Skip to main content
Robert_Cerny
New Member
March 5, 2021
Question

CVE-2021-26858

  • March 5, 2021
  • 1 reply
  • 4558 views

Hi,

I checked our FG100E for new 0day MS Exchange exploit CVE-2021-26858 and found that it's listed in IPS database already, but action is set to PASS. Does it mean that it will go through to our Exchange server?

 

Thanks, 

 

Robert

    1 reply

    Robert_Cerny
    New Member
    March 6, 2021

    Hi,

    I love answering my own questions :) Please find an answer from IPS team below:

     

    All our signatures are released as "Pass" initially as a precautionary step to monitor the signature upon initial release. The signature will be set to "Block" right after the signature is proven to be stable. We have requested the signature to be set to "Block". Barring any unforeseen circumstances, the update should be reflected in the next IPS definitions release.

    If needed, please manually set the action of these signatures to Block in your IPS sensor.
    comelfex
    New Member
    March 15, 2021
    How does it identify the exploit exactly? It goes via https and Port 443, so the only thing I see is IP addresses. Or how does it work?