F5 Releases Security Updates for Multiple Products
Security updates address six vulnerabilities rated as High impact and four rated as Medium impact
Summary
Security updates address six vulnerabilities rated as High impact and four rated as Medium impact
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
- NGINX Instance Manager
- NGINX API Connectivity Manager
- NGINX Security Monitoring
Threat details
Introduction
F5 has released an overview of vulnerabilities for some of their networking products, including BIG-IP and BIG-IQ Centralized Management. The security advisory addresses six vulnerabilities rated as High impact and four rated as Medium impact. An attacker could exploit these vulnerabilities to escalate privileges, execute remote commands, impersonate a BIG-IP APM system, carry out cross-site scripting (XSS), create a denial-of-service (DoS) condition, or gain access to configuration objects outside of their assigned environment.
Remediation advice
Affected organisations are encouraged to review K000133251: Overview of F5 vulnerabilities (May 2023) and apply any relevant updates or mitigations.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 3 May 2023 5:15 pm