""ET EXPLOIT Possible SolarWinds Orion API Local File Disclosure (SWNetPerfMon.db) (CVE-2020-10148)""

SID: 2031460

Revision: 2

Class Type: web-application-attack

Metadata: affected_product Web_Server_Applications, attack_target Client_Endpoint, created_at 2020_12_29, cve CVE_2020_10148, deployment Perimeter, updated_at 2020_12_29

Reference:

  • cve

  • 2020-10148

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: any

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "GET|20|" Depth: 4

  • Value: "/SWNetPerfMon.db.i18n.ashx?"

Within: 100

PCRE:

Special Options:

  • nocase

source