Attack Surface Management Discovery Engine release v2024.02.15
This Attack Surface Management Discovery Engine release includes:
Bug Fixes
- Use AWS Lambda as backup to check s3 bucket existence
- Fixed release date and enhanced description/remediation for leaked secrets Issue
- Citrix Product CPE cleanup
- Only hide an Entity if connection reset is the only fingerprint
- Fixed Godaddy integration errors
- Fixed generic fingerprints to remove unnecessary follow-on http calls
Vulnerability Checks
- Added CVE-2024-22024 Vulnerability Check - (Ivanti Connect Secure - XML External Entity Injection)
Technology Fingerprints
- Microsoft Exchange fingerprint enhancements
- Added Ivanti Avalanche Detection Technology Fingerprint
- Improved the following twelve fingerprints:
- Adobe CRXDE Lite
- Apache Hadoop
- Connect Box
- Connectwise
- Draytek
- Entrust IdentityGuard
- Hadoop Yarn
- HiveManager
- Honeywell Tuxedo
- Idera
- Keenetic
- One Identity Password Manager