SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP ARRIS VAP2500 list_mac_address cmb_macaddrfilter command injection attempt
This rule will trigger if - POST request is destined to vulnerable URI `/list_mac_address.php"` - POST body contains vulnerable parameter `cmb_macaddrfilter` and shell meta-characters are present in its value.
These rules detects an exploit for Command Injection Remote Code Execution vulnerability present in ARRIS VAP2500 default public facing web server. This vulnerability can allow an un-authenticated user to execute code with root privileges.
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None
Tactic: Initial Access
Technique: Exploit Public-Facing Application
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org