-3
IPList Malicious Site IP Address List
IPList Amazon AMAZON ap-southeast-6
IPList Amazon EC2 ap-southeast-6
IPList Amazon AMAZON ap-south-1
IPList Amazon EC2 ap-south-1
IPList Amazon CLOUDFRONT ap-south-1
IPList Amazon AMAZON ap-southeast-1
IPList Amazon EC2 ap-southeast-1
IPList Amazon AMAZON ap-southeast-2
IPList Amazon EC2 ap-southeast-2
IPList Amazon AMAZON ca-central-1
IPList Amazon EC2 ca-central-1
IPList Amazon AMAZON cn-north-1
IPList Amazon EC2 cn-north-1
IPList Amazon AMAZON cn-northwest-1
IPList Amazon EC2 cn-northwest-1
IPList Amazon AMAZON eu-central-1
IPList Amazon EC2 eu-central-1
IPList Amazon AMAZON eu-north-1
IPList Amazon EC2 eu-north-1
IPList Amazon AMAZON ap-southeast-5
IPList Amazon AMAZON eu-west-1
IPList Amazon EC2 ap-southeast-5
IPList Amazon EC2 eu-west-1
IPList Amazon AMAZON eu-west-2
IPList Amazon EC2 eu-west-2
IPList Amazon AMAZON eu-west-3
IPList Amazon EC2 eu-west-3
IPList Amazon AMAZON me-south-1
IPList Amazon EC2 me-south-1
IPList Amazon AMAZON sa-east-1
IPList Amazon EC2 sa-east-1
IPList Amazon AMAZON us-east-1
IPList Amazon EC2 us-east-1
IPList Amazon AMAZON eusc-de-east-1
IPList Amazon EC2 eusc-de-east-1
IPList Amazon AMAZON us-east-2
IPList Amazon EC2 us-east-2
IPList Forcepoint Drop IP Address List
IPList Amazon AMAZON us-gov-east-1
IPList Amazon EC2 us-gov-east-1
IPList Amazon AMAZON us-gov-west-1
IPList Amazon EC2 us-gov-west-1
IPList Amazon AMAZON us-west-1
IPList Amazon EC2 us-west-1
IPList Amazon AMAZON us-west-2
IPList Amazon EC2 us-west-2
IPList Amazon AMAZON eu-south-1
IPList Amazon EC2 eu-south-1
IPList Amazon AMAZON ap-southeast-3
IPList Amazon EC2 ap-southeast-3
IPList Amazon AMAZON ap-east-2
IPList Amazon AMAZON mx-central-1
IPList Amazon AMAZON ap-southeast-7
IPList Amazon EC2 ap-southeast-7
IPList Amazon EC2 mx-central-1
IPList Amazon EC2 ap-east-2
IPList Amazon EC2 ap-southeast-4
IPList Amazon AMAZON ap-southeast-4
IPList Amazon AMAZON ca-west-1
IPList Amazon EC2 ca-west-1
Situation HTTP_CSU-Shared-Variables
Application Akamai-Infrastructure
Application TOR
Application Manoto
Application DNS-Over-HTTPS

DISCLAIMER AND COPYRIGHT

Copyright © 2024 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.