QID 375591
Date Published: 2021-05-31
QID 375591: F5 BIG-IP BIND Vulnerability (K11426315)
F5's BIG-IP is a family of products covering software and hardware designed around application availability, access control, and security solutions.
Vulnerable Component: BIG-IP (All Modules)
Affected Versions:
16.0.0 - 16.0.1
15.1.0 - 15.1.3
14.1.0 - 14.1.4
13.1.0 - 13.1.4
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker may be able to send a crafted incremental zone transfer (IXFR) that causes the named process to terminate due to a failed assertion.
Solution
The vendor has released any patch, for more information please visit: K11426315Workaround:
If incremental zone transfers (IXFR) are enabled in your BIND configuration, you can mitigate this vulnerability by setting the request-ixfr no; option in the desired configuration block (options, zone, or server). Doing so disables incremental zone transfers and prevents the failing assertion from being evaluated.
If incremental zone transfers (IXFR) are enabled in your BIND configuration, you can mitigate this vulnerability by setting the request-ixfr no; option in the desired configuration block (options, zone, or server). Doing so disables incremental zone transfers and prevents the failing assertion from being evaluated.
Vendor References
- K11426315 -
support.f5.com/csp/article/K11426315
CVEs related to QID 375591
Software Advisories
| Advisory ID | Software | Component | Link |
|---|