ET EXPLOIT Possible Dovecot Memory Corruption Inbound (CVE-2019-11500)

SID: 2033451Rev: 12 views
History
Sourceet/open
CreatedJuly 27, 2021
UpdatedJuly 27, 2021
Classificationattempted-admin
alert tcp any any -> [$HOME_NET,$SMTP_SERVERS] [25,143,993,995] (msg:"ET EXPLOIT Possible Dovecot Memory Corruption Inbound (CVE-2019-11500)"; flow:to_server,established; content:"|22|"; content:"|00|"; distance:0; content:"|5c|"; distance:200; reference:url,nickroessler.com/dovecot-cve-2019-11500/; reference:cve,2019-11500; classtype:attempted-admin; sid:2033451; rev:1; metadata:attack_target Server, created_at 2021_07_27, cve CVE_2019_11500, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2021_07_27, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)

Metadata

attack targetServer
created at2021_07_27
deploymentInternal
confidenceMedium
signature severityMajor
tagExploit
updated at2021_07_27
mitre tactic idTA0001
mitre tactic nameInitial_Access
mitre technique idT1190
mitre technique nameExploit_Public_Facing_Application

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!