Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS for CVE-2020-16898 / CVE-2020-16899

Hi,

about Sophos IPS and recently hyped CVE Ping of death / bad neighbour:

Snort has detections for the attack on CVE-2020-16898 / CVE-2020-16899

Those are:
https://www.snort.org/rule_docs/1-55984
https://www.snort.org/rule_docs/1-55993

There is a new Sophos IPS Document / Pattern V 9.17.53

Sophos IPS shows different names for the patterns than snort.
Made it a bit difficult to find on my XG.
Sophos' IDs are
2304055
2304163

Current IPS Detections on XG for those ICMP IPv6 attacks contain the CVE ID in their name:

OS-WINDOWS Microsoft Windows CVE-2020-16898 IPV6 Stack Overflow Vulnerability

2304055

os-windows

1 - Critical

Windows

Server

Drop packet
OS-WINDOWS Microsoft Windows CVE-2020-16898 IPV6 Stack Overflow Vulnerability

2304163

os-windows

1 - Critical

Windows

Server

Drop packet

Thanks for the quick implementation of the patterns!



This thread was automatically locked due to age.
Parents Reply Children
No Data