This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS for CVE-2020-16898 / CVE-2020-16899

Hi,

about Sophos IPS and recently hyped CVE Ping of death / bad neighbour:

Snort has detections for the attack on CVE-2020-16898 / CVE-2020-16899

Those are:
https://www.snort.org/rule_docs/1-55984
https://www.snort.org/rule_docs/1-55993

There is a new Sophos IPS Document / Pattern V 9.17.53

Sophos IPS shows different names for the patterns than snort.
Made it a bit difficult to find on my XG.
Sophos' IDs are
2304055
2304163

Current IPS Detections on XG for those ICMP IPv6 attacks contain the CVE ID in their name:

OS-WINDOWS Microsoft Windows CVE-2020-16898 IPV6 Stack Overflow Vulnerability

2304055

os-windows

1 - Critical

Windows

Server

Drop packet
OS-WINDOWS Microsoft Windows CVE-2020-16898 IPV6 Stack Overflow Vulnerability

2304163

os-windows

1 - Critical

Windows

Server

Drop packet

Thanks for the quick implementation of the patterns!



This thread was automatically locked due to age.
Parents Reply Children
No Data