PurseChicken
Member
- Thread starter
- #1
Hello,
I was looking at my local network today, and I noticed that a device on my network is constantly being denied due to an IPS rule. Specifically in the Buffer Overflow Category with the name "SSL OpenSSL CRL Verification X.400 Address Handling Type Confusion Vulnerability (CVE-2023-0286)" Here is a link to the details of this detection in my WatchGuard appliance: https://securityportal.watchguard.com/threats/detail?ruleId=1231758
After some digging, I found that this appears to be my R1S with a MAC address that is associated with Vendor "u-blox ag" (OUI 20:BA:36). All of the traffic appears to be going to destination IP addresses that are associated with AWS. Additionally, it appears DNS lookups occur for "v1authz.prod.rivianservices.com" in the same cycle of the events.
Granted, my home setup also doubles as my lab, so I am sure I am unique in seeing this as most home users may not notice. That being said, I am posting here to see if anyone else has happened to see this on their network or if they have any insight. Definitely a discussion topic. I will likely also contact Rivian about this as well.
Thanks!
I was looking at my local network today, and I noticed that a device on my network is constantly being denied due to an IPS rule. Specifically in the Buffer Overflow Category with the name "SSL OpenSSL CRL Verification X.400 Address Handling Type Confusion Vulnerability (CVE-2023-0286)" Here is a link to the details of this detection in my WatchGuard appliance: https://securityportal.watchguard.com/threats/detail?ruleId=1231758
After some digging, I found that this appears to be my R1S with a MAC address that is associated with Vendor "u-blox ag" (OUI 20:BA:36). All of the traffic appears to be going to destination IP addresses that are associated with AWS. Additionally, it appears DNS lookups occur for "v1authz.prod.rivianservices.com" in the same cycle of the events.
Granted, my home setup also doubles as my lab, so I am sure I am unique in seeing this as most home users may not notice. That being said, I am posting here to see if anyone else has happened to see this on their network or if they have any insight. Definitely a discussion topic. I will likely also contact Rivian about this as well.
Thanks!
Sponsored