SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Citrix ADC and Gateway information disclosure attempt
This rule detects an attempted information disclosure by an unauthenticated user in vulnerable versions of Citrix ADC and Citrix Gateway by searching for specific parameters sent in an exploit attempt.
This rule detects an attempted information disclosure by an unauthenticated user in vulnerable versions of Citrix ADC and Citrix Gateway.
No public information
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
MITRE::ATT&CK Framework::Enterprise::Reconnaissance::Gather Victim Host Information
MITRE::ATT&CK Framework::Enterprise::Initial Access::External Remote Services
Vulnerability::Severity::High
Vulnerability::Severity::Critical
Vulnerability::Severity::Medium
Information Leak
Information Leakage happens when an attacker manipulates a system into revealing sensitive information, either through malformed input or by taking advantage of another feature of the system.
CVE-2020-8196 |
Loading description
|
CVE-2020-8195 |
Loading description
|
Tactic: Initial Access
Technique: Exploit Public-Facing Application
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org