2025年10月16日星期四

F5 Products Multiple Vulnerabilities

F5 Products Multiple Vulnerabilities

Release Date: 16 Oct 2025

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in F5 Products. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, data manipulation, elevation of privilege, security restriction bypass, sensitive information disclosure and denial of service condition on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Elevation of Privilege
  • Cross-Site Scripting
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

BIG-IP (all modules)

  • version 17.5.0 - 17.5.1
  • version 17.1.0 - 17.1.2
  • version 16.1.0 - 16.1.6
  • version 15.1.0 - 15.1.10

F5OS-A

  • version 1.8.0 - 1.8.13
  • version 1.5.1 - 1.5.3

F5OS-C

  • version 1.8.0 - 1.8.1
  • version 1.6.0 - 1.6.23

BIG-IP Next SPK

  • version 2.0.0 - 2.0.2
  • version 1.7.0 - 1.9.2

BIG-IP Next CNF

  • version 2.0.0 - 2.1.0
  • version 1.1.0 - 1.4.1

BIG-IP Next for Kubernetes

  • version 2.0.0 - 2.1.0

BIG-IP SSL Orchestrator

  • version 17.5.0
  • version 17.1.0 - 17.1.2
  • version 16.1.0 - 16.1.5
  • version 15.1.0 - 15.1.10

BIG-IP ASM

  • version 17.1.0 - 17.1.2
  • version 16.1.0 - 16.1.5

BIG-IP Advanced WAF/ASM

  • version 17.5.0 - 17.5.1
  • version 17.1.0 - 17.1.2
  • version 16.1.0 - 16.1.6
  • version 15.1.0 - 15.1.10

BIG-IP PEM

  • version 17.5.0
  • version 17.1.0 - 17.1.2
  • version 16.1.0 - 16.1.6
  • version 15.1.0 - 15.1.10

BIG-IP AFM

  • version 17.5.0
  • version 17.1.0 - 17.1.2
  • version 15.1.0 - 15.1.10

BIG-IP APM

  • version 17.5.0 - 17.5.1
  • version 17.1.0 - 17.1.2
  • version 16.1.0 - 16.1.6
  • version 15.1.0 - 15.1.10

BIG-IP APM, APM with SWG, SSL Orchestrator, SSL Orchestrator with SWG

  • version 17.5.0
  • version 17.1.0 - 17.1.2
  • version 16.1.0 - 16.1.6
  • version 15.1.0 - 15.1.10

NGINX App Protect WAF

  • version 4.5.0 - 4.6.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

蘋果產品多個漏洞

蘋果產品多個漏洞 發佈日期: 2025年12月15日 風險: 極高度風險 類型: 操作系統 - 流動裝置及操作系統 於蘋果產品發現多個漏洞。遠端...