Forum Discussion
F5 Rules for AWS WAF - CVE-2021-22118 & CVE-2016-1000027
- Sep 19, 2023
Hi chanzk ,
Unlike the full blown WAF security solutions, F5 rules on AWS WAF are limited in total capacity, limiting the types of CVEs we can offer protection against. Normally, F5 rules include protection against CVEs that are common among customers. CVE-2016-1000027 may affect only few, therefore it wasn't included yet. We will add it in our next updates.
CVE-2021-22118 is a local vulnerability, not a network vulnerability. So less relevant for a WAF.
Thanks.
Hi ambrosetse
Yes it was updated. sorry it took me longer to answer than expected.
Hi Joel_Cohen
I would like to know if the following rule in "F5 Rules for AWS WAF - Common Vulnerabilities and Exposures (CVE) Rules" protect on the CVE-2016-100027?
If not, which rule will protect on the CVE?
Also, I find that the action is "Use action defined in the rule", I would like to know the default action of the rule is BLOCK or COUNT?
- Pradeep_KandiJan 31, 2024Employee
Hi ambrosetse
Yes, the rule you pasted will mitigate the CVE that was mentioned, and the deployed rules' course of action would be to BLOCK. Hope this helps.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com