Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Update Details

Security Intelligence Center
Print

Update #3383 (05/18/2021)

4 new signatures:

MEDIUMHTTP:STC:DL:SFMK-OFC-PMD-OOBHTTP: SoftMaker Office PlanMaker PMD Out of Bounds Write
MEDIUMHTTP:DIR:SINEC-NMS-FILEUTLS-TRVHTTP: Siemens SINEC NMS FirmwareFileUtils extractToFolder Directory Traversal
CRITICALHTTP:CTS:CAYIN-CMS-COMMAND-INJHTTP: Cayin CMS CVE-2020-7357 Command Injection
CRITICALHTTP:CTS:SOLARWINDS-NCM-VST-AFWHTTP: SolarWinds Network Configuration Manager VulnerabilitySettings Arbitrary File Write

2 updated signatures:

MEDIUMHTTP:APACHE:OPENMEETINGS-NT-DOSHTTP: Apache OpenMeetings NetTest Web Service Denial of Service
CRITICALHTTP:CTS:VMWARE-MUL-CNFG-CMDINJHTTP: VMware Multiple Products Configurator Command Injection


Details of the signatures included within this bulletin:


HTTP:STC:DL:SFMK-OFC-PMD-OOB - HTTP: SoftMaker Office PlanMaker PMD Out of Bounds Write

Severity: MEDIUM

Description:

This signature detects attempts to exploit a known vulnerability against SoftMaker Office PlanMaker. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the SoftMaker Office.

Supported On:

idp-5.1.110161014, idp-4.1.0, mx-16.1, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, srx-17.4, idp-5.1.110170603, vsrx3bsd-18.2, srx-18.2, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, srx-branch-19.1, vsrx-19.2, srx-19.2, srx-branch-19.2, vsrx3bsd-19.2, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, j-series-9.5, mx-11.4, srx-12.1, srx-branch-12.1, vsrx-12.1, vsrx-15.1

References:

  • cve: CVE-2020-13580

Affected Products:

  • Softmaker planmaker_2021 1014

HTTP:DIR:SINEC-NMS-FILEUTLS-TRV - HTTP: Siemens SINEC NMS FirmwareFileUtils extractToFolder Directory Traversal

Severity: MEDIUM

Description:

This signature detects attempts to exploit a known vulnerability against Siemens SINEC NMS. A successful attack can lead to directory traversal and arbitrary code execution.

Supported On:

idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1

References:

  • url: https://www.zerodayinitiative.com/advisories/ZDI-21-253/
  • cve: CVE-2020-25237

Affected Products:

  • Siemens sinema_server
  • Siemens sinec_network_management_system 1.0
  • Siemens sinec_network_management_system
  • Siemens sinema_server 14.0

HTTP:APACHE:OPENMEETINGS-NT-DOS - HTTP: Apache OpenMeetings NetTest Web Service Denial of Service

Severity: MEDIUM

Description:

This signature detects attempts to exploit a known vulnerability against Apache OpenMeetings. A successful attack can result in a denial-of-service condition.

Supported On:

idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1

References:

  • cve: CVE-2021-27576
  • url: http://openmeetings.apache.org/security.html
  • cve: CVE-2020-13951

Affected Products:

  • Apache openmeetings 4.0.0

HTTP:CTS:VMWARE-MUL-CNFG-CMDINJ - HTTP: VMware Multiple Products Configurator Command Injection

Severity: CRITICAL

Description:

This signature detects attempts to exploit a known vulnerability against multiple VMware products. A successful attack can lead to command injection and arbitrary code execution.

Supported On:

idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1

References:

  • cve: CVE-2020-4006
  • url: https://www.vmware.com/security/advisories/VMSA-2020-0027.html

Affected Products:

  • Vmware cloud_foundation 4.0
  • Vmware cloud_foundation 4.0.1
  • Vmware vrealize_suite_lifecycle_manager 8.0-8.2

HTTP:CTS:SOLARWINDS-NCM-VST-AFW - HTTP: SolarWinds Network Configuration Manager VulnerabilitySettings Arbitrary File Write

Severity: CRITICAL

Description:

This signature detects attempts to exploit a known vulnerability against SolarWinds Network Configuration Manager. A successful attack can lead to arbitrary code execution.

Supported On:

idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1

References:

  • url: https://support.solarwinds.com/SuccessCenter/s/article/NCM-2020-2-1-Hotfix-2?language=en_U
  • url: http://www.zerodayinitiative.com/advisories/ZDI-21-067/
  • cve: CVE-2020-27871

Affected Products:

  • Solarwinds orion_platform 2020.2.1

HTTP:CTS:CAYIN-CMS-COMMAND-INJ - HTTP: Cayin CMS CVE-2020-7357 Command Injection

Severity: CRITICAL

Description:

This signature detects attempts to exploit a known vulnerability against Cayin CMS. A successful attack can lead to command injection and arbitrary code execution.

Supported On:

idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1

References:

  • cve: CVE-2020-7357

Affected Products:

  • Cayintech cms 7.5
  • Cayintech cms 8.0
  • Cayintech cms 8.2
Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out