QID 378024
Date Published: 2023-03-22
QID 378024: F5 BIG-IP iRulesLX Debug NodeJS Vulnerability CVE-2019-6644 (K75532331)
The BIG-IP system will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible. (CVE-2019-6644)
Vulnerable Component:
Affected Versions:
14.0.0
14.1.0
13.0.0 - 13.1.2
12.1.3 - 12.1.4
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
A remote attacker may be able to attach a remote computer to the debug port and evaluate arbitrary JavaScript.
Solution
Please refer to K75532331 for more information. Workaround:
To mitigate this vulnerability,you should consider the following recommendations: Permit management access to F5 products only over a secure network, and limit shell access to only trusted users. For more information about securing access to BIG-IP and Enterprise Manager systems, refer to K13309: Restricting access to the Configuration utility by source IP address (11.x - 15.x) and K13092: Overview of securing access to the BIG-IP system. Lock down management port access and configure the self IP port lockdown feature to disallow unneeded ports on all self IP addresses. For more information, refer to K13250: Overview of port lockdown behavior (10.x - 11.x) or K17333: Overview of port lockdown behavior (12.x - 15.x).
To mitigate this vulnerability,you should consider the following recommendations: Permit management access to F5 products only over a secure network, and limit shell access to only trusted users. For more information about securing access to BIG-IP and Enterprise Manager systems, refer to K13309: Restricting access to the Configuration utility by source IP address (11.x - 15.x) and K13092: Overview of securing access to the BIG-IP system. Lock down management port access and configure the self IP port lockdown feature to disallow unneeded ports on all self IP addresses. For more information, refer to K13250: Overview of port lockdown behavior (10.x - 11.x) or K17333: Overview of port lockdown behavior (12.x - 15.x).
Vendor References
- K75532331 -
my.f5.com/manage/s/article/K75532331
CVEs related to QID 378024
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K75532331 |
|