F5 Networks Alert
2768Warning Date
Severity Level
Warning Number
Target Sector
2 February, 2022
● High
2022-4312
All
F5 Networks has released security updates to address a vulnerability in the following products:
- BIG-IP (all modules)
- 16.1.0 - 16.1.1
- 15.1.0 - 15.1.4
- 14.1.0 - 14.1.4
- 13.1.0 - 13.1.4
- 12.1.0 - 12.1.6
- 11.6.1 - 11.6.5
- BIG-IQ Centralized Management
- 8.0.0 - 8.1.0
- 7.0.0 - 7.1.0
- F5OS-C
- 1.1.0
*Vulnerability in: Python
Remote attacker could exploit this vulnerability by bypassing restrictions on a vulnerable systems to gain unauthorized access to resources and to modify files.
The CERT team encourages users to review F5 Networks security advisory and update the affected products:
Until a fixed is introduced for BIG-IQ Centralized Management and as temporary mitigations you should restrict management access to only trusted users and devices to F5 products over a secure network. For more information about securing access to BIG-IQ systems, refer to the below links: