CVE-2019-6652: Medium severity f5 big-ip and big-iq centralized management vulnerability
Published Sep 25, 2019
·Updated
In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).
Affected Software
1 affected component
F5 BIG-IQ Centralized Management>=6.0.0<=6.1.0
Event History
Sep 25, 2019
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-6652.
2
What is the title of this vulnerability?
The title of this vulnerability is In BIG-IQ 6.0.0-6.1.0 services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).
3
What is the severity of CVE-2019-6652?
The severity of CVE-2019-6652 is medium with a severity value of 6.5.
4
What software versions are affected by CVE-2019-6652?
The BIG-IQ Centralized Management versions 6.0.0-6.1.0 are affected by CVE-2019-6652.
5
How can I fix CVE-2019-6652?
To fix CVE-2019-6652, upgrade to a version higher than 6.1.0 of BIG-IQ Centralized Management.