SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Microsoft Windows Open Management Infrastructure remote code execution attempt
This rule looks for attempts to bypass authentication to invoke an unsafe function in the Windows Open Management Infrastructure web application.
This rule fires on attempts to exploit a remote code execution vulnerability in Microsoft Windows.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
Rule Categories::Server::Web Applications
Rule Categories::Operating Systems::Windows
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Authentication Bypass
An Authentication Bypass occurs when there is a way to avoid providing user credentials to a system before performing restricted operations on said system.
CVE-2021-38647 |
Loading description
|