2020 年 4 月的签名更新

针对 2020-04-27 周发现的漏洞生成新的特征码规则。您可以下载并配置这些签名规则,以保护您的设备免受安全漏洞攻击。

签名版本

签名版本 44 适用于 NetScaler VPX 11.1、NetScaler 12.0、Citrix ADC 12.1、Citrix ADC 13.0 平台。

注意:

启用发布主体和响应主体签名规则可能会影响 Citrix ADC CPU。

常见漏洞条目 (CVE) 见解

以下是签名规则、CVE ID 及其描述的列表。

签名规则 CVE ID 说明
999683 CVE-2020-9043 WEB-WORDPRESS wpCentral Plugin Prior To 1.5.1 - Connection Key Disclosure Vulnerability (CVE-2020-9043)
999684   WEB-WORDPRESS Duplicate-Post Plugin Version 3.2.3 and Prior - Persistent Cross-site Scripting
999685   WEB-WORDPRESS Duplicate-Post Plugin Version 3.2.3 and Prior - Persistent Cross-site Scripting
999686 CVE-2020-0618 WEB-MISC Microsoft SQL Server Reporting Services - Remote Code Execution Vulnerability (CVE-2020-0618)
999687 CVE-2019-16278 WEB-MISC Nostromo Nhttpd Prior to 1.3.7 - Strcutl Function Allows Unauthenticated Remote Code Execution (CVE-2019-16278)
999688 CVE-2019-1937 WEB-MISC Cisco UCS Director 6.6.0.0 to 6.6.1.0 and 6.7.0.0 to 6.7.1.0 - Authentication Bypass Vulnerability (CVE-2019-1937)
999689   WEB-WORDPRESS Duplicate-Post Plugin Version 3.2.3 and Prior - Persistent Cross-site Scripting
999690 CVE-2020-9006 WEB-WORDPRESS Popup Builder Plugin Prior to 3.0 - SQL Injection Via PHP Deserialization Vulnerability (CVE-2020-9006)
999691   WEB-WORDPRESS Duplicate-Post Plugin Version 3.2.3 and Prior - Persistent Cross-site Scripting
999692   WEB-MISC prevent request smuggling via content-length and transfer-encoding header
999693   WEB-WORDPRESS ThemeGrill Demo Importer Plugin Prior To 1.6.3 - Authentication Bypass And Database Wipe Vulnerability
999694 CVE-2019-17237 WEB-WORDPRESS IgniteUp Coming Soon and Maintenance Mode Plugin Prior to 3.4.1 - CSRF Vulnerability Via Message (CVE-2019-17237)
999695 CVE-2019-17237 WEB-WORDPRESS IgniteUp Coming Soon and Maintenance Mode Plugin Prior to 3.4.1 - CSRF Vulnerability Via Subject (CVE-2019-17237)

2020 年 4 月的签名更新