QID 376465

Date Published: 2022-03-22

QID 376465: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) OpenSSH Client Vulnerability (K48050136)

The client side in OpenSSH 5.7 through 8.3 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). (CVE-2020-14145).

Vulnerable Component: BIG-IP ASM,LTM,APM

Affected Versions:
16.0.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0 - 13.1.4

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

SSH sessions may be vulnerable to a man-in-the-middle attack.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    For more information about patch details please refer to K48050136
    Vendor References

    CVEs related to QID 376465

    Software Advisories
    Advisory ID Software Component Link