cscli scenarios install crowdsecurity/CVE-2022-37042Detects attempts of exploit of CVE-2022-37042 RCE vulnerability.
1type: trigger2#debug: true3name: crowdsecurity/CVE-2022-370424description: "Detect CVE-2022-37042 exploits"5filter: |6 (7 Upper(evt.Meta.http_path) contains Upper('/service/extension/backup/mboximport?account-name=admin&ow=2&no-switch=1&append=1') ||8 Upper(evt.Meta.http_path) contains Upper('/service/extension/backup/mboximport?account-name=admin&account-status=1&ow=cmd')9 )10 and evt.Meta.http_status startsWith ('40') and11 Upper(evt.Meta.http_verb) == 'POST'1213blackhole: 2m14groupby: "evt.Meta.source_ip"15labels:16 type: exploit17 remediation: true18 classification:19 - attack.T159520 - attack.T119021 - cve.CVE-2022-3704222 spoofable: 023 confidence: 324 behavior: "http:exploit"25 label: "ZCS CVE-2022-37042"26 service: zimbra27