CVE-2019-6672: High severity f5 big-ip advanced firewall manager vulnerability
On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, and 13.1.0-13.1.3.1, when bad-actor detection is configured on a wildcard virtual server on platforms with hardware-based sPVA, the performance of the BIG-IP AFM system is degraded.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6672?
CVE-2019-6672 has a moderate severity rating due to the performance degradation it causes on affected systems.
How do I fix CVE-2019-6672?
To remediate CVE-2019-6672, update the BIG-IP AFM to a version that is not affected by this vulnerability.
Which versions of F5 BIG-IP Advanced Firewall Manager are affected by CVE-2019-6672?
CVE-2019-6672 affects F5 BIG-IP Advanced Firewall Manager versions 13.1.0-13.1.3.1, 14.0.0-14.1.2, and 15.0.0-15.0.1.
What impact does CVE-2019-6672 have on system performance?
CVE-2019-6672 results in degraded system performance specifically when bad-actor detection is configured on a wildcard virtual server.
Is there a workaround for CVE-2019-6672?
F5 has not provided specific workarounds for CVE-2019-6672, and updating to an unaffected version is recommended.