SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.
SERVER-OTHER Delta Electronics InfraSuite Device Master information disclosure attempt
This rule looks for InfraSuite commands sent to Delta Electronics servers that contain path traversal sequences in either the "fileName" or "value__" parameters. Successful exploitation may allow an attacker to retrieve arbitrary files from the device, leading to information disclosure.
This rule fires on attempts to exploit an information disclosure vulnerability in Delta Electronics InfraSuite Device Master servers.
No public information
No known false positives
Cisco Talos Intelligence Group
Rule Categories::Server::Other
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
MITRE::ATT&CK Framework::Enterprise::Discovery::System Information Discovery
Vulnerability::Severity::High
Vulnerability::Severity::Critical
Information Leak
Information Leakage happens when an attacker manipulates a system into revealing sensitive information, either through malformed input or by taking advantage of another feature of the system.
CVE-2022-41657 |
Loading description
|