F5 Networks Alert
2497Warning Date
Severity Level
Warning Number
Target Sector
26 April, 2022
● High
2022-4715
All
F5 Networks has released security updates to address several vulnerabilities in the following products:
- Traffix SDC
- 5.2.0
- BIG-IP (LTM, AAM, Advanced WAF, AFM, Analytics, APM, ASM, DDHD, DNS, FPS, GTM, Link Controller, PEM, SSLO)
- 16.0.0 - 16.1.2
- 15.0.0 - 15.1.5
- 14.1.0 - 14.1.4
An attacker could exploit these vulnerabilities by doing the following:
- Escalating privilege
- Execute arbitrary code
The CERT team encourages users to review F5 Networks security advisory and apply the necessary updates:
And to mitigate "Traffix SDC" vulnerability, you can disable user namespaces for non-containerized deployments by setting user.max_user_namespaces to 0. To do so, run the following commands:
- echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf
sysctl -p /etc/sysctl.d/userns.conf