F5 BIG-IP Unspecified SSL Authentication Bypass Vulnerability
BID:14215
Info
F5 BIG-IP Unspecified SSL Authentication Bypass Vulnerability
| Bugtraq ID: | 14215 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Jul 12 2005 12:00AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
F5 BIG-IP 9.1 F5 BIG-IP 9.0.5 F5 BIG-IP 9.0.4 F5 BIG-IP 9.0.3 F5 BIG-IP 9.0.2 |
| Not Vulnerable: | |
Discussion
F5 BIG-IP Unspecified SSL Authentication Bypass Vulnerability
F5 BIG-IP is susceptible to an unspecified SSL authentication bypass vulnerability.
It is conjectured that if the BIG-IP is configured to authenticate by utilizing certificate-based authentication, attackers may be able to bypass the requested authentication checks. This allows remote attackers to gain access to protected Web sites. Depending on the nature of the protected Web sites, various further attacks may also be possible.
Further details are not currently available. This BID will be updated as more information is disclosed.
Versions of BIP-IP from 9.0.2 through to 9.1 are affected.
F5 BIG-IP is susceptible to an unspecified SSL authentication bypass vulnerability.
It is conjectured that if the BIG-IP is configured to authenticate by utilizing certificate-based authentication, attackers may be able to bypass the requested authentication checks. This allows remote attackers to gain access to protected Web sites. Depending on the nature of the protected Web sites, various further attacks may also be possible.
Further details are not currently available. This BID will be updated as more information is disclosed.
Versions of BIP-IP from 9.0.2 through to 9.1 are affected.
Exploit / POC
F5 BIG-IP Unspecified SSL Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
F5 BIG-IP Unspecified SSL Authentication Bypass Vulnerability
Solution:
The vendor has released an advisory, and fixes for versions 9.0.4, 9.0.5, and 9.1. Users of versions 9.0.2 or 9.0.3 must first upgrade to one of the supported versions prior to applying fixes.
Users with valid FTP credentials may retrieve fixes from the following location:
ftp://ftp.f5.com/Domestic/bigip/bigip9x-hotfix-CR49528/
Please see the referenced advisory for further information.
Solution:
The vendor has released an advisory, and fixes for versions 9.0.4, 9.0.5, and 9.1. Users of versions 9.0.2 or 9.0.3 must first upgrade to one of the supported versions prior to applying fixes.
Users with valid FTP credentials may retrieve fixes from the following location:
ftp://ftp.f5.com/Domestic/bigip/bigip9x-hotfix-CR49528/
Please see the referenced advisory for further information.
References
F5 BIG-IP Unspecified SSL Authentication Bypass Vulnerability
References:
References:
- BigIP Product Information (F5 Software)
- Solution ID: SOL4944 (F5 Software)