IDS/IPS Signatures for CVE 2022-22965 (Spring4Shell)
JurjenArnold
Newbie ✭
Will there be signatures released for CVE 2022-22965 (Spring4Shell)?
I see several vendors (Trend Micro, Sophos, CloudFlare, Fortinet) that have them already since last friday, but when I checked a few minutes ago, I saw no new signatures on our firewalls.
Category: Firewall Security Services
0
Answers
@JurjenArnold
Sonicwall has released below signatures.
SonicWall’s, (IPS) Intrusion Prevention System, provides protection against this threat:
• IPS: 2609 JAVA Spring Framework Command Injection (Spring4Shell)
• IPS: 13431 JAVA Spring Framework Remote Code Execution (Spring4Shell) 2
• IPS: 13432 JAVA Spring Framework Remote Code Execution (Spring4Shell) G-1
• IPS: 13443 JAVA Spring Framework Remote Code Execution (Spring4Shell) G-2
• IPS: 13444 JAVA Spring Framework Remote Code Execution (Spring4Shell) IOC