F5-K98334513: Medium severity f5 big-ip (dns, ltm enabled with dns services license) vulnerability
Published Oct 10, 2023
·Updated
When a BIG-IP DNS or BIG-IP LTM system is enabled with the DNS Services license, and a TSIG key is created, the key is logged in plaintext in the audit log.
Affected Software
5 affected componentsFixes available
F5 BIG-IP (DNS, LTM enabled with DNS Services license3)
17.1.0
F5 BIG-IP (DNS, LTM enabled with DNS Services license3)>=16.1.0<=16.1.3
16.1.4
F5 BIG-IP (DNS, LTM enabled with DNS Services license3)>=15.1.0<=15.1.8
15.1.9
F5 BIG-IP (DNS, LTM enabled with DNS Services license3)>=14.1.0<=14.1.5
F5 BIG-IP (DNS, LTM enabled with DNS Services license3)>=13.1.0<=13.1.5
Event History
Oct 10, 2023
Advisory Published
via F5·10:13 AM
Frequently Asked Questions
1
What is the severity of F5-K98334513?
The severity of F5-K98334513 is considered high due to the risk of sensitive key exposure.
2
How do I fix F5-K98334513?
To fix F5-K98334513, upgrade to the appropriate versions 17.1.0, 16.1.4, 15.1.9, or any higher patched versions indicated in the advisory.
3
What systems are affected by F5-K98334513?
F5-K98334513 affects BIG-IP systems that have DNS Services enabled.
4
What type of data is exposed in F5-K98334513?
F5-K98334513 exposes TSIG keys in plaintext within the audit log.
5
Is there a workaround for F5-K98334513?
There is no documented workaround for F5-K98334513, so upgrading is essential.