Skip to main content
FSM_FTNT
Staff
Staff
August 26, 2022

Technical Tip: Using FortiSIEM to detect Synacor Zimbra Collaboration MBoxImport Vulnerabilities | CVE-2022-27925, CVE-2022-37042, CVE-2022-30333

  • August 26, 2022
  • 0 replies
  • 596 views
Description

This article describes how to use custom Rules in FortiSIEM to raise Incidents for incident response related to attacks that attempt to exploit the Zimbra Collaboration Arbitrary File Upload and Authentication Bypass Vulnerability.

 

A report is also provided to gain historical visibility into the logs.

 

The article will be continually updated as more information becomes available.

Scope

The Rules and Reports leverage logs from other Fortinet products that can be used to detect the attack in addition to FortiGate logs.

 

For more information on the vulnerabilities, visit FortiGuard Outbreak alert.

Solution

1) Use FortiSIEM_ZimbraRCE_Reports_v1.xml as the file to import the Reports.

 

- Navigate to Resource / Reports.
- It is recommended to create a new group under Resource / Reports / Security called 'Zimbra RCE' and import reports to this group.

- Select the Import option under More.
- Select FortiSIEM_ZimbraRCE_Reports_v1.xml and import.

 

2) Use fortiSIEM_ZimbraRCE_Rules_v1.xml as the file to import the Rules.


- Navigate to Resource / Rules.
- It is recommended to create a new group under Resource / Rules / Security / Threat Hunting is created called 'Zimbra RCE' and import the rules to this group.

- Select the Import.

- Select fortiSIEM_ZimbraRCE_Rules_v1.xml and import.

- Select the Import.

- Select fortiSIEM_ZimbraRCE_Rules_v1.xml and import.
- Validate that these Rules are enabled.


FortiSIEM provides content packs for easy installation of these Rules and Reports:


What is included in Fortinet_FortiSIEM_Zimbra_RCE.zip?


- A FortiSIEM Rule to help with detection.
- A FortiSIEM Report to help with historical reporting.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!