""ET EXPLOIT Adobe ColdFusion Unauthorized File Access (CVE-2024-20767)""

SID: 2053030

Revision: 1

Class Type: attempted-user

Metadata: affected_product Adobe_Coldfusion, attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2024_05_30, cve CVE_2024_20767, deployment Perimeter, confidence High, signature_severity Major, updated_at 2024_05_30

Reference:

  • cve

  • 2024-20767

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "GET"

  • Value: "/pms?module=logging&file_name=" Depth: 30

  • Value: "|2e 2e 2f|"

  • Value: "&number_of_lines="

  • Value: "uuid="

Within:

PCRE:

Special Options:

  • http_method

  • http_uri

  • fast_pattern

  • http_uri

  • http_uri

  • http_header

source