F5 Networks Alert
2744Warning Date
Severity Level
Warning Number
Target Sector
29 April, 2020
● High
2020-1189
All
Description:
F5 Networks has released a clarification to address a vulnerability in the following product:
- BIG-IQ Centralized Management
- 7.0.0
- 6.0.0 - 6.1.0
- 5.2.0 - 5.4.0
Threats:
Attacker could exploit the vulnerability by establishing a connection to the BIG-IQ HA synchronization with no authentication. As a result, the BIG-IQ data may be compromised.
Best practice and Recommendations:
The CERT team encourages users to update version 7.0.0 to 7.1.0.
For the other versions, it's recommended to apply the following mitigation:
- Ensure that the discovery network (the network used by BIG-IQ to communicate with the managed BIG-IP devices) is over a secure network with appropriate encryption, such as a VPN.
- Ensure that the BIG-IQ discovery network is on a secure network that has security measures in place to prevent Address Resolution Protocol (ARP) poisoning attacks or to block gratuitous ARP (GARP) packets.
For more details: