""ET WEB_SPECIFIC_APPS Possible MobileIron MDM RCE Inbound (CVE-2020-15505)""

SID: 2033606

Revision: 1

Class Type: attempted-admin

Metadata: created_at 2021_07_28, cve CVE_2020_15505, updated_at 2021_07_28

Reference:

  • cve

  • 2020-15505

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: [$HOME_NET,$HTTP_SERVERS]

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "POST"

  • Value: "/mifs/|2e 3b|/"

  • Value: "|63 02 00 48 00 84|" Depth: 9

  • Value: "B|00|e|00|a|00|n|00|F|00|a|00|c|00|"

  • Value: "r|00|m|00|i|00 3a 00 2f 00 2f|"

Within:

PCRE:

Special Options:

  • http_method

  • fast_pattern

  • http_uri

  • http_uri

  • http_uri

  • http_uri

source