Your review has been sent successfully

F5 Networks Alert

2744
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

29 April, 2020

● High

2020-1189

All

Description:

F5 Networks has released a clarification to address a vulnerability in the following product:

  • BIG-IQ Centralized Management
    • 7.0.0
    • 6.0.0 - 6.1.0
    • 5.2.0 - 5.4.0

Threats:

Attacker could exploit the vulnerability by establishing a connection to the BIG-IQ HA synchronization with no authentication. As a result, the BIG-IQ data may be compromised.

Best practice and Recommendations:

The CERT team encourages users to update version 7.0.0 to 7.1.0.

For the other versions, it's recommended to apply the following mitigation:

  • Ensure that the discovery network (the network used by BIG-IQ to communicate with the managed BIG-IP devices) is over a secure network with appropriate encryption, such as a VPN.
  • Ensure that the BIG-IQ discovery network is on a secure network that has security measures in place to prevent Address Resolution Protocol (ARP) poisoning attacks or to block gratuitous ARP (GARP) packets.

For more details:

Last updated at 29 April, 2020

Rate the content

rate-icon
up icon