Technical Tip: Using FortiSIEM to detect Synacor Zimbra Collaboration MBoxImport Vulnerabilities | CVE-2022-27925, CVE-2022-37042, CVE-2022-30333
- August 26, 2022
- 0 replies
- 596 views
| Description | This article describes how to use custom Rules in FortiSIEM to raise Incidents for incident response related to attacks that attempt to exploit the Zimbra Collaboration Arbitrary File Upload and Authentication Bypass Vulnerability.
A report is also provided to gain historical visibility into the logs.
The article will be continually updated as more information becomes available. |
| Scope | The Rules and Reports leverage logs from other Fortinet products that can be used to detect the attack in addition to FortiGate logs.
For more information on the vulnerabilities, visit FortiGuard Outbreak alert. |
| Solution | 1) Use FortiSIEM_ZimbraRCE_Reports_v1.xml as the file to import the Reports.
- Navigate to Resource / Reports. - Select the Import option under More.
2) Use fortiSIEM_ZimbraRCE_Rules_v1.xml as the file to import the Rules.
- Select the Import. - Select fortiSIEM_ZimbraRCE_Rules_v1.xml and import. - Select the Import. - Select fortiSIEM_ZimbraRCE_Rules_v1.xml and import.
|
