Cisco ASA FTD Exploit CVE-2020-3452
Description
Detects exploitation attempts on Cisco ASA FTD systems exploiting CVE-2020-3452 with a status code of 200 (sccessful exploitation)
Query · sigma
selection_endpoint: cs-uri-query|contains: - +CSCOT+/translation-table - +CSCOT+/oem-customization selection_path_select: cs-uri-query|contains: - '&textdomain=/' - '&textdomain=%' - '&name=/' - '&name=%' select_status_code: sc-status: 200 condition: selection_endpoint and selection_path_select and select_status_code
Known false positives
- Unknown