mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
name: Citrix ADC Exploitation CVE-2023-3519
|
||||
id: 76ac2dcb-333c-4a77-8ae9-2720cfae47a8
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2023-07-21'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
@@ -14,7 +14,7 @@ description: This analytic is designed to assist in hunting for potential exploi
|
||||
|
||||
Please be aware that this analytic is based on current understanding of the vulnerability, and adjustments may be required as more information becomes available.
|
||||
search: '| tstats count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Web where Web.url IN ("*/saml/login","/cgi/samlauth","*/saml/activelogin","/cgi/samlart?samlart=*","*/cgi/logout") Web.http_method=POST
|
||||
as lastTime from datamodel=Web where Web.url IN ("*/saml/login","/cgi/samlauth","*/saml/activelogin","/cgi/samlart?samlart=*","*/cgi/logout","/gwtest/formssso?event=start&target=*","/netscaler/ns_gui/vpn/*") Web.http_method=POST
|
||||
by Web.http_user_agent, Web.status Web.http_method, Web.url, Web.url_length, Web.src, Web.dest, sourcetype
|
||||
| `drop_dm_object_name("Web")`
|
||||
| `security_content_ctime(firstTime)`
|
||||
@@ -26,6 +26,8 @@ known_false_positives: False positives may be present based on organization use
|
||||
references:
|
||||
- https://blog.assetnote.io/2023/07/21/citrix-CVE-2023-3519-analysis/
|
||||
- https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467
|
||||
- https://securityintelligence.com/x-force/x-force-uncovers-global-netscaler-gateway-credential-harvesting-campaign/
|
||||
- https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
|
||||
tags:
|
||||
analytic_story:
|
||||
- Citrix Netscaler ADC CVE-2023-3519
|
||||
|
||||
@@ -20,6 +20,7 @@ known_false_positives: False positives may be present with legitimate applicatio
|
||||
references:
|
||||
- https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html
|
||||
- https://www.rapid7.com/blog/post/2023/10/04/etr-cve-2023-22515-zero-day-privilege-escalation-in-confluence-server-and-data-center/
|
||||
- https://attackerkb.com/topics/Q5f0ItSzw5/cve-2023-22515/rapid7-analysis
|
||||
tags:
|
||||
analytic_story:
|
||||
- CVE-2023-22515 Privilege Escalation Vulnerability Confluence Data Center and Server
|
||||
|
||||
Reference in New Issue
Block a user