Defender-DeviceTvmSoftwareVulnerabilitiesKB
| ActionType | Title | Sample | Rule |
|---|---|---|---|
| any | Vulnerability knowledge base | Y | Y |
any: Vulnerability knowledge base
#Detection Fields #
Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.
| Name | Rules | Vendors |
|---|---|---|
CveId | 1 detection rule | Kusto |
CvssVector | 1 detection rule | Kusto |
IsExploitAvailable | 1 detection rule | Kusto |
Example Event #
{
"AffectedSoftware": [
"schneider-electric:bmxnor0200h_firmware"
],
"AffectedSoftware@odata.type": "#Collection(String)",
"CveId": "CVE-2019-6810",
"CveSupportability": "Supported",
"CvssScore": 8.6,
"CvssVector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C",
"EpssScore": 0.01729,
"IsExploitAvailable": 0,
"IsExploitAvailable@odata.type": "#SByte",
"LastModifiedTime": "2026-06-17T02:39:43.35Z",
"PublishedDate": "2019-08-12T00:00:00Z",
"VulnerabilityDescription": "Summary: The Schneider Electric BMXNOR0200H Ethernet / Serial RTU module is vulnerable to an Improper Access Control vulnerability. This vulnerability exists in all firmware versions of the module and can be exploited by unauthorized users when using the IEC 60870-5-104 protocol. By exploiting this vulnerability, a remote attacker could execute arbitrary commands on the system. Impact: If this vulnerability is exploited, an attacker could gain unauthorized access to the Schneider Electric BMXNOR0200H Ethernet / Serial RTU module and execute arbitrary commands. This could lead to unauthorized control of the system and potential disruption of critical operations. [Generated by AI]",
"VulnerabilitySeverityLevel": "High"
}
Detection Patterns #
Initial Access: Exploit Public-Facing Application
Defender-DeviceNetworkEvents InboundConnectionAccepted: Inbound connection acceptedORDefender-DeviceTvmSoftwareVulnerabilities any: Software vulnerabilities on devicesORDefender-DeviceTvmSoftwareVulnerabilitiesKB any: Vulnerability knowledge baseORDefender-ExposureGraphNodes any: Exposure graph nodes
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
ActionType (kusto rule field) | contains | inboundconnection | 1 rule | kusto |
type (kusto rule field) | eq | DeviceInventoryId | 1 rule | kusto |