THL HUNT GENERIC-CVE-2023-20198 Cisco IOS-XE Forged Bare-Hex Authorization Token (Public Exploit Class)

SID: 3500190Rev: 1Enabled2 views
Filehunters-ledger.rules
CreatedSeptember 2, 2026
UpdatedSeptember 2, 2026
Classificationweb-application-attack
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"THL HUNT GENERIC-CVE-2023-20198 Cisco IOS-XE Forged Bare-Hex Authorization Token (Public Exploit Class)"; flow:established,to_server; content:"Authorization"; http_header; pcre:"/^Authorization:\s*[a-f0-9]{18}\s*$/mHi"; threshold:type limit,track by_src,count 1,seconds 3600; classtype:web-application-attack; sid:3500190; rev:1; metadata:author The_Hunters_Ledger, date 2026-08-17, reference https://the-hunters-ledger.com/hunting-detections/opendirectory-13-140-145-210-weblogic-deserialization-telecom-harvester-20260817-detections/;)

Metadata

authorThe_Hunters_Ledger
date2026-08-17
referencehttps://the-hunters-ledger.com/hunting-detections/opendirectory-13-140-145-210-weblogic-deserialization-telecom-harvester-20260817-detections/

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!