Specific Action change on Individual Signature

cancel
Showing results for 
Search instead for 
Did you mean: 

Specific Action change on Individual Signature

L2 Linker

Hi Experts,

We've configured a Vulnerability profile with the Action of Default. For the Windows Print night mare vulnerability (Version ID: 8424, signature ID:91333) and the CVE ID: CVE-2021-1675 I see the default action is marked as 'Alert' which will allow the traffic.

I am trying to change the action of an specific Vulnerability signature from Alert to Block. When I go to the profile and find the signature in the Exceptions and change it to Block. If I click on enable and Click OK, this specific one is showing under the 'exceptions' tab as expected. 

Will it be exempted from the traffic processing? Am I missing something? 

How do I change the default behavior of only this signature to be reset ?

Thanks in advance

91333 Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-1675 code-execution alert 7.1.0

2 REPLIES 2

Cyber Elite
Cyber Elite

@nsrini1991,

So if you pull the latest updates these have actually been modified away from Alert and to reset-server, but as an FYI you would want to apply the same action to all three IDs (91333, 91346, 91349) to be fully covered. 

Create a new rule on your Vulnerability protection profile that specifies CVE-2021-1675 with the action set to however you want. This will override all signatures that are created for CVE-2021-1675 and apply the desired action.Capture.PNG

 

Hi,

Many thanks for the reply.

If I'm not wrong, we'll create an custom rule just for this CVE (with the specific action: reset-both) and add it to the existing Vulnerability Protection Profile.

If yes, can you please let me know how this is different from changing the default action of this CVE to reset-both under the exceptions tab? Is it same or different?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!