Release notes for update package 1833-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Friday February 07, 2025
MD5 CHECKSUM:     dc0e89f6d7949f40f269d32ade93618a
SHA1 CHECKSUM:     99d38e47421b7be24e47b81d19ba33a5d39c4f87
SHA256 CHECKSUM:     6f3e9d666a3b50b46628b27ae040768b0a509164832d7bc0b304ef747bcf94dd


UPDATE CRITICALITY:    HIGH

List of detected attacks in this update package:

Risk level Description Reference Vulnerability
High     An attempt to exploit a vulnerability in Microsoft .NET Framework detected     CVE-2024-29059     Microsoft-.NET-Framework-Information-Disclosure-CVE-2024-29059
High     An attempt to exploit a vulnerability in SAP Internet Communication Manager detected     CVE-2022-22536     SAP-Internet-Communication-Manager-HTTP-Request-Smuggling

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

HTTP Request Header Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High SAP-Internet-Communication-Manager-HTTP-Request-Smuggling CVE-2022-22536 HTTP_CSH-SAP-Internet-Communication-Manager-HTTP-Request-Smuggling Suspected Compromise
High Microsoft-.NET-Framework-Information-Disclosure-CVE-2024-29059 CVE-2024-29059 HTTP_CSH-Microsoft-.NET-Framework-Information-Disclosure-CVE-2024-29059 Suspected Compromise

Updated detected attacks:

HTTP Client Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High SAP-Internet-Communication-Manager-HTTP-Request-Smuggling CVE-2022-22536 HTTP_CS-SAP-Internet-Communication-Manager-HTTP-Request-Smuggling Suspected Compromise
Fingerprint regexp changed

HTTP Request URI

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Suspicious-Windows-Script-Retrieval-Via-WebDav No CVE/CAN HTTP_CSU-Suspicious-Windows-Script-File-Retrieval-Via-WebDav Suspected Compromise
Fingerprint regexp changed

Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
Low HTML-Tag-Detector No CVE/CAN File-Text_HTML-Tag-Detector System Inspections
Description has changed
Fingerprint regexp changed
High ADODB.Stream-ActiveX-Object-Local-Disk-Write No CVE/CAN File-Text_ADODB.Stream-ActiveX-Object-Local-Disk-Write Potential Compromise
Fingerprint regexp changed

LIST OF OTHER CHANGES:

Updated objects:

Type Name Changes
IPList TOR exit nodes IP Address List
IPList Amazon AMAZON
IPList Amazon EC2
IPList Microsoft Azure datacenter for australiaeast
IPList TOR relay nodes IP Address List
IPList Microsoft Azure datacenter for centralindia
IPList Microsoft Azure datacenter for centralus
IPList Microsoft Azure datacenter for eastus2euap
IPList Microsoft Azure datacenter for eastus2
IPList Microsoft Azure datacenter for eastus
IPList Microsoft Azure datacenter for centralfrance
IPList Microsoft Azure datacenter for japaneast
IPList Microsoft Azure datacenter for northcentralus
IPList Microsoft Azure datacenter for northeurope
IPList Microsoft Azure datacenter for southcentralus
IPList Microsoft Azure datacenter for westeurope
IPList Microsoft Azure datacenter for westus
IPList Microsoft Azure datacenter
IPList Malicious Site IP Address List
IPList Microsoft Azure datacenter for malaysiasouth
IPList Microsoft Azure service for Dynamics365BusinessCentral
IPList Microsoft Azure service for Marketplace
IPList NordVPN Servers IP Address List
IPList Forcepoint Drop IP Address List
IPList Amazon AMAZON us-west-2
IPList Amazon EC2 us-west-2
IPList Microsoft Azure datacenter for switzerlandn
IPList Microsoft Azure service for AzureCloud
IPList Microsoft Azure service for AzureMonitor
IPList Microsoft Azure service for AzureResourceManager
IPList Microsoft Azure service for PowerBI
IPList Microsoft Azure datacenter for usstagee
IPList Microsoft Azure datacenter for westus3
IPList Microsoft Azure service for AzureSecurityCenter
IPList Microsoft Azure datacenter for mexicocentral
IPList Microsoft Azure datacenter for newzealandnorth
IPList Microsoft Azure datacenter for polandcentral
IPList Microsoft Azure datacenter for spaincentral
Situation HTTP_CSU-Shared-Variables
Situation HTTP_CSH-Shared-Variables
Situation HTTP_PSU-Shared-Variables
Fingerprint regexp changed
Application TOR
Application NordVPN

DISCLAIMER AND COPYRIGHT

Copyright © 2025 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.