First published: Fri Nov 15 2019(Updated: )
On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of systems resources which may lead to a denial of service.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Access Policy Manager | >=13.1.0<13.1.3 | |
F5 BIG-IP Access Policy Manager | >=14.0.0<14.0.1.1 | |
F5 BIG-IP Access Policy Manager | >=14.1.0<14.1.2.1 | |
F5 BIG-IP Advanced Firewall Manager | >=13.1.0<13.1.3 | |
F5 BIG-IP Advanced Firewall Manager | >=14.0.0<14.0.1.1 | |
F5 BIG-IP Advanced Firewall Manager | >=14.1.0<14.1.2.1 | |
F5 BIG-IP Analytics | >=13.1.0<13.1.3 | |
F5 BIG-IP Analytics | >=14.0.0<14.0.1.1 | |
F5 BIG-IP Analytics | >=14.1.0<14.1.2.1 | |
F5 Big-ip Application Acceleration Manager | >=13.1.0<13.1.3 | |
F5 Big-ip Application Acceleration Manager | >=14.0.0<14.0.1.1 | |
F5 Big-ip Application Acceleration Manager | >=14.1.0<14.1.2.1 | |
F5 BIG-IP Application Security Manager | >=13.1.0<13.1.3 | |
F5 BIG-IP Application Security Manager | >=14.0.0<14.0.1.1 | |
F5 BIG-IP Application Security Manager | >=14.1.0<14.1.2.1 | |
F5 Big-ip Domain Name System | >=13.1.0<13.1.3 | |
F5 Big-ip Domain Name System | >=14.0.0<14.0.1.1 | |
F5 Big-ip Domain Name System | >=14.1.0<14.1.2.1 | |
F5 Big-ip Edge Gateway | >=13.1.0<13.1.3 | |
F5 Big-ip Edge Gateway | >=14.0.0<14.0.1.1 | |
F5 Big-ip Edge Gateway | >=14.1.0<14.1.2.1 | |
F5 Big-ip Fraud Protection Service | >=13.1.0<13.1.3 | |
F5 Big-ip Fraud Protection Service | >=14.0.0<14.0.1.1 | |
F5 Big-ip Fraud Protection Service | >=14.1.0<14.1.2.1 | |
F5 Big-ip Global Traffic Manager | >=13.1.0<13.1.3 | |
F5 Big-ip Global Traffic Manager | >=14.0.0<14.0.1.1 | |
F5 Big-ip Global Traffic Manager | >=14.1.0<14.1.2.1 | |
F5 Big-ip Link Controller | >=13.1.0<13.1.3 | |
F5 Big-ip Link Controller | >=14.0.0<14.0.1.1 | |
F5 Big-ip Link Controller | >=14.1.0<14.1.2.1 | |
F5 Big-ip Local Traffic Manager | >=13.1.0<13.1.3 | |
F5 Big-ip Local Traffic Manager | >=14.0.0<14.0.1.1 | |
F5 Big-ip Local Traffic Manager | >=14.1.0<14.1.2.1 | |
F5 Big-ip Policy Enforcement Manager | >=13.1.0<13.1.3 | |
F5 Big-ip Policy Enforcement Manager | >=14.0.0<14.0.1.1 | |
F5 Big-ip Policy Enforcement Manager | >=14.1.0<14.1.2.1 | |
F5 Big-ip Webaccelerator | >=13.1.0<13.1.3 | |
F5 Big-ip Webaccelerator | >=14.0.0<14.0.1.1 | |
F5 Big-ip Webaccelerator | >=14.1.0<14.1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6660 is a vulnerability on F5 BIG-IP products that allows undisclosed HTTP requests to consume excessive system resources, potentially leading to a denial of service.
F5 BIG-IP Access Policy Manager, F5 BIG-IP Advanced Firewall Manager, F5 BIG-IP Analytics, F5 BIG-IP Application Acceleration Manager, F5 BIG-IP Application Security Manager, F5 BIG-IP Domain Name System, F5 BIG-IP Edge Gateway, F5 BIG-IP Fraud Protection Service, F5 BIG-IP Global Traffic Manager, F5 BIG-IP Link Controller, F5 BIG-IP Local Traffic Manager, F5 BIG-IP Policy Enforcement Manager, F5 BIG-IP Webaccelerator are affected.
CVE-2019-6660 has a severity of 7.5 (High).
Apply the appropriate patches provided by F5 Networks to mitigate the vulnerability.
You can find more information about CVE-2019-6660 on the F5 Networks support website.