First published: Fri Nov 15 2019(Updated: )
On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow current best practices.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Access Policy Manager | >=14.1.0<14.1.2 | |
F5 BIG-IP Access Policy Manager | =15.0.0 | |
F5 BIG-IP Advanced Firewall Manager | >=14.1.0<14.1.2 | |
F5 BIG-IP Advanced Firewall Manager | =15.0.0 | |
F5 BIG-IP Analytics | >=14.1.0<14.1.2 | |
F5 BIG-IP Analytics | =15.0.0 | |
F5 Big-ip Application Acceleration Manager | >=14.1.0<14.1.2 | |
F5 Big-ip Application Acceleration Manager | =15.0.0 | |
F5 BIG-IP Application Security Manager | >=14.1.0<14.1.2 | |
F5 BIG-IP Application Security Manager | =15.0.0 | |
F5 Big-ip Domain Name System | >=14.1.0<14.1.2 | |
F5 Big-ip Domain Name System | =15.0.0 | |
F5 Big-ip Edge Gateway | >=14.1.0<14.1.2 | |
F5 Big-ip Edge Gateway | =15.0.0 | |
F5 Big-ip Fraud Protection Service | >=14.1.0<14.1.2 | |
F5 Big-ip Fraud Protection Service | =15.0.0 | |
F5 Big-ip Global Traffic Manager | >=14.1.0<14.1.2 | |
F5 Big-ip Global Traffic Manager | =15.0.0 | |
F5 Big-ip Link Controller | >=14.1.0<14.1.2 | |
F5 Big-ip Link Controller | =15.0.0 | |
F5 Big-ip Local Traffic Manager | >=14.1.0<14.1.2 | |
F5 Big-ip Local Traffic Manager | =15.0.0 | |
F5 Big-ip Policy Enforcement Manager | >=14.1.0<14.1.2 | |
F5 Big-ip Policy Enforcement Manager | =15.0.0 | |
F5 Big-ip Webaccelerator | >=14.1.0<14.1.2 | |
F5 Big-ip Webaccelerator | =15.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6664 is a vulnerability that affects the management port on BIG-IP devices running certain versions of software.
The affected software includes F5 BIG-IP Access Policy Manager, Advanced Firewall Manager, Analytics, Application Acceleration Manager, Application Security Manager, Domain Name System, Edge Gateway, Fraud Protection Service, Global Traffic Manager, Link Controller, Local Traffic Manager, Policy Enforcement Manager, and Webaccelerator.
CVE-2019-6664 has a severity rating of 7.5 (high).
Under certain conditions, network protections on the management port may not follow current best practices.
To fix CVE-2019-6664, upgrade to a version of the affected software that is not vulnerable.