Intrusion Prevention

Suricata.TCP.Handshake.Content.Detection.Bypass

Description

This indicates an attack attempt to exploit a Security Policy Bypass Vulnerability in OISF Suricata.
The vulnerability is due to an error in the vulnerable application when handling a maliciously crafted response. An attacker can exploit this to bypass security policies on the on the affected machine via maliciously crafted response.

Affected Products

OISF Suricata prior to 4.0.4

Impact

Security Bypass: Remote attackers can bypass security checks of vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor:
https://redmine.openinfosecfoundation.org/issues/2427

CVE References

CVE-2018-6794