{
    "description": "Derived from list posted by CISA at https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
    "name": "CISA published vulnerabilities",
    "id": "anchore_cisa_vulnerabilities",
    "policies": [
        {
            "comment": "CISA vulnerabilities that apply to packages in containers",
            "id": "a348aff0-ebb8-4b90-99ff-bb17740c1306",
            "name": "CISA Vulnerabilities List",
            "rules": [
                {
                    "action": "STOP",
                    "comment": "Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints.",
                    "gate": "vulnerabilities",
                    "id": "e612114b-d360-4fa0-993e-c754b8817604",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-27104"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call.",
                    "gate": "vulnerabilities",
                    "id": "1df5c885-902b-4e1b-9249-f3d9159e5961",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-27102"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html.",
                    "gate": "vulnerabilities",
                    "id": "0269aea2-b7ee-4cb7-80a3-a9960b7114de",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-27101"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html.",
                    "gate": "vulnerabilities",
                    "id": "55ba7d12-b827-4386-94af-566fa2750f35",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-27103"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
                    "gate": "vulnerabilities",
                    "id": "d6ef29c3-774d-480a-9da5-480008be54d8",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-21017"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
                    "gate": "vulnerabilities",
                    "id": "6a608f2d-bc36-44d6-becd-31859190275c",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-28550"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.",
                    "gate": "vulnerabilities",
                    "id": "1ace2209-1765-4977-820f-948810351325",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-4939"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.",
                    "gate": "vulnerabilities",
                    "id": "657d2338-86de-4e90-b779-52cd1bf0a089",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-15961"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.",
                    "gate": "vulnerabilities",
                    "id": "37a6234f-584a-4e31-9123-02040c6057fa",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-4878"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.",
                    "gate": "vulnerabilities",
                    "id": "3db395c8-6e03-40f2-b982-79e95bea9a30",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-5735"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "",
                    "gate": "vulnerabilities",
                    "id": "116568ed-379b-47f0-8537-9b8c00118ce0",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-2215"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "",
                    "gate": "vulnerabilities",
                    "id": "0d9746ea-46ae-40e3-8fbb-47dd4e23b38e",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0041"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "",
                    "gate": "vulnerabilities",
                    "id": "b0f40fa4-7bc4-456c-b16a-fe9dc5315826",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0069"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 contains a vulnerability which can lead to RCE.",
                    "gate": "vulnerabilities",
                    "id": "4ebccd29-9f0f-4df1-83eb-d7ca459d1f21",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-9805"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Apache HTTP server vulnerabilities allow an attacker to use a path traversal attack to map URLs to files outside the expected document root and perform RCE.",
                    "gate": "vulnerabilities",
                    "id": "eea929d6-97d0-41c5-91da-2cdb2accda02",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-42013"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration \"require all denied\", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.",
                    "gate": "vulnerabilities",
                    "id": "d9d1935f-7eb1-4e43-84dc-6431c5738fc8",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-41773"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.",
                    "gate": "vulnerabilities",
                    "id": "339c343d-172d-4c9f-aafd-202d89ffcf06",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-0211"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Apache Shiro before 1.2.5, when a cipher key has not been configured for the \"remember me\" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.",
                    "gate": "vulnerabilities",
                    "id": "ec29e7d7-e9c2-4f12-9b08-b6ecddacb206",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-4437"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).",
                    "gate": "vulnerabilities",
                    "id": "3b223f74-e871-440c-8042-780bdbeed4b1",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-17558"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.",
                    "gate": "vulnerabilities",
                    "id": "b95ea9b3-a5c8-482c-a76c-86b806d785e5",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-17530"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.",
                    "gate": "vulnerabilities",
                    "id": "6c252b47-f03c-46dd-8c31-15f9ee9a16bb",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-5638"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 contain a vulnerability which can allow for remote code execution.",
                    "gate": "vulnerabilities",
                    "id": "70921464-209f-46ce-a590-691417919561",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-11776"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Apple iOS and iPadOS Arbitrary Code Execution",
                    "gate": "vulnerabilities",
                    "id": "8273b928-1cb6-4200-9ca5-9acef2f0924e",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30858"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.",
                    "gate": "vulnerabilities",
                    "id": "3257e270-689c-4ff7-81d8-65f71d16f725",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-6223"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An integer overflow was addressed with improved input validation vulnerability affecting iOS devices that allows for remote code execution.",
                    "gate": "vulnerabilities",
                    "id": "03245231-0fba-4fe9-90cd-ec297cf3554f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30860"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A memory corruption issue was addressed with improved input validation. Processing a maliciously crafted font may lead to arbitrary code execution.",
                    "gate": "vulnerabilities",
                    "id": "966c12e6-3fe1-4cf4-bc5c-fab3dcb363ca",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-27930"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "",
                    "gate": "vulnerabilities",
                    "id": "23e2b3c8-5791-437a-b23f-e0f1acb9c9c2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30807"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A malicious application may be able to disclose kernel memory.",
                    "gate": "vulnerabilities",
                    "id": "aff85876-2345-45e2-b861-1a82e3015a7b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-27950"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A malicious application may be able to execute arbitrary code with kernel privileges.",
                    "gate": "vulnerabilities",
                    "id": "6e038b36-112c-4593-b082-04a5e315bf16",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-27932"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Processing a maliciously crafted PDF may lead to arbitrary code execution.",
                    "gate": "vulnerabilities",
                    "id": "22c74223-060e-4d05-8842-87ff211cca5f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30860"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination.",
                    "gate": "vulnerabilities",
                    "id": "a0e88a5f-0fff-4b0b-96b3-399da8cfb73a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-9818"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Processing a maliciously crafted mail message may lead to heap corruption.",
                    "gate": "vulnerabilities",
                    "id": "4dcc5959-ae7f-4c8d-846c-410481d49a4e",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-9819"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Use after free issue. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.",
                    "gate": "vulnerabilities",
                    "id": "fa6c2167-1caf-495b-aeed-bb54b84be345",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30762"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited",
                    "gate": "vulnerabilities",
                    "id": "38dbfbbd-6fb2-43a1-ac91-8ef97f1fc6e3",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1782"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.",
                    "gate": "vulnerabilities",
                    "id": "e9ff47cc-84ac-4424-9518-496040cd891b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1870"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.",
                    "gate": "vulnerabilities",
                    "id": "2a7a5274-20bd-48cf-a7c5-5011f1876d17",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1871"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..",
                    "gate": "vulnerabilities",
                    "id": "94025fba-e867-4df0-bb91-f1ddacf5c747",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1879"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.",
                    "gate": "vulnerabilities",
                    "id": "e7058702-77a9-45ce-be53-f9d6963937e7",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30661"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.",
                    "gate": "vulnerabilities",
                    "id": "b45694d3-2321-4b89-a7ab-23ef35b2267d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30666"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..",
                    "gate": "vulnerabilities",
                    "id": "7243e48f-55b6-4057-b284-d6258863ca2f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30713"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "\u00a0A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..",
                    "gate": "vulnerabilities",
                    "id": "ef96fdd2-4fdc-403e-b55a-ecb724b4e15c",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30657"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.",
                    "gate": "vulnerabilities",
                    "id": "fc598700-6439-46e0-8366-9336c4959f85",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30665"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Integer overflow. Processing maliciously crafted web content may lead to arbitrary code execution.",
                    "gate": "vulnerabilities",
                    "id": "79ef5db4-ab57-4116-a4ff-295ca36cdd32",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30663"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Memory corruption issue. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.",
                    "gate": "vulnerabilities",
                    "id": "a4273f16-426c-4eda-84ed-efae675f64ed",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30761"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Apple XNU kernel contains a type confusion vulnerability which allows a malicious application to execute arbitrary code with kernel privileges.",
                    "gate": "vulnerabilities",
                    "id": "d0baabf2-2b7c-4ed2-97dc-73546ea43934",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30869"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A memory consumption issue was addressed with improved memory handling. An application may be able to execute arbitrary code with kernel privileges.",
                    "gate": "vulnerabilities",
                    "id": "259474b3-605d-4ac1-89cd-0c039d96dc4e",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-9859"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A path traversal vulnerability in Arcadyan firmware could allow unauthenticated remote attackers to bypass authentication. It impacts many routers.",
                    "gate": "vulnerabilities",
                    "id": "933c1042-82f9-4f44-b7dd-23445d97f804",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-20090"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode. This vulnerability has known active exploitation against Yealink Device Management servers. It is assessed this product utilizes the affected Arm firmware.",
                    "gate": "vulnerabilities",
                    "id": "9d3b7f4e-4b95-4663-bc97-1cfac32461d9",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-27562"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r8p0 through r30p0.",
                    "gate": "vulnerabilities",
                    "id": "304937cf-77aa-43d3-80e7-e5fe76b6f38b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-28664"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.",
                    "gate": "vulnerabilities",
                    "id": "6f5f2d88-647d-4624-9fda-18e53c0ddaa5",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-28663"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.",
                    "gate": "vulnerabilities",
                    "id": "4ec3e0bd-979d-4684-b4bd-88de0760ecbc",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-3398"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Atlassian Confluence Server The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5 contains an OGNL injection vulnerability which allows an attacker to execute arbitrary code.",
                    "gate": "vulnerabilities",
                    "id": "d3e8d5b5-a8fa-4f56-adcb-0a973d43a1b2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-26084"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5, from version 3.1.0 before 3.1.6, from version 3.2.0 before 3.2.8, from version 3.3.0 before 3.3.5, and from version 3.4.0 before 3.4.4 are affected by this vulnerability.",
                    "gate": "vulnerabilities",
                    "id": "6b4d238c-a5b1-4a9d-aba5-0f0b04b0fc7d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-11580"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.",
                    "gate": "vulnerabilities",
                    "id": "9b34d4df-bc06-4951-a60e-2743bef355ea",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-3396"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "BQE BillQuick Web Suite 2018 through 2021 prior to 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation.",
                    "gate": "vulnerabilities",
                    "id": "2b3e756a-2a74-4c89-bfda-2e1a36d5ea59",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-42258"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability cannot be used to obtain access to ASA or FTD system files or underlying operating system (OS) files.",
                    "gate": "vulnerabilities",
                    "id": "7ca886f0-a063-45eb-b99b-700d00179b13",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-3452"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations.",
                    "gate": "vulnerabilities",
                    "id": "bf1c0f79-96e5-43cf-8f4b-fc671d5c6f9d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-3580"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.",
                    "gate": "vulnerabilities",
                    "id": "ca90742c-af47-4140-9187-676eaf54cc44",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1497"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.",
                    "gate": "vulnerabilities",
                    "id": "b8d08828-21e3-493d-9a18-2407244a319d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1498"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.",
                    "gate": "vulnerabilities",
                    "id": "c0f6f334-a525-410a-a11f-92568ebd46b4",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-0171"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).",
                    "gate": "vulnerabilities",
                    "id": "5b64f110-16bc-4515-ab80-f940df99998b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-3118"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols.",
                    "gate": "vulnerabilities",
                    "id": "e5ec78e5-4f8e-4569-99cb-30cda5775080",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-3566"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols.",
                    "gate": "vulnerabilities",
                    "id": "a659f12d-b59a-4dcf-957e-63f672797e34",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-3569"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.",
                    "gate": "vulnerabilities",
                    "id": "c6d3e9fb-417e-4063-b28c-d91a399cbedd",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-3161"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information.",
                    "gate": "vulnerabilities",
                    "id": "b9d47c06-de60-4b07-bdf1-53fabe9e74d5",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-1653"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.",
                    "gate": "vulnerabilities",
                    "id": "f3fed977-92de-45c1-871f-98fd9167f0c1",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-0296"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Citrix StoreFront Server contains a XXE processing vulnerability that could allow an unauthenticated attacker to retrieve potentially sensitive information.",
                    "gate": "vulnerabilities",
                    "id": "129208f9-676e-4339-b4c0-245dd555a99a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-13608"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.",
                    "gate": "vulnerabilities",
                    "id": "91e1a261-583c-45da-98e5-430a7de3e174",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8193"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Application Delivery Controller (ADC), Gateway, and SDWAN WANOP",
                    "gate": "vulnerabilities",
                    "id": "a2fa4385-2a01-490e-8597-81349543ced1",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8195"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.",
                    "gate": "vulnerabilities",
                    "id": "b6341155-77e8-49f1-8ad4-d5c4c1ff462d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8196"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Issue in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0 allowing Directory Traversal.",
                    "gate": "vulnerabilities",
                    "id": "e7f4e068-a800-42ab-9171-f29d7e0b6d17",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-19781"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Citrix Workspace app and Receiver for Windows prior to version 1904 contains an incorrect access control vulnerability which allows for code execution.",
                    "gate": "vulnerabilities",
                    "id": "ab770ebf-abb5-45a3-b088-65c5072899be",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-11634"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20 contain a vulnerability in the web interface allowing for remote code execution.",
                    "gate": "vulnerabilities",
                    "id": "35820064-6e2a-4cb7-b824-88f55e998bfb",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-29557"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.",
                    "gate": "vulnerabilities",
                    "id": "2f342f43-9dd3-42e1-a08c-4c47fb4e06cb",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-25506"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.",
                    "gate": "vulnerabilities",
                    "id": "5e8b7a9c-34c6-4d6e-8b30-6bfdc5144b59",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-15811"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.",
                    "gate": "vulnerabilities",
                    "id": "385ffa94-c7ed-4a91-92bc-07d6cce1cdd0",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-18325"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka \"2017-08 (Critical) Possible remote code execution on DNN sites.\"",
                    "gate": "vulnerabilities",
                    "id": "6882db1a-5ff4-47f0-af03-141db044c8ee",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-9822"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\\DockerDesktop\\version-bin\\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.",
                    "gate": "vulnerabilities",
                    "id": "4b9e60d5-af3f-4f6a-91aa-d6b3ad533a5a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-15752"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI.",
                    "gate": "vulnerabilities",
                    "id": "cda959c5-6e5f-40c4-88e0-75581ea83917",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8515"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.",
                    "gate": "vulnerabilities",
                    "id": "9f3d0d90-ce7e-4b29-ac4c-9aed33e6beea",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-7600"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Anyone with the ability to upload an image that goes through the GitLab Workhorse could achieve RCE via a specially crafted file.",
                    "gate": "vulnerabilities",
                    "id": "579feb3d-0cdb-482d-9ca8-c57ec444f110",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-22205"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Issue in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.",
                    "gate": "vulnerabilities",
                    "id": "deeb416b-8ac3-4b01-ab9a-f46705b56d19",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-6789"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Issue in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.",
                    "gate": "vulnerabilities",
                    "id": "6b7021a9-c939-40c1-b71c-89271590bc57",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8657"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Issue in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to run arbitrary commands as root via a crafted NSE script for nmap 7.",
                    "gate": "vulnerabilities",
                    "id": "507ee939-50ed-4f73-bb70-6505be195a19",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8655"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.",
                    "gate": "vulnerabilities",
                    "id": "d24ae112-e829-45dd-887b-ccb73f39b071",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-5902"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The iControl REST interface has an unauthenticated remote command execution vulnerability.",
                    "gate": "vulnerabilities",
                    "id": "6cc64ee4-bcd3-4563-9255-7c6741ce80a4",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-22986"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server.",
                    "gate": "vulnerabilities",
                    "id": "422253bd-1a56-48ba-a369-a56898fc1991",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-35464"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.",
                    "gate": "vulnerabilities",
                    "id": "9cccae36-5476-4d17-abba-c4f6f3054a4b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-5591"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.",
                    "gate": "vulnerabilities",
                    "id": "a4d98be9-469c-4be0-ba41-fab4a11869b7",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-12812"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An Improper Limitation of a Pathname to a Restricted Directory (\"Path Traversal\") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.",
                    "gate": "vulnerabilities",
                    "id": "5fc4f628-1220-4bc3-a3a5-6ead5ad2ae61",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-13379"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "2020dd74-04e4-4b61-9184-e2fc6732ff89",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-16010"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "1d21b3fc-d5d9-4e77-b80b-137ed3a45cff",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-15999"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "eed39cfd-1744-4db2-a5c6-21ebbfa7228c",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-21166"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "afb7d906-f05a-4cec-b0f1-8615034bd5ba",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-16017"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Information disclosure in Google Chrome that exists due to excessive data output in core.",
                    "gate": "vulnerabilities",
                    "id": "15f37a53-d713-4f76-91f8-e013d39fe1a5",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-37976"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "60ac821f-9561-4881-99c1-2ec08624be8c",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-16009"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Google Chrome out-of-bounds write that allows to execute arbitrary code on the target system.",
                    "gate": "vulnerabilities",
                    "id": "d5574cac-562b-4839-a185-1780d56525f3",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30632"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "6416d7d3-b4e9-4ce3-944b-fbfa02a8efd2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-16013"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Google Chrome Use-After-Free vulnerability",
                    "gate": "vulnerabilities",
                    "id": "5a3a800c-e9ec-42fb-8d55-311762cfb9e9",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30633"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "4b3d1fef-3237-4ec4-a027-aa493519e643",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-21148"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Use-after-free weakness in Portals, Google's new web page navigation system for Chrome. Successful exploitation can let attackers to execute code.",
                    "gate": "vulnerabilities",
                    "id": "fe2dacac-3293-473b-a592-8400c69b146b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-37973"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "13f34b53-b9a5-43c5-841e-8baa61da244a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30551"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Google Chrome use-after-free error within the V8 browser engine.",
                    "gate": "vulnerabilities",
                    "id": "c4b8ada4-a412-466c-ab9d-b0e837b3c1ae",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-37975"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "4fd807bf-6f6b-496d-9315-81147d5ea751",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-6418"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "9eba4707-307f-4f3d-80c1-41853294ae23",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30554"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "41dc9e10-f7c5-4534-b36f-a60e5741a413",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-21206"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "",
                    "gate": "vulnerabilities",
                    "id": "aad50f85-0564-42c6-9271-e595b276edcd",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-38000"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "",
                    "gate": "vulnerabilities",
                    "id": "8cd830dc-d68b-422e-90b2-b7bcfa63c933",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-38003"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "5ff953a8-3496-4842-9b75-dd2871d6d532",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-21224"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "d64169cf-1920-4dcc-a60d-b73009eed70e",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-21193"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "3b537776-7904-48a3-b364-3660e813aa23",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-21220"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
                    "gate": "vulnerabilities",
                    "id": "9aaaa59e-75f8-460b-9f01-3c89d684b2d7",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30563"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.",
                    "gate": "vulnerabilities",
                    "id": "1119a479-07b1-4058-b7c6-2fa98b80db7d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-4430"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.",
                    "gate": "vulnerabilities",
                    "id": "233a635a-e468-4e81-adec-3f8e8268435a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-4427"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.",
                    "gate": "vulnerabilities",
                    "id": "7e80d0dc-e49b-4a43-8b68-c6182c4ddf62",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-4428"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as \"admin\", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.",
                    "gate": "vulnerabilities",
                    "id": "7c0b9338-7e79-4813-a011-16c57a08cadb",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-4716"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.",
                    "gate": "vulnerabilities",
                    "id": "f926d466-828b-4fc5-a3fe-bf5318d009d6",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-3715"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.",
                    "gate": "vulnerabilities",
                    "id": "1e97253b-ffca-494a-8562-0af390518bb8",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-3718"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability that allows remote attackers to execute arbitrary code via unspecified vectors.",
                    "gate": "vulnerabilities",
                    "id": "72fde21f-ccc4-4134-b00b-b89bf2ef246b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-15505"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021.",
                    "gate": "vulnerabilities",
                    "id": "72b515ee-7197-455e-9b17-9f9f7a0f91da",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-30116"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).",
                    "gate": "vulnerabilities",
                    "id": "a10b395e-d1bd-40aa-a646-9e83787632aa",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-7961"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.",
                    "gate": "vulnerabilities",
                    "id": "67b527f4-5a3b-44d7-92c2-c6fb0d76a513",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-23874"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Micro Focus Access Manager versions prior to 5.0 contain a vulnerability which allows for information leakage.",
                    "gate": "vulnerabilities",
                    "id": "0530981d-e53e-41cd-afde-548b2025429f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-22506"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.",
                    "gate": "vulnerabilities",
                    "id": "ee6c8151-624b-48cc-bdad-95f314e2229c",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-22502"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka \"Group Policy Preferences Password Elevation of Privilege Vulnerability.\"",
                    "gate": "vulnerabilities",
                    "id": "a804f68b-1c39-496a-b5ad-d221cc6fffda",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2014-1812"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Azure Open Management Infrastructure Remote Code Execution Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "e6027e97-943a-497f-9935-c8e88630828f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-38647"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The kernel-mode driver allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0143 and CVE-2016-0165.",
                    "gate": "vulnerabilities",
                    "id": "8e287553-8134-4fd6-b4b2-dfebaa9c52e5",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-0167"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory.",
                    "gate": "vulnerabilities",
                    "id": "7de49ed1-7512-4b1d-a9d9-a00031980cd8",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0878"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows Kernel Information Disclosure Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "832e0011-5fd7-473e-ae18-4550dbddb20d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-31955"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Defender Remote Code Execution Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "26712ccb-947e-414d-a637-03688f16dbd7",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1647"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Desktop Window Manager (DWM) Core Library Elevation of Privilege Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "090b1b73-b566-4fd3-989e-f73749ffa283",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-33739"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Media Center allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka \"Windows Media Center Remote Code Execution Vulnerability.\"",
                    "gate": "vulnerabilities",
                    "id": "cb8bbcd7-233d-4682-9e7a-674d3828c13c",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-0185"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.",
                    "gate": "vulnerabilities",
                    "id": "bcca4e10-fbcf-457c-8195-bafb7a636099",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0683"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows Kernel Local Elevation of Privilege Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "e8daa836-9392-4f0e-ad21-b412def75d70",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-17087"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows MSHTML Platform Remote Code Execution Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "5cc8fcc4-ea02-4291-b406-72be562d0a3b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-33742"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2021-31201.",
                    "gate": "vulnerabilities",
                    "id": "5f78fac1-adc2-414d-b25c-de7e51809bf5",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-31199"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows Kernel Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-31979, CVE-2021-34514.",
                    "gate": "vulnerabilities",
                    "id": "0d9400c3-79cd-4933-a766-f6e6b5a95e44",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-33771"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows NTFS Elevation of Privilege Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "fc85f437-fae0-46bc-8062-631c2cf0a0e3",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-31956"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2021-31199.",
                    "gate": "vulnerabilities",
                    "id": "2c746494-4572-4cfa-bbc0-8b1c627e8b92",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-31201"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows Kernel Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-33771, CVE-2021-34514.",
                    "gate": "vulnerabilities",
                    "id": "f291adad-f156-4baa-995c-2c97ebc24012",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-31979"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format. This CVE ID is unique from CVE-2020-1020.",
                    "gate": "vulnerabilities",
                    "id": "bdd638b7-9bd9-4548-bdcb-3cbd52ed1fd6",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0938"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Exchange Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2020-17117, CVE-2020-17132, CVE-2020-17141, CVE-2020-17142.",
                    "gate": "vulnerabilities",
                    "id": "8fc44e46-e5af-4e69-a72c-73be4e7038e5",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-17144"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.",
                    "gate": "vulnerabilities",
                    "id": "2650fcc9-b459-45f2-8d03-1b1e11247b0d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0986"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format. This CVE ID is unique from CVE-2020-0938.",
                    "gate": "vulnerabilities",
                    "id": "b0a6023a-f75d-4d65-9e2e-ce81665fcedd",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-1020"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Open Management Infrastructure Elevation of Privilege Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "965d0ae9-8c25-418f-91b1-7cec6cb978ef",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-38645"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2021-33768, CVE-2021-34470.",
                    "gate": "vulnerabilities",
                    "id": "2734bb19-d0cf-4767-95ca-92bc0366bf0f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-34523"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with \"If: <http://\" in a PROPFIND request.",
                    "gate": "vulnerabilities",
                    "id": "2449a0e2-a941-4b1c-a1fa-461111c5dda0",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-7269"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows Update Medic Service Elevation of Privilege Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "9bb2ff82-b052-4394-948f-5509ba6b2d03",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-36948"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Open Management Infrastructure Elevation of Privilege Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "8649e2eb-2f70-4227-a136-bc80a8ff295b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-38649"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.",
                    "gate": "vulnerabilities",
                    "id": "de1f103b-b898-409d-a31a-ba775bd07354",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0688"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The SMBv1 server allows remote attackers to execute arbitrary code via crafted packets, aka \"Windows SMB Remote Code Execution Vulnerability.\" This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.",
                    "gate": "vulnerabilities",
                    "id": "f8ebf3a8-456f-4a38-98c0-42dbb053213b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-0143"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The kernel-mode drivers allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability\"",
                    "gate": "vulnerabilities",
                    "id": "a1c8a3fd-5fc6-46b9-b67e-f0e363a147d7",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-7255"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests.",
                    "gate": "vulnerabilities",
                    "id": "8347d945-abf5-47de-98f7-164590f6f6d3",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-0708"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206.",
                    "gate": "vulnerabilities",
                    "id": "00fc53a5-3ad9-4651-8751-e85b028a573d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-34473"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A spoofing vulnerability exists when Windows incorrectly validates file signatures.",
                    "gate": "vulnerabilities",
                    "id": "3e407c60-04d6-49be-95c8-b78c489ac537",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-1464"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1698.",
                    "gate": "vulnerabilities",
                    "id": "733303b3-7393-45be-9061-2860a4de35e2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1732"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows Print Spooler Remote Code Execution Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "2fff6c41-d0e0-4597-98c8-f169943e379b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-34527"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Exchange Server Security Feature Bypass Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "235fcaae-8ccd-438e-b796-04e83442abbb",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-31207"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.",
                    "gate": "vulnerabilities",
                    "id": "bc4c0700-4b3b-4479-b451-c4ed7357bb2d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-0803"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.",
                    "gate": "vulnerabilities",
                    "id": "28d20598-7848-43e3-b5e3-55e06b25e0f6",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-1040"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-27072.",
                    "gate": "vulnerabilities",
                    "id": "a2aaa5ed-3f41-4d24-86bf-0aa5733f2ce3",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-28310"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests.",
                    "gate": "vulnerabilities",
                    "id": "dae4e0df-a0d5-4910-9223-576833815195",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-1350"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Internet Explorer Memory Corruption Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "874d5f07-bf20-4836-a4e3-10c79f28a60c",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-26411"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.",
                    "gate": "vulnerabilities",
                    "id": "15a311b1-3f44-4fb7-8f29-f604a2f4dcc3",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-0859"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft MSHTML Remote Code Execution Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "0dc7d995-2a5b-40fb-946d-79c3399cbec9",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-40444"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application.",
                    "gate": "vulnerabilities",
                    "id": "e6921a9d-d11e-44d7-9f1d-50e8cbd049e6",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-8759"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka \"Scripting Engine Memory Corruption Vulnerability.\" This CVE ID is unique from CVE-2018-8643.",
                    "gate": "vulnerabilities",
                    "id": "6d0e1257-3f43-4315-abf6-4e7501b27bb5",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-8653"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.",
                    "gate": "vulnerabilities",
                    "id": "e6cc0ea1-0a39-4afc-8e2f-462ad836390d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-0797"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows Local Security Authority (LSA) Spoofing Vulnerability \"PetitPotam\"",
                    "gate": "vulnerabilities",
                    "id": "14875910-60e8-4d97-9437-fd3f1c5bc9e9",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-36942"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303.",
                    "gate": "vulnerabilities",
                    "id": "8c331994-2ed8-4fad-9aba-070456cdd917",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-1215"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka \"Microsoft Office Memory Corruption Vulnerability\". This CVE ID is unique from CVE-2017-11884.",
                    "gate": "vulnerabilities",
                    "id": "cb16c77d-4815-4ee0-822a-a57f6567bba4",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-11882"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows a remote code execution vulnerability due to the way objects are handled in memory, aka \"Microsoft Office Memory Corruption Vulnerability\".",
                    "gate": "vulnerabilities",
                    "id": "e4f366cb-f64f-4c0a-83dc-2ffcc93f0be8",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-0798"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows a remote code execution vulnerability due to the way objects are handled in memory, aka \"Microsoft Office Memory Corruption Vulnerability\". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.",
                    "gate": "vulnerabilities",
                    "id": "bb2c0c15-89f4-4b0c-a8e9-986003b7b442",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-0802"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers \"system state\" corruption, as exploited in the wild in April 2012, aka \"MSCOMCTL.OCX RCE Vulnerability.",
                    "gate": "vulnerabilities",
                    "id": "34af72ee-d5a1-48bf-b61d-24029ae9904e",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2012-0158"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows remote attackers to execute arbitrary code via a crafted RTF document, aka \"Microsoft Office Memory Corruption Vulnerability.\"",
                    "gate": "vulnerabilities",
                    "id": "27866a6c-d65a-424e-93e1-c027300937af",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2015-1641"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Internet Explorer Remote Code Execution Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "3be438e2-b6df-44fe-9118-5c5f218a783a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-27085"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input, aka \"MSHTML Engine Remote Code Execution Vulnerability.",
                    "gate": "vulnerabilities",
                    "id": "69469259-422d-4417-a78c-7bee47af7fa7",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-0541"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka \"Microsoft Office Memory Corruption Vulnerability\". This CVE ID is unique from CVE-2017-11884.",
                    "gate": "vulnerabilities",
                    "id": "97e0b42c-11e9-44b3-8abb-edf3a38a08e2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-11882"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.",
                    "gate": "vulnerabilities",
                    "id": "0734df03-890b-4716-9cb9-33c32f4b84f5",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0674"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24108, CVE-2021-27057.",
                    "gate": "vulnerabilities",
                    "id": "7fa236b6-65b8-4f8c-a192-5634a008b6f1",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-27059"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. This CVE ID is unique from CVE-2019-1221.",
                    "gate": "vulnerabilities",
                    "id": "9e42e6ed-2ec5-4b2b-ba20-899779cb12a5",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-1367"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows remote attackers to execute arbitrary code via a crafted document, aka \"Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API.\"",
                    "gate": "vulnerabilities",
                    "id": "17d9c88a-1752-4c98-a5c2-4e66d707902a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-0199"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1555, CVE-2020-1570.",
                    "gate": "vulnerabilities",
                    "id": "0645a7ca-7792-4f4b-8965-8c70f447b7fa",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-1380"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.",
                    "gate": "vulnerabilities",
                    "id": "42167087-d7b4-40a7-9a94-6a7f7a896841",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-1429"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka \"Microsoft Outlook Security Feature Bypass Vulnerability.\"",
                    "gate": "vulnerabilities",
                    "id": "69c8037e-18d4-4720-8fb7-a7730fa646e0",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-11774"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. This CVE ID is unique from CVE-2020-0970.",
                    "gate": "vulnerabilities",
                    "id": "dac68cff-c067-4eaa-8e84-a6a2f6c8b5cd",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0968"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC), aka 'Netlogon Elevation of Privilege Vulnerability'.",
                    "gate": "vulnerabilities",
                    "id": "8a7ed92d-45e0-473b-a3b6-865034d2f0e3",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-1472"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.",
                    "gate": "vulnerabilities",
                    "id": "d7a8cca1-8733-42b4-ad6f-465d5e2e1721",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-26855"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-27065, CVE-2021-27078.",
                    "gate": "vulnerabilities",
                    "id": "5cc14b57-5812-47ad-b300-91108dcf28d8",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-26858"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27078.",
                    "gate": "vulnerabilities",
                    "id": "b359b05f-32c8-49cd-ab33-80c0b49a4c3c",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-27065"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory",
                    "gate": "vulnerabilities",
                    "id": "0b3cc923-8a12-43ad-a6d5-d41960472607",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-1054"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Windows Print Spooler Elevation of Privilege Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "e20eaba4-b4df-4c91-bdc0-7cf346d0f2ed",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1675"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Scripting Engine Memory Corruption Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "ce42ee2d-6430-4a39-bcd4-063b4b0af052",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-34448"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.",
                    "gate": "vulnerabilities",
                    "id": "8450cead-b1b5-488b-92a8-6a0f88881e8b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0601"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.",
                    "gate": "vulnerabilities",
                    "id": "0e11063d-993e-4dfb-ab3d-e430dd8c1364",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-0604"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.",
                    "gate": "vulnerabilities",
                    "id": "1f9ec993-1a75-4048-bf4a-2b8aab58082a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-0646"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797.",
                    "gate": "vulnerabilities",
                    "id": "ad97e910-ceac-4840-a009-97eec6403003",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-0808"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.",
                    "gate": "vulnerabilities",
                    "id": "96d73989-c280-47f2-bfab-644f83d176fa",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-26857"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input.",
                    "gate": "vulnerabilities",
                    "id": "ef184b46-9839-401a-8087-9b123aed2c0a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-1147"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.",
                    "gate": "vulnerabilities",
                    "id": "ee168f4c-47b5-407e-b543-9182f8f096d0",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-1214"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows local users to gain privileges via a crafted application, aka \"Microsoft Office OLE DLL Side Loading Vulnerability.\"",
                    "gate": "vulnerabilities",
                    "id": "ac28e182-d258-4f3f-86b8-8cdb436c38a9",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-3235"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Azure Open Management Infrastructure Remote Code Execution Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "d6265ec4-6eac-4e53-aaf2-79865c8962c8",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-38647"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.",
                    "gate": "vulnerabilities",
                    "id": "9bed5223-7748-47d8-84da-fcc547d1088d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-0863"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft Windows Common Log File System Driver contains an unspecified vulnerability which allows for privilege escalation.",
                    "gate": "vulnerabilities",
                    "id": "9f83b5e9-b79f-41c2-a5e1-e3f2ab043148",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-36955"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Open Management Infrastructure Elevation of Privilege Vulnerability",
                    "gate": "vulnerabilities",
                    "id": "dff82b2f-f408-49c9-be12-28c58d4d76d2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-38648"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A race condition can cause a use-after-free when running the nsDocShell destructor. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.",
                    "gate": "vulnerabilities",
                    "id": "45e5de45-2600-4615-a068-8a9713be9958",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-6819"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A race condition can cause a use-after-free when handling a ReadableStream. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.",
                    "gate": "vulnerabilities",
                    "id": "93726973-4973-4602-9003-b6fbdef0c892",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-6820"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1",
                    "gate": "vulnerabilities",
                    "id": "63dbe1bd-56ce-4c4a-aa56-d46f2118fd1b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-17026"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user",
                    "gate": "vulnerabilities",
                    "id": "b25e58b8-a0f2-415e-8fbc-3681745419f7",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-15949"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.",
                    "gate": "vulnerabilities",
                    "id": "9bfb48ec-8609-4bbf-879c-31ed67c1428a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-26919"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123",
                    "gate": "vulnerabilities",
                    "id": "b43ae0f6-18fe-4f3e-a018-f5aafb679999",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-19356"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence",
                    "gate": "vulnerabilities",
                    "id": "5ac112de-bf50-49f6-bdd2-b2ff95ea0e85",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-2555"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component.",
                    "gate": "vulnerabilities",
                    "id": "57b415c4-5882-47f7-85b0-1a183a825481",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2012-3152"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris.",
                    "gate": "vulnerabilities",
                    "id": "32ba31db-b6d3-4b94-aea2-316651fae5b8",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-14871"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar.",
                    "gate": "vulnerabilities",
                    "id": "a68dd7e2-adeb-43d5-953e-5481123c6de4",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2015-4852"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.",
                    "gate": "vulnerabilities",
                    "id": "fa5c3ee8-6cc9-4b7f-a3e5-0c623ef78238",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-14750"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.",
                    "gate": "vulnerabilities",
                    "id": "3ad6c96a-b110-49f2-8b27-37d28f1361c2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-14882"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.",
                    "gate": "vulnerabilities",
                    "id": "e075d726-8565-47f1-a0ed-c769ce12e43b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-14883"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.",
                    "gate": "vulnerabilities",
                    "id": "8c09516c-c0dc-4a7f-a90a-d2e1e11beb18",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8644"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Contains a .NET deserialization vulnerability in the RadAsyncUpload function that can result in remote code execution.",
                    "gate": "vulnerabilities",
                    "id": "689e55e6-d77d-40da-a4d0-9f14c0aee116",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-18935"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Vulnerability to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway.",
                    "gate": "vulnerabilities",
                    "id": "3212a747-da5a-4f78-be1b-e5b07e02946a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-22893"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.",
                    "gate": "vulnerabilities",
                    "id": "352ff511-e9c4-4b67-88b3-306129dfeee0",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8243"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.",
                    "gate": "vulnerabilities",
                    "id": "b2c5ee8f-7091-4487-a9d2-266640afff51",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-22900"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.",
                    "gate": "vulnerabilities",
                    "id": "d2a9f7cb-04a0-4a6c-a12b-47a5e67878e7",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-22894"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.",
                    "gate": "vulnerabilities",
                    "id": "fd921a10-4149-4d3b-a03a-0455d94ecbb0",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8260"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature.",
                    "gate": "vulnerabilities",
                    "id": "f590081f-472e-4326-b04a-8d7961905a4f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-22899"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability.",
                    "gate": "vulnerabilities",
                    "id": "6161e7e3-2ea4-49f0-ba01-892fea0989b2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-11510"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Pulse Secure's Connect and Policy secure platforms contain a vulnerability in the admin web interface which allows an attacker to inject and execute commands.",
                    "gate": "vulnerabilities",
                    "id": "57abdb3f-0466-4a08-9ef2-bd18af7344b3",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-11539"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Improper handling of address deregistration on failure can lead to new GPU address allocation failure.",
                    "gate": "vulnerabilities",
                    "id": "c355ca04-0aa5-41b1-9292-4f147e33b6c4",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1906"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Possible use after free due to improper handling of memory mapping of multiple processes simultaneously",
                    "gate": "vulnerabilities",
                    "id": "3b07d01d-fa5d-421c-bc1f-13b85f2830f2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-1905"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.",
                    "gate": "vulnerabilities",
                    "id": "2e848c22-1887-44fa-974f-7eee008d2326",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-10221"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Realtek Jungle SDK version v2.x up to v3.4.14B arbitrary code execution.",
                    "gate": "vulnerabilities",
                    "id": "a7c2b1f9-7058-456e-a0d1-4ae8e99ddf3e",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-35395"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows unauthorized access to arbitrary files on the host's filesystem, including configuration files. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.",
                    "gate": "vulnerabilities",
                    "id": "2a9426c8-6f2a-4046-a98e-d9c6c0e446c9",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-16651"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.",
                    "gate": "vulnerabilities",
                    "id": "4c05be68-5e7e-4379-9636-a5c56d3db6c6",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-11652"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication.",
                    "gate": "vulnerabilities",
                    "id": "0acc5e78-331d-440f-bc3a-358c2ea07faa",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-11651"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.",
                    "gate": "vulnerabilities",
                    "id": "b68eded5-6b24-45bd-9e93-db816e1dfaff",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-16846"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing \"traverse to parent directory\" are passed through to the file APIs.",
                    "gate": "vulnerabilities",
                    "id": "76184a47-ae4c-4ed5-843e-f178999a67e8",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-2380"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.",
                    "gate": "vulnerabilities",
                    "id": "bd20b700-6b92-4147-97f7-0f97874e55a0",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-3976"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request.",
                    "gate": "vulnerabilities",
                    "id": "d7381757-bdeb-4cef-9994-6139d597065a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2010-5326"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.",
                    "gate": "vulnerabilities",
                    "id": "b5438ad6-e374-419a-9743-765f3561b911",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-9563"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system.",
                    "gate": "vulnerabilities",
                    "id": "8be9ccd7-f4ea-4f08-a86c-2f8230ae6f5b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-6287"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.",
                    "gate": "vulnerabilities",
                    "id": "8f8b9a0a-4e12-4736-b081-bc22100cdf1c",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-6207"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.",
                    "gate": "vulnerabilities",
                    "id": "1c513695-fc99-4f63-aab3-5e9bbd1c8966",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-3976"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.",
                    "gate": "vulnerabilities",
                    "id": "09c57a69-19fe-4b3c-81a9-2c1f1d4fa583",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-16256"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.",
                    "gate": "vulnerabilities",
                    "id": "7c11b774-87bc-4955-9c1a-79be6969a2c4",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-10148"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability.",
                    "gate": "vulnerabilities",
                    "id": "e89e6fbd-ce86-41d2-af8c-eeda7352691c",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-35211"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by \"sudo cat /etc/passwd.\"",
                    "gate": "vulnerabilities",
                    "id": "a4b0b987-c4aa-4b9f-9e6e-d77c82298e3a",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2016-3643"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).",
                    "gate": "vulnerabilities",
                    "id": "9f205c52-9453-4df8-a6c0-10e32ecfefb2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-10199"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.",
                    "gate": "vulnerabilities",
                    "id": "dc550b7d-09a8-483c-8a62-cf0c906baa30",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-20021"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Vulnerability in SonicWall SMA100 versions 9.0.0.3 and earlier allow an unauthenticated user to gain read-only access to unauthorized resources.",
                    "gate": "vulnerabilities",
                    "id": "6f5adf51-1a76-4dd3-827f-4cda1598bf2f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-7481"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.",
                    "gate": "vulnerabilities",
                    "id": "6f121db4-50da-4d0a-9335-2e7baf85a3aa",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-20022"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.",
                    "gate": "vulnerabilities",
                    "id": "a0602bb2-3956-4eff-9dc9-e12089170231",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-20023"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information in SMA100 build version 10.x.",
                    "gate": "vulnerabilities",
                    "id": "c6ec9fa4-81e5-4eb3-b1f5-493a998e261f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-20016"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A SQL injection issue that causes affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone.",
                    "gate": "vulnerabilities",
                    "id": "a1f870e7-f66a-42db-ad74-0f4528f30fa2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-12271"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request.",
                    "gate": "vulnerabilities",
                    "id": "9297decc-b9cf-424d-a0d6-4d5deae0caf1",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-10181"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution.",
                    "gate": "vulnerabilities",
                    "id": "43cf61d7-68c2-4a9f-8922-340f838dd6de",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-6327"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Allows a bypass of remote-login access control because the same key is used for different customers' installations.",
                    "gate": "vulnerabilities",
                    "id": "c4d025ca-136d-4ad9-9f05-519f3320e528",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-18988"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey.",
                    "gate": "vulnerabilities",
                    "id": "3dae78be-4a5a-44d0-b675-1c5221056d34",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2017-9248"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Tenda AC11 devices with firmware through 02.03.01.104_CN contain a stack buffer overflow vulnerability in /goform/setmac which allows for arbitrary execution.",
                    "gate": "vulnerabilities",
                    "id": "f77b0992-0abf-4b6e-8897-cef8be3c9ed9",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-31755"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.",
                    "gate": "vulnerabilities",
                    "id": "e1506343-88e7-4a54-aaaf-15c7734f2165",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-10987"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Issue on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the \"formsetUsbUnload\" function executes a dosystemCmd function with untrusted input.",
                    "gate": "vulnerabilities",
                    "id": "8de2ada8-7fbf-4d4a-b241-321f29ada791",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-14558"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Issue in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\\think\\Request/input&filter=phpinfo&data=1 query string.",
                    "gate": "vulnerabilities",
                    "id": "1f046f27-873b-401f-8967-9afe19237113",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2018-20062"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.",
                    "gate": "vulnerabilities",
                    "id": "e5afc503-9cef-4e83-b7f3-b6fa96aa4fa2",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-9082"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE).",
                    "gate": "vulnerabilities",
                    "id": "b9ad24fa-5b98-4526-b2a5-2ea301e9d259",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-18187"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE).",
                    "gate": "vulnerabilities",
                    "id": "af650ee1-6179-4560-909a-1664cb5c74ad",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8467"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components.",
                    "gate": "vulnerabilities",
                    "id": "a5c89373-b049-47ef-9a85-84c3b10aa80f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8468"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation",
                    "gate": "vulnerabilities",
                    "id": "4f634fb3-22b0-45d5-a834-56b39a5c9585",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-24557"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login.",
                    "gate": "vulnerabilities",
                    "id": "6f71bdc9-2b0f-49cb-b362-c038a2b57521",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-8599"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
                    "gate": "vulnerabilities",
                    "id": "59224dea-8502-4c54-9c12-431da9012250",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-36742"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product's management console in order to exploit this vulnerability.",
                    "gate": "vulnerabilities",
                    "id": "6cc7f0d7-0a23-4010-83d2-7bce964eb5ef",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-36741"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "TVT NVMS-1000 devices allow GET /.. Directory Traversal",
                    "gate": "vulnerabilities",
                    "id": "14ce02be-0dc9-4f07-a3c1-92d8fbcdfa4b",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-20085"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Unraid 6.8.0 allows authentication bypass.",
                    "gate": "vulnerabilities",
                    "id": "a6ddead7-982c-462e-b008-72810351e772",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-5849"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Unraid through 6.8.0 allows Remote Code Execution.",
                    "gate": "vulnerabilities",
                    "id": "8ab6d31f-f176-43a8-bab1-61a3f1b6f28d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-5847"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.",
                    "gate": "vulnerabilities",
                    "id": "356d1a74-3578-49a0-a081-7daba9c6dcce",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-16759"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.",
                    "gate": "vulnerabilities",
                    "id": "3494f3f0-85cb-44ec-b909-6ac1411079ea",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-17496"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "OpenSLP as used in ESXi and the Horizon DaaS appliances have a heap overwrite issue. A malicious actor with network access to port 427 on an ESXi host or on any Horizon DaaS management appliance may be able to overwrite the heap of the OpenSLP service resulting in remote code execution.",
                    "gate": "vulnerabilities",
                    "id": "cfe4737a-63c4-4f7e-b439-14a086c44781",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-5544"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.",
                    "gate": "vulnerabilities",
                    "id": "b8efde00-fda8-4a6f-9670-deef90253923",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-3992"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Privilege escalation vulnerability due to improper use of setuid binaries.",
                    "gate": "vulnerabilities",
                    "id": "1f43ef75-e9f3-4936-bceb-57574a94e39d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-3950"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "VMWare vCenter Server file upload vulnerability in the vmware-analytics service that allows to execute code on vCenter Server.",
                    "gate": "vulnerabilities",
                    "id": "ca9b006c-8ee5-4dc7-9298-64efbb849162",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-22005"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.",
                    "gate": "vulnerabilities",
                    "id": "2b75b6a6-c9af-4f2c-a165-5323de8a5130",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-3952"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.",
                    "gate": "vulnerabilities",
                    "id": "b3666123-f9e3-43fb-9842-aec0ea444879",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-21972"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.",
                    "gate": "vulnerabilities",
                    "id": "b4583f40-10db-400c-876d-69e4804ce04f",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-21985"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "VMWare Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.",
                    "gate": "vulnerabilities",
                    "id": "1f17eaa4-b426-4b24-87ff-b42e9bffce78",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-4006"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension.",
                    "gate": "vulnerabilities",
                    "id": "70cb33d1-cdd0-40c0-b5a1-b562bbbe19b7",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-25213"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.",
                    "gate": "vulnerabilities",
                    "id": "9d501227-200c-48e7-8ecf-df8f789b6597",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-11738"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.",
                    "gate": "vulnerabilities",
                    "id": "1c258cad-1cce-48cf-9f61-0ea196a37342",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-9978"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication",
                    "gate": "vulnerabilities",
                    "id": "b7331a9f-1aed-44dc-896b-8e4f35337b9d",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-27561"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Zoho ManageEngine ADSelfService Plus versions 6113 and earlier contain an authentication bypass vulnerability which allows for RCE.",
                    "gate": "vulnerabilities",
                    "id": "50683554-ca01-4ab4-8586-54cd711a5503",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2021-40539"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.",
                    "gate": "vulnerabilities",
                    "id": "2d200f30-9d46-4557-b100-e301c96044bd",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-10189"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.",
                    "gate": "vulnerabilities",
                    "id": "0727da73-300f-44bf-b8ee-1c079b7c487e",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2019-8394"
                        }
                    ],
                    "trigger": "blacklist"
                },
                {
                    "action": "STOP",
                    "comment": "Firmware version 4.60 of ZyXEL USG devices contains an undocumented account (zyfwp) with an unchangeable password.",
                    "gate": "vulnerabilities",
                    "id": "ccdcdf33-e350-4ae4-b49c-1bdf5c4472c0",
                    "params": [
                        {
                            "name": "vulnerability_ids",
                            "value": "CVE-2020-29583"
                        }
                    ],
                    "trigger": "blacklist"
                }
            ],
            "version": "1_0"
        }
    ],
    "mappings": [
        {
            "id": "16d46f0b-df61-45d8-bc49-d34b405f4968",
            "image": {
                "type": "tag",
                "value": "*"
            },
            "name": "default",
            "policy_ids": [
                "a348aff0-ebb8-4b90-99ff-bb17740c1306"
            ],
            "registry": "*",
            "repository": "*",
            "whitelist_ids": []
        }
    ],
    "version": "1_0",
    "whitelisted_images": [],
    "blacklisted_images": [],
    "whitelists": []
}
