ET WEB_SPECIFIC_APPS Citrix StoreFront XML Parsing Exception Response (CVE-2023-5914)
Query · suricata
flow:established,to_client; flowbits:isset,ET.Citrix.CVE_2023_5914; http.response_body; content:"System.Xml.XmlException"; pcre:"/^(?:(?!\x3c\x2fdiv\x3e).)+(?:on(?:(?:s(?:elec|ubmi)|rese)t|d(?:blclick|ragdrop)|(?:mouse|key)[a-z]+|c(?:hange|lick)|(?:un)?load|focus|blur|error)|s(?:cript|tyle\x3d))/R"; http.cookie; content:"Citrix_AuthSvc|3d|"; content:"path=/Citrix/teststoreAuth"; fast_pattern; http.stat_code; content:"200"; target:dest_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.Citrix.CVE_2023_5914