First published: Wed Sep 25 2019(Updated: )
In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IQ Centralized Management | >=6.0.0<=6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-6652.
The title of this vulnerability is In BIG-IQ 6.0.0-6.1.0 services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).
The severity of CVE-2019-6652 is medium with a severity value of 6.5.
The BIG-IQ Centralized Management versions 6.0.0-6.1.0 are affected by CVE-2019-6652.
To fix CVE-2019-6652, upgrade to a version higher than 6.1.0 of BIG-IQ Centralized Management.