F5 Networks Updates
3118Warning Date
Severity Level
Warning Number
Target Sector
25 December, 2019
● Medium
2019-766
All
Description:
F5 Networks has released security updates to address multiple vulnerabilities in the following products:
- BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator).
15.x - 14.x - 13.x - 12.x - 11.x
- BIG-IQ Centralized Management
7.x - 6.x - 5.x
- Enterprise Manager
3.x
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS) attack.
- Man in the middle attack.
- Disruption of service.
- Overwrite certain configuration files.
- Escalation of privilege.
Best practice and Recommendations:
The CERT team encourages users to update the affected products and to review F5 Networks security advisory:
https://support.f5.com/csp/new-updated-articles