F5 Networks Update
2936Warning Date
Severity Level
Warning Number
Target Sector
3 November, 2020
● High
2020-2007
All
Description:
F5 Networks has released a security updates to address multiple vulnerabilities in the following product:
- BIG-IP (LTM, AAM, Advanced WAF, AFM, Analytics, APM, ASM, DDHD, DNS, FPS, GTM, Link Controller, PEM, SSLO, Edge Gateway, WebAccelerator )
- 14.1.2.5-14.1.2.7
- 14.1.0-14.1.0.1
- 16.0.0
- 15.1.0
- 14.1.0 - 14.1.2
- 13.1.0 - 13.1.3
- 12.1.0 - 12.1.5
- 11.6.1 - 11.6.5
- BIG-IQ Centralized Management
- 7.0.0
- 7.1.0
- 6.0.0 - 6.1.0
- 5.4.0
- Traffix SDC
- 5.0.0 - 5.1.0
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS)
- Cross-site scripting (XSS) attack
- Brute force attack
- Remote code execution
- Sensitive information disclosure
Best practice and Recommendations:
The CERT team encourages users to review F5 Networks security advisory and apply the necessary updates:
- https://support.f5.com/csp/article/K57274211
- https://support.f5.com/csp/article/K20059815
- https://support.f5.com/csp/article/K43310520
- https://support.f5.com/csp/article/K03125360
- https://support.f5.com/csp/article/K53821711
- https://support.f5.com/csp/article/K82530456
- https://support.f5.com/csp/article/K21540525
- https://support.f5.com/csp/article/K32055534
- https://support.f5.com/csp/article/K75111593