Your review has been sent successfully

F5 Networks Alert

1990
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

2 February, 2022

● High

2022-4312

All

Description:

F5 Networks has released security updates to address a vulnerability in the following products:

  • BIG-IP (all modules)
    • 16.1.0 - 16.1.1
    • 15.1.0 - 15.1.4
    • 14.1.0 - 14.1.4
    • 13.1.0 - 13.1.4
    • 12.1.0 - 12.1.6
    • 11.6.1 - 11.6.5
  • BIG-IQ Centralized Management
    • 8.0.0 - 8.1.0
    • 7.0.0 - 7.1.0
  • F5OS-C
    • 1.1.0

*Vulnerability in: Python

Threats:

Remote attacker could exploit this vulnerability by bypassing restrictions on a vulnerable systems to gain unauthorized access to resources and to modify files.

Best practice and Recommendations:

The CERT team encourages users to review F5 Networks security advisory and update the affected products:

Until a fixed is introduced for BIG-IQ Centralized Management and as temporary mitigations you should restrict management access to only trusted users and devices to F5 products over a secure network. For more information about securing access to BIG-IQ systems, refer to the below links:

Last updated at 2 February, 2022

Rate the content

rate-icon
up icon