F5-K20850144: Medium severity f5 big-ip and big-iq centralized management vulnerability
The BIG-IP and BIG-IQ systems do not encrypt the values of two Database (DB) variables, a password used for a proxy server connection and a RADIUS/TACACS+ shared secret.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K20850144?
The severity of F5-K20850144 is considered high due to the risk of sensitive credentials being exposed in plain text.
How do I fix F5-K20850144?
To fix F5-K20850144, upgrade your F5 BIG-IP or BIG-IQ systems to the recommended versions where the vulnerabilities have been addressed.
What are the affected versions of F5-K20850144?
F5-K20850144 affects F5 BIG-IP versions 15.1.0 to 15.1.9, 16.1.0 to 16.1.4, 17.1.0, and specific versions of BIG-IQ Centralized Management from 8.0.0 to 8.3.0.
What vulnerabilities does F5-K20850144 expose?
F5-K20850144 exposes the plaintext storage of a proxy server password and a RADIUS/TACACS+ shared secret, posing a security risk.
Can I mitigate F5-K20850144 without upgrading?
Mitigating F5-K20850144 without upgrading is not recommended; it is essential to upgrade to secure the sensitive information.