QID 376243
QID 376243: F5 BIG-IP Local Traffic Manager (LTM), Application Security Manager (ASM), Access Policy Manager (APM) OpenSSH client Vulnerability (K48050136)
The client side in OpenSSH 5.7 through 8.3 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).CVE-2020-14145
Vulnerable Component: BIG-IP APM,ASM,LTM
Affected Versions:
16.0.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0 - 13.1.4
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
SSH sessions may be vulnerable to a man-in-the-middle attack.
Solution
The vendor has released patch, for more information please visit: K48050136
Vendor References
- K48050136 -
support.f5.com/csp/article/K48050136
CVEs related to QID 376243
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K48050136 |
|