WAF Rule Set Update Announcement

Name waf.sig
Version 1.2.19
StoneOS Version 5.5R2-W-1.1 or above, BDS 5.5R8-3.4 or above
Release Date 2024-12-9
New Rules
(5)
Rule ID Rule Name Rule Details
1070210329 Yapi NoSQL Injection Vulnerability Click for Details
1070210330 Weaver e-Mobile Management Platform Remote Command Execution Vulnerability Click for Details
1070210331 Wanhu ezOFFICE downloadservlet Directory Traversal Vulnerability Click for Details
1070210332 CVE-2020-7361:ZenTao Pro Remote Code Execution Vulnerability Click for Details
1070210333 CVE-2024-42327:Zabbix api_jsonrpc.php SQL injection Vulnerability Click for Details
Updated Rules
(1)
Rule ID Description Ruel Details
1070210324 CVE-2024-9264:Grafana Post-Auth DuckDB SQL Injection Vulnerability Click for Details