Check: AADC-AG-000062
A10 Networks ADC ALG STIG:
AADC-AG-000062
(in versions v2 r1 through v1 r1)
Title
The A10 Networks ADC, when used to load balance web applications, must strip HTTP response headers. (Cat II impact)
Discussion
Providing too much information in error messages risks compromising the data and security of the application and system. HTTP response headers can disclose vulnerabilities about a web server. This information can be used by an attacker. The A10 Networks ADC can filter response headers; this removes the web server’s identifying headers in outgoing responses (such as Server, X-Powered-By, and X-AspNet-Version).
Check Content
If the device is not used to load balance web servers, this is not applicable. If the device is used to load balance web servers, verify that the A10 Networks ADC strips HTTP response headers. The following command displays WAF templates: show slb template waf If the configured WAF templates do not have the "filter-resp-hdrs" option configured, this is a finding.
Fix Text
If the device is used to load balance web servers, configure the device to strip HTTP response headers. The following command configures a WAF template and includes the option to strip HTTP response headers: slb template waf filter-resp-hdrs
Additional Identifiers
Rule ID: SV-237040r639567_rule
Vulnerability ID: V-237040
Group Title: SRG-NET-000273-ALG-000129
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001312 |
The information system generates error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |