Forum Discussion

chanzk's avatar
chanzk
Icon for Altostratus rankAltostratus
Sep 14, 2023

F5 Rules for AWS WAF - CVE-2021-22118 & CVE-2016-1000027

Hello, We're checking in the AWS marketplace for the F5 Rules for AWS WAF - Common Vulnerabilities and Exposures (CVE) Rules and want to check if the following CVEs are covered by this rule set? C...
  • Joel_Cohen's avatar
    Sep 19, 2023

    Hi chanzk ,

    Unlike the full blown WAF security solutions, F5 rules on AWS WAF are limited in total capacity, limiting the types of CVEs we can offer protection against. Normally, F5 rules include protection against CVEs that are common among customers. CVE-2016-1000027 may affect only few, therefore it wasn't included yet. We will add it in our next updates.

    CVE-2021-22118 is a local vulnerability, not a network vulnerability. So less relevant for a WAF.

    Thanks.