On this page
Atomicorp WAF Rule 312863
Rule Summary
- Rule ID: 312863
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Potential Reflected File Download (RFD) Attack.
- Observed CWEs: CWE-79 (1), CWE-200 (1), CWE-306 (1), CWE-425 (1)
- Phase: 2 (request body)
- Request surfaces: Request URI
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rules detects when a potential reflected download attack (RFD) has been detected.
Troubleshooting
False Positives
If you believe this is a false positive,
Tuning Guidance
Please see the Tuning the Atomicorp WAF Rules page for basic information.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2018-0127 | Cisco RV132W/RV134W Router - Information Disclosure | rv132w firmware | 9.8 (v3.1) | Critical |
| CVE-2019-17504 | Kirona-DRS 5.5.3.5 - Information Disclosure | dynamic resource scheduling | 6.1 (v3.1) | Medium |
| CVE-2019-17503 | Kirona-DRS 5.5.3.5 - Information Disclosure | dynamic resource scheduling | 5.3 (v3.1) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
| CWE | Related Published CVEs |
|---|---|
| CWE-79 | CVE-2019-17504 |
| CWE-200 | CVE-2018-0127 |
| CWE-306 | CVE-2018-0127 |
| CWE-425 | CVE-2019-17503 |
Documentation Source
- Original wiki page: WAF 312863
- Source revision: 5239
- Source revision date: 2014-11-05