<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower still missing latest F5 CVE's? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-still-missing-latest-f5-cve-s/m-p/4312298#M1079505</link>
    <description>&lt;P&gt;Looking for the Intrusion Rules that match these CVE's; the first one shows up but the others do not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alerts about these from F5 were sent out around 3/10/21, does anyone now where the other Intrusion rules for these might be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CVE-2021-22986&amp;nbsp; &amp;nbsp; &amp;nbsp;(found, corresponds to SID&amp;nbsp;57298)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CVE-2021-22987&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CVE-2021-22991&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CVE-2021-22992&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Mar 2021 14:12:11 GMT</pubDate>
    <dc:creator>ashaw216</dc:creator>
    <dc:date>2021-03-23T14:12:11Z</dc:date>
    <item>
      <title>Firepower still missing latest F5 CVE's?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-still-missing-latest-f5-cve-s/m-p/4312298#M1079505</link>
      <description>&lt;P&gt;Looking for the Intrusion Rules that match these CVE's; the first one shows up but the others do not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alerts about these from F5 were sent out around 3/10/21, does anyone now where the other Intrusion rules for these might be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CVE-2021-22986&amp;nbsp; &amp;nbsp; &amp;nbsp;(found, corresponds to SID&amp;nbsp;57298)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CVE-2021-22987&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CVE-2021-22991&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CVE-2021-22992&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 14:12:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-still-missing-latest-f5-cve-s/m-p/4312298#M1079505</guid>
      <dc:creator>ashaw216</dc:creator>
      <dc:date>2021-03-23T14:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower still missing latest F5 CVE's?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-still-missing-latest-f5-cve-s/m-p/4312461#M1079513</link>
      <description>&lt;P&gt;I noticed that &lt;STRONG&gt;2021-03-17-001-vrt&lt;/STRONG&gt; didn't have the rules. It looks like Firepower Management Center wasn't recognizing the newer &lt;STRONG&gt;2021-03-22-001-vrt &lt;/STRONG&gt;ruleset. That one added SIDs 57336 and 57337 (among others) which address two of the F5 vulnerabilities. You can download it manually and upload it to your FMC.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://software.cisco.com/download/home/286259687/type/286321931/release/SRU" target="_blank"&gt;https://software.cisco.com/download/home/286259687/type/286321931/release/SRU&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Short of opening a TAC case, we can can only wait for Talos to publish a newer SRU to see about the other ones.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 17:48:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-still-missing-latest-f5-cve-s/m-p/4312461#M1079513</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-03-23T17:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower still missing latest F5 CVE's?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-still-missing-latest-f5-cve-s/m-p/4313025#M1079558</link>
      <description>&lt;P&gt;Thanks for the suggestion. Our FMC shows that it's running the 03-22 vrt and I found those SIDs, but how did you figure out which CVEs these go to? The Rule Documentation reference link leads to a "Missing documentation" page on Snort.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 11:56:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-still-missing-latest-f5-cve-s/m-p/4313025#M1079558</guid>
      <dc:creator>ashaw216</dc:creator>
      <dc:date>2021-03-24T11:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower still missing latest F5 CVE's?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-still-missing-latest-f5-cve-s/m-p/4313207#M1079569</link>
      <description>&lt;P&gt;I cross-referenced them by looking at the description in the SRU vs. the description on F5's notice which did include the associated CVEs.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 16:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-still-missing-latest-f5-cve-s/m-p/4313207#M1079569</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-03-24T16:47:07Z</dc:date>
    </item>
  </channel>
</rss>

