SID: 2032095

Revision: 3

Class Type: attempted-admin

Metadata: attack_target IoT, created_at 2021_03_17, cve CVE_2021_27561_CVE_2021_27562, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2021_09_20

Reference:

  • cve

  • 2021-27561

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "/premise/front/getPingData?url=http|3a 2f 2f|0.0.0.0|3a|9600/sm/api/v1/firewall/zone/services?zone=" Depth: 91

Within:

PCRE:

Special Options:

  • fast_pattern

  • http_uri

source