""ET WEB_SPECIFIC_APPS Fortra FileCatalyst Workflow Insecure HSQLDB Default Credentials""

SID: 2055590

Revision: 1

Class Type: attempted-admin

Metadata: attack_target Server, tls_state plaintext, created_at 2024_08_29, cve CVE_2024_6633, deployment Perimeter, confidence High, signature_severity Critical, updated_at 2024_08_29, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1078, mitre_technique_name Valid_Accounts

Reference:

  • cve

  • 2024-6633

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: 4406

Flow: established,to_server

Contents:

  • Value: "|02|SA"

  • Value: "|0b|GOSENSGO613"

Within: 12

PCRE:

Special Options:

  • nocase

  • fast_pattern

source