First published: Tue Oct 10 2023(Updated: )
The BIG-IP and BIG-IQ systems do not encrypt the values of two Database (DB) variables, a password used for a proxy server connection and a RADIUS/TACACS+ shared secret.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP | 17.1.0 | |
F5 BIG-IP | >=16.1.0<=16.1.3 | 16.1.4 |
F5 BIG-IP | >=15.1.0<=15.1.8 | 15.1.9 |
F5 BIG-IP | >=14.1.0<=14.1.5 | |
F5 BIG-IP | >=13.1.0<=13.1.5 | |
F5 BIG-IQ Centralized Management | >=8.0.0<=8.3.0 | - |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K20850144 is considered high due to the risk of sensitive credentials being exposed in plain text.
To fix F5-K20850144, upgrade your F5 BIG-IP or BIG-IQ systems to the recommended versions where the vulnerabilities have been addressed.
F5-K20850144 affects F5 BIG-IP versions 15.1.0 to 15.1.9, 16.1.0 to 16.1.4, 17.1.0, and specific versions of BIG-IQ Centralized Management from 8.0.0 to 8.3.0.
F5-K20850144 exposes the plaintext storage of a proxy server password and a RADIUS/TACACS+ shared secret, posing a security risk.
Mitigating F5-K20850144 without upgrading is not recommended; it is essential to upgrade to secure the sensitive information.