""ET EXPLOIT Xiongmai/HiSilicon DVR - OpenTelnet Inbound - Possilbe CVE-2020-22253 Attempt""

SID: 2041646

Revision: 1

Class Type: attempted-recon

Metadata: attack_target IoT, created_at 2022_12_02, cve CVE_2020_22253, deployment Perimeter, confidence High, signature_severity Informational, updated_at 2022_12_02

Reference:

  • cve

  • 2020-22253

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: $HOME_NET

Destination Port: 9530

Flow: established,to_server

Contents:

  • Value: "|13|OpenTelnet:OpenOnce"

Within:

PCRE:

Special Options:

source