ATTACK [PTsecurity] Cisco Adaptive Security Appliance 8.x SNMP overflow RCE Attempt
Sourceptresearch/attackdetection
CreatedDecember 13, 2021
UpdatedDecember 13, 2021
Classificationattempted-admin
alert udp any any -> $HOME_NET 161 (msg:"ATTACK [PTsecurity] Cisco Adaptive Security Appliance 8.x SNMP overflow RCE Attempt"; byte_jump:1, 6; content:"|A5|"; content:"|2B 06 01 02 01 01 01|"; distance:0; content:"|2B 06 01 04 01 09 09 83 6B 01 03 03 01 01 05 09|"; isdataat:30,relative; reference:url, blogs.cisco.com/security/shadow-brokers; reference:cve, 2016-6366; classtype:attempted-admin; reference:url, github.com/ptresearch/AttackDetection; sid:10000099; rev:2;)
References
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!