CVE-2019-6628: High severity f5 big-ip policy enforcement manager vulnerability
Published Jul 3, 2019
·Updated
On BIG-IP PEM 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, under certain conditions, the TMM process may terminate and restart while processing BIG-IP PEM traffic with the OpenVPN classifier.
Affected Software
2 affected components
F5 Big-ip Policy Enforcement Manager>=14.0.0<=14.0.0.4
F5 Big-ip Policy Enforcement Manager>=14.1.0<=14.1.0.5
Event History
Jul 3, 2019
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-6628?
CVE-2019-6628 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2019-6628?
To mitigate CVE-2019-6628, upgrade the F5 BIG-IP Policy Enforcement Manager to version 14.1.0.6 or later, or version 14.0.0.5 or later.
3
What causes the CVE-2019-6628 vulnerability?
CVE-2019-6628 occurs when the TMM process unexpectedly terminates under specific conditions while processing BIG-IP PEM traffic.
4
Which versions of F5 BIG-IP are affected by CVE-2019-6628?
F5 BIG-IP versions 14.1.0 to 14.1.0.5 and 14.0.0 to 14.0.0.4 are affected by CVE-2019-6628.
5
Is there a workaround for CVE-2019-6628?
There is no official workaround for CVE-2019-6628; upgrading to a fixed version is the recommended action.