CVE-2019-6687: High severity f5 application security manager vulnerability
Published Dec 23, 2019
·Updated
On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints.
Affected Software
1 affected component
F5 BIG-IP Application Security Manager>=15.0.0<15.1.0
Event History
Dec 23, 2019
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-6687?
The severity of CVE-2019-6687 is classified as critical due to improper authentication of remote endpoints.
2
How do I fix CVE-2019-6687?
To fix CVE-2019-6687, upgrade the BIG-IP ASM Cloud Security Services profile to version 15.1.0 or later.
3
Which versions are affected by CVE-2019-6687?
CVE-2019-6687 affects F5 BIG-IP Application Security Manager versions 15.0.0 to 15.0.1.1.
4
What type of vulnerability is CVE-2019-6687?
CVE-2019-6687 is an authentication vulnerability that allows potential bypass of security mechanisms.
5
What are the potential impacts of CVE-2019-6687?
The potential impacts of CVE-2019-6687 include unauthorized access to sensitive data and potential exposure to man-in-the-middle attacks.