- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- IPS : CVE-2020-9615 Signature
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS : CVE-2020-9615 Signature
Hello,
After new CVE has released, when the IPS signature release on Firewall(Day or Week)? For example, CVE-2020-9615.
Thank you
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In case you need to create a custom rule or need a signature that is not published via Checkpoint feeds you can always import a snort rule if one exists for this signature.
eg. https://blog.snort.org/2020/03/snort-rule-update-for-march-10-2020.html
- Use the snort importer config on the manager, set to detect only and run the script to check IPS performance for this signature.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There has to be enough details made available about the CVE for a signature to be developed.
It also has to be exploitable over the network.
This one in particular requires local access to the Mac, as described here: https://gizmodo.com/you-need-to-update-adobe-acrobat-for-macos-right-now-1843466382
We added signatures for several other Adobe-related CVEs yesterday.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In case you need to create a custom rule or need a signature that is not published via Checkpoint feeds you can always import a snort rule if one exists for this signature.
eg. https://blog.snort.org/2020/03/snort-rule-update-for-march-10-2020.html
- Use the snort importer config on the manager, set to detect only and run the script to check IPS performance for this signature.
