cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3304
Views
10
Helpful
3
Replies

Find FireSight/Sourcefire rule(s) from CVE?

cshutters
Level 1
Level 1

All,

 

I have been attempting to identify which FireSight/Sourcefire rule(s) cover a particular CVE identifier.  The CVE information is often found within a particular rule, but I have not been able to discover any way within the Defense Center to search by CVE.

 

We have a Defense Center 750 running code version 5.3.1.1 (OS version 5.3.0).

 

Thanks in advance!

 

Chris Shutters

cshutters <at> csu.org

 

3 Replies 3

adhogan
Level 1
Level 1

Edit your Intrusion Policy and go to the Rules section.

On the left side accordion panel select "Rule Content."

Click Reference

Click CVE ID

Enter CVE ID and click OK.

adhogan,

 

Thank you!  I suspect it is unlikely that I would have ever found that.

 

Chris

Hi, Is anyway able to create CSV report to show rules with associate CVE ID?

We have Defense center 3500.

Please advise

Review Cisco Networking for a $25 gift card