F5-K000138643: High severity f5 traffix systems signaling delivery controller vulnerability
OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mmanswerauthpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000138643?
The severity of F5-K000138643 is considered high due to its potential to allow authentication bypass.
How do I fix F5-K000138643?
To fix F5-K000138643, it is recommended to update the affected F5 Traffix SDC to the latest version that addresses this vulnerability.
Which versions of F5 software are affected by F5-K000138643?
F5-K000138643 affects F5 Traffix SDC version 5.2.0 and 5.1.0.
What types of attacks does F5-K000138643 expose systems to?
F5-K000138643 exposes systems to row hammer attacks that may lead to authentication bypass.
What is the root cause of F5-K000138643?
The root cause of F5-K000138643 is related to the handling of integer values in the mm_answer_authpassword function which can be exploited through bit flips.