ATTACK [PTsecurity] Cisco Adaptive Security Appliance 8.x SNMP overflow RCE Attempt

SID: 10000099Rev: 20 views
Sourceptresearch/attackdetection
CreatedDecember 13, 2021
UpdatedDecember 13, 2021
Classificationattempted-admin
alert udp any any -> $HOME_NET 161 (msg:"ATTACK [PTsecurity] Cisco Adaptive Security Appliance 8.x SNMP overflow RCE Attempt"; byte_jump:1, 6; content:"|A5|"; content:"|2B 06 01 02 01 01 01|"; distance:0; content:"|2B 06 01 04 01 09 09 83 6B 01 03 03 01 01 05 09|"; isdataat:30,relative; reference:url, blogs.cisco.com/security/shadow-brokers; reference:cve, 2016-6366; classtype:attempted-admin; reference:url, github.com/ptresearch/AttackDetection; sid:10000099; rev:2;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!