Back to Rule

Rule History

SID: 2030240 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 1Jun 2, 2020, 12:00 PM

ET EXPLOIT Possible VMware Cloud Director RCE Attempt (CVE-2020-3956)

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Possible VMware Cloud Director RCE Attempt (CVE-2020-3956)"; flow:established,to_server; http.method; content:"PUT"; http.cookie; content:"vcloud_jwt="; startswith; http.request_body; content:"|3a|Host|3e 24 7b|"; content:".getDeclaredConstructors|28 29 5b|"; distance:0; fast_pattern; flowbits:set,ET.20203956; reference:url,citadelo.com/en/blog/full-infrastructure-takeover-of-vmware-cloud-director-CVE-2020-3956/; classtype:attempted-admin; sid:2030240; rev:1; metadata:affected_product VMware, attack_target Server, created_at 2020_06_02, cve CVE_2020_3956, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2020_06_02;)

Jun 2, 2020, 12:00 PM

Jun 2, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

Sep 21, 2024, 3:00 AM

rules/emerging-exploit.rules