Your review has been sent successfully

F5 Networks Alerts

1785
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

25 August, 2021

● High

2021-3410

All

Description:

F5 Networks has released security alerts to address multiple vulnerabilities in the following products:

  • BIG-IP
    • 16.0.0 - 16.1.0
    • 15.1.0 - 15.1.3
    • 14.1.0 - 14.1.4
    • 13.1.0 - 13.1.4
    • 12.1.0 - 12.1.6
    • 11.6.1 - 11.6.5
    • 7.0
    • 6.0
    • 5.0
    • 4.1
    • 3.0
  • Vulnerability in:
      • TMUI
      • compression functions
      • BIG-IP Advanced WAF and ASM
      • TMM
      • GTP iRules
      • GTP profiles
      • OCSP authentication module,
      • Guided Configuration control plane,
      • TMM on AWS,
      • BIG-IP APM access profile,
      • TMUI
      • iRuleLX, BIG-IP DNS,
      • BIG-IP ASM MySQL database
      • bd process,
      • WebSocket processing,
      • iControl SOAP
      • TMUI/Configuration utility
  • BIG-IQ Centralized Management
    • 8.0.0 - 8.1.0
    • 7.0.0 - 7.1.0
    • 6.0.0 - 6.1.0
  • Vulnerability in:
      • iControl SOAP

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Denial of service (DoS)- remotely
  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF).
  • Execute arbitrary code

Best practice and Recommendations:

The CERT team encourages users to review F5 Networks security advisory:

Last updated at 25 August, 2021

Rate the content

rate-icon
up icon