<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Alert ID 7002</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/125838/alert-id-7002</link><description>Hi Team, 
 
 I am getting more than 80 mails on daily basis. Can some one tell me how I can resolve this issue. 
 Device XG230 
 Alert ID: 7002 Message: OS-WINDOWS Microsoft Windows SMB Server SMBv1 CVE-2017-0147 Information Disclosure</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Alert ID 7002</title><link>https://community.sophos.com/thread/467453?ContentTypeID=1</link><pubDate>Tue, 04 May 2021 20:58:15 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3875c248-f19f-4373-95ea-097b5553bd14</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Are PDFs being received in email causing the issue. Which version of XG are you using and do you auto update on your firmware enabled?&lt;/p&gt;
&lt;p&gt;ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Alert ID 7002</title><link>https://community.sophos.com/thread/467440?ContentTypeID=1</link><pubDate>Tue, 04 May 2021 15:35:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0bf6b8f0-0451-4eb2-a88b-df06ec9c6176</guid><dc:creator>Herbert Navas</dc:creator><description>&lt;p&gt;I&amp;#39;m getting the same alert! But no KB to look or any info related and support does not help&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Alert ID 7002</title><link>https://community.sophos.com/thread/460244?ContentTypeID=1</link><pubDate>Mon, 08 Feb 2021 18:37:05 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8a7c693e-5f4f-4658-8c30-60ea3d718dec</guid><dc:creator>Duane Bruce</dc:creator><description>&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;I will give that a try.&lt;/p&gt;
&lt;div style="background:initial;border:initial;border-collapse:initial;border-radius:initial;border-spacing:initial;color:initial;clear:initial;float:initial;font:initial;text-align:initial;text-decoration:initial;text-indent:initial;vertical-align:initial;"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Alert ID 7002</title><link>https://community.sophos.com/thread/460189?ContentTypeID=1</link><pubDate>Mon, 08 Feb 2021 10:55:20 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d27ae6af-9f18-4beb-b19e-1dcd0246a150</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;try this and then search the KBA for other tuning options&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/126/Screen-Shot-2021_2D00_02_2D00_08-at-21.53.27.png" /&gt;&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Alert ID 7002</title><link>https://community.sophos.com/thread/460158?ContentTypeID=1</link><pubDate>Sun, 07 Feb 2021 22:30:44 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4427380f-1999-4931-b9e9-848fc707d010</guid><dc:creator>Duane Bruce</dc:creator><description>&lt;p&gt;1} &amp;quot;tune&amp;quot;?&lt;/p&gt;
&lt;p&gt;2} The device is fully up to date and uncompromised (based on my inspection).&amp;nbsp; Device didn&amp;#39;t have adobe installed and only one pdf present which I deleted.&amp;nbsp; Still no joy,,&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;div style="background:initial;border:initial;border-collapse:initial;border-radius:initial;border-spacing:initial;color:initial;clear:initial;float:initial;font:initial;text-align:initial;text-decoration:initial;text-indent:initial;vertical-align:initial;"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Alert ID 7002</title><link>https://community.sophos.com/thread/460156?ContentTypeID=1</link><pubDate>Sun, 07 Feb 2021 22:27:16 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5b436a1f-3add-4ef5-9fe8-bcbf442cda39</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Sounds like you need to tune your XG and also see if there is an adobe update.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Alert ID 7002</title><link>https://community.sophos.com/thread/460155?ContentTypeID=1</link><pubDate>Sun, 07 Feb 2021 22:22:29 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d4ba9be5-0415-48ed-aed6-f23c76676e28</guid><dc:creator>Duane Bruce</dc:creator><description>&lt;p&gt;I am seeing the same ID over 200 times in the last 10 hours for&amp;nbsp;&lt;/p&gt;
&lt;div&gt;&lt;b&gt;Attack&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;:&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;FILE-PDF Adobe Acrobat ImageConversion PCX Parsing Out-Of-Bounds Write yet my control center shows no active attacks?!&amp;nbsp; I inspected the source (a fully up to date ios 14 iphone) and can find nothing amiss on the device.&amp;nbsp; REALLY scratching my head.&lt;/div&gt;
&lt;div style="background:initial;border:initial;border-collapse:initial;border-radius:initial;border-spacing:initial;color:initial;clear:initial;float:initial;font:initial;text-align:initial;text-decoration:initial;text-indent:initial;vertical-align:initial;"&gt;&lt;/div&gt;
&lt;div style="background:initial;border:initial;border-collapse:initial;border-radius:initial;border-spacing:initial;color:initial;clear:initial;float:initial;font:initial;text-align:initial;text-decoration:initial;text-indent:initial;vertical-align:initial;"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Alert ID 7002</title><link>https://community.sophos.com/thread/460111?ContentTypeID=1</link><pubDate>Sat, 06 Feb 2021 23:32:28 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7367c779-080a-4aa5-a4f2-526f2b6ed621</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;identify which internal device is triggering the alarm and review its settings.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>