F5-K000159607: High severity F5 BIG-IQ Centralized Management vulnerability
An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000159607?
F5-K000159607 is classified as a critical vulnerability due to its potential to allow unauthenticated attackers to bypass cryptographic verifications.
How do I fix F5-K000159607?
To fix F5-K000159607, upgrade node-forge to a version later than 1.3.1 and ensure your software is updated to the latest version of F5 BIG-IQ Centralized Management.
What versions of F5 BIG-IQ Centralized Management are affected by F5-K000159607?
F5-K000159607 affects F5 BIG-IQ Centralized Management versions 8.3.0 to 8.4.0 inclusive.
Who can be affected by F5-K000159607?
Unauthenticated attackers can exploit F5-K000159607 to manipulate ASN.1 structures and potentially compromise security.
What security risks are associated with F5-K000159607?
The security risks associated with F5-K000159607 include unauthorized bypassing of cryptographic verifications and potential data integrity issues.