CVE-2019-6674: High severity f5 big-ip ssl orchestrator vulnerability
Published Nov 27, 2019
·Updated
On F5 SSL Orchestrator 15.0.0-15.0.1 and 14.0.0-14.1.2, TMM may crash when processing SSLO data in a service-chaining configuration.
Affected Software
2 affected components
F5 SSL Orchestrator>=14.0.0<=14.1.2
F5 SSL Orchestrator>=15.0.0<=15.0.1
Event History
Nov 27, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this F5 SSL Orchestrator vulnerability?
The vulnerability ID is CVE-2019-6674.
2
What is the severity of CVE-2019-6674?
The severity of CVE-2019-6674 is high (7.5).
3
Which versions of F5 SSL Orchestrator are affected by CVE-2019-6674?
F5 SSL Orchestrator 15.0.0-15.0.1 and 14.0.0-14.1.2 are affected by CVE-2019-6674.
4
What is the impact of this vulnerability?
The vulnerability may cause the TMM service to crash when processing SSLO data in a service-chaining configuration.
5
How can I fix CVE-2019-6674?
Update F5 SSL Orchestrator to version 15.0.2 or 14.1.3 to fix CVE-2019-6674.