SELECTED BY THE TALOS SECURITY INTELLIGENCE AND RESEARCH GROUP
Title: Cisco urging users to update Firepower Management Center immediately to fix severe bug
Description: Cisco disclosed a high-severity vulnerability in its Firepower Management Center last week that could allow an attacker to bypass the usual authentication steps. The vulnerability -- which was assigned a 9.8 severity score out of 10 -- exists in the way Firepower handles LDAP authentication responses from an external authentication server. An attacker could exploit this flaw by sending a specially crafted HTTP request to the device. Users are also encouraged to turn off LDAP configuration on their devices. Cisco also disclosed seven high-severity flaws and 19 medium-severity security issues in some of its other products, including Smart Software Manager.
Reference: https://www.zdnet.com/article/cisco-patch-this-critical-firewall-bug-in-firepower-management-center/
Snort SIDs: 52627 - 52632, 52641 - 52646
Title: Exploitation of Citrix vulnerability spikes after POC released, patches followed
Description: Citrix rushed out a patch for its Application Delivery Controller (ADC) and Citrix Gateway products after proof of concept code leaked for a major vulnerability. The company first disclosed CVE-2019-19781 in December, saying a patch was forthcoming. But security researchers have noticed an uptick in exploitation attacks, forcing Citrix to move up its timeline.
Reference: https://threatpost.com/citrix-patch-rollout-critical-rce-flaw/152041/
Snort SIDs: 52620