F5 BIG-IP 多個漏洞
發佈日期:
2021年01月06日
1560
觀看次數
風險: 中度風險
類型: 操作系統 - Network
於 F5 BIG-IP 發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、彷冒、遠端執行任意程式碼、資料篡改、跨網站指令碼及繞過保安限制。
影響
- 跨網站指令碼
- 阻斷服務
- 遠端執行程式碼
- 繞過保安限制
- 仿冒
- 篡改
受影響之系統或技術
BIG-IP (LTM, AAM, Advanced WAF, AFM, Analytics, APM, ASM, DDHD, DNS, FPS, GTM, Link Controller, PEM, SSLO)
- 版本 11.6.1 - 11.6.5
- 版本 12.1.0 - 12.1.5
- 版本 13.1.0 - 13.1.3
- 版本 14.1.0 - 14.1.3
- 版本 15.1.0 - 15.1.2
- 版本 16.0.0 - 16.0.1
Enterprise Manager
- 版本 3.1.1
BIG-IQ Centralized Management
- 版本 5.0.0 - 5.4.0
- 版本 6.0.0 - 6.1.0
- 版本 7.0.0 - 7.1.0
F5 iWorkflow
- 版本 2.3.0
Traffix SDC
- 版本 4.4.0
- 版本 5.0.0 - 5.1.0
解決方案
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
- https://support.f5.com/csp/article/K38481791
- https://support.f5.com/csp/article/K42531048
- https://support.f5.com/csp/article/K24551552
- https://support.f5.com/csp/article/K21350967
- https://support.f5.com/csp/article/K38481791
- https://support.f5.com/csp/article/K11315080
- https://support.f5.com/csp/article/K64119434
- https://support.f5.com/csp/article/K57542514
- https://support.f5.com/csp/article/K90011301
- https://support.f5.com/csp/article/K02453220
- https://support.f5.com/csp/article/K66544153
漏洞識別碼
- CVE-2018-20685
- CVE-2019-3856
- CVE-2019-3857
- CVE-2019-3863
- CVE-2009-5155
- CVE-2019-6110
- CVE-2019-6111
- CVE-2019-9636
- CVE-2019-17563
- CVE-2020-10029
- CVE-2020-11022
- CVE-2020-11023
資料來源
相關連結
- https://support.f5.com/csp/article/K38481791
- https://support.f5.com/csp/article/K42531048
- https://support.f5.com/csp/article/K24551552
- https://support.f5.com/csp/article/K21350967
- https://support.f5.com/csp/article/K38481791
- https://support.f5.com/csp/article/K11315080
- https://support.f5.com/csp/article/K64119434
- https://support.f5.com/csp/article/K57542514
- https://support.f5.com/csp/article/K90011301
- https://support.f5.com/csp/article/K02453220
- https://support.f5.com/csp/article/K66544153
- https://www.auscert.org.au/bulletins/ESB-2020.3038.2/
- https://www.auscert.org.au/bulletins/ESB-2019.0346.3/
- https://www.auscert.org.au/bulletins/ESB-2020.0294.2/
- https://www.auscert.org.au/bulletins/ESB-2020.1411.2/
- https://www.auscert.org.au/bulletins/ESB-2020.3038.2/
- https://www.auscert.org.au/bulletins/ESB-2020.1410.2/
- https://www.auscert.org.au/bulletins/ESB-2019.0994.3/
- https://www.auscert.org.au/bulletins/ESB-2020.3176.2/
- https://www.auscert.org.au/bulletins/ESB-2020.3214.2/
- https://www.auscert.org.au/bulletins/ESB-2020.2660.3/
分享至