F5-K000148692: Medium severity f5 big-ip ssl orchestrator vulnerability
Published Nov 26, 2024
·Updated
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
Affected Software
4 affected components
F5 BIG-IP (APM, SSL Orchestrator)>=17.1.0<=17.1.2
F5 BIG-IP (APM, SSL Orchestrator)>=16.1.0<=16.1.5
F5 BIG-IP (APM, SSL Orchestrator)>=15.1.0<=15.1.10
F5 Traffix SDC=5.2
Event History
Nov 26, 2024
Advisory Published
via F5·10:53 PM
Frequently Asked Questions
1
What is the severity of F5-K000148692?
The severity of F5-K000148692 is high due to potential bypass of certificate validation.
2
How do I fix F5-K000148692?
To fix F5-K000148692, upgrade to the latest version of the affected software.
3
Which versions are affected by F5-K000148692?
F5-K000148692 affects specific versions of F5 BIG-IP and F5 Traffix SDC software as outlined in the advisory.
4
Is the vulnerability in F5-K000148692 exploitable remotely?
Yes, F5-K000148692 can potentially be exploited remotely if the required conditions are met.
5
What impact does F5-K000148692 have on data security?
F5-K000148692 can undermine the integrity of secure communications by improperly validating TLS certificates.