First published: Wed Feb 14 2024(Updated: )
When an SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | =17.1.0 | 17.1.1 |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.3 | 16.1.4 |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.8 | 15.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The F5-K000134516 vulnerability has a moderate severity level due to potential CPU resource exhaustion.
To resolve F5-K000134516, upgrade your F5 BIG-IP to the specified remedial versions: 17.1.1, 16.1.4, or 15.1.9.
F5-K000134516 affects F5 BIG-IP versions 17.1.0, 16.1.0 to 16.1.3, and 15.1.0 to 15.1.8.
Yes, F5-K000134516 can lead to degradation of service due to increased CPU utilization from undisclosed requests.
It is not recommended to use F5 BIG-IP without patching for F5-K000134516 as it poses a risk of resource exhaustion.