ET EXPLOIT Cisco REST API Container for Cisco IOS XE Software Authentication Bypass - Successful Exploit (CVE-2019-12643)
Query · suricata
flow:established,to_client;
flowbits:isset,ET.Cisco_ABypass;
http.stat_code;
content:"200";
file.data; strip_whitespace;
content:"|5b 7b 22|last-access-time|22 3a|"; fast_pattern;
content:"|22|token-id|22 3a 22|"; within:200;
pcre:"/^[a-zA-Z0-9]{5,40}/R";
xbits:set,ET.Cisco_ABypass,track ip_pair,expire 60;
target:dest_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.Cisco_ABypass
Feeds into
-
1 rule read
ET.Cisco_ABypass· view all