2026年8月11日星期二

F5 Products Denial of Service Vulnerability

F5 Products Denial of Service Vulnerability

A vulnerability was identified in F5 Products. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.

 

Note:

No patch is currently available for CVE-2026-42534 of the affected products. Hence, the risk level is rated as High Risk.


Impact

  • Denial of Service

System / Technologies affected

BIG-IP Next SPK

 

  • 2.0.0 - 2.0.3
  • 1.7.0 - 1.9.2

 

BIG-IP Next CNF

 

  • 2.0.0 - 2.3.2
  • 1.1.0 - 1.4.3

 

BIG-IP Next for Kubernetes

 

  • 2.0.0 - 2.3.2

 

BIG-IP DNS

 

  • 21.1.03
  • 17.5.0 - 17.5.13
  • 17.1.0 - 17.1.33
 

Solutions

Notes: No patch is currently available.

 

Workaround:

Mitigate the vulnerability of attacks by following workaround:

 

  • Restrict upstream DNS servers. Ensure that the DNS cache resolvers on your BIG-IP systems are configured to query only trusted, internal DNS servers.
  • Use DNS over Transport Layer Security (TLS). If supported, configure DNS resolution over TLS to prevent man-in-the-middle (MITM) attacks on the DNS path that could inject crafted Extension Mechanisms for DNS (EDNS) responses.
  • Network segmentation: Isolate the DNS resolution path so that upstream DNS servers are on a trusted, protected network segment.
  • Limit DNS features: If provisioning DNS or DNS cache resolution are not required, disable them to eliminate the attack surface entirely.

 

Please visit the vendor web-site for more details.

 

Apply workarounds issued by the vendor:


Vulnerability Identifier


Source


Related Link

https://my.f5.com/manage/s/article/K000162784

沒有留言:

發佈留言

F5 產品阻斷服務漏洞

F5 產品阻斷服務漏洞 發佈日期: 2026年08月11日 於 F5 產品發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。   注意: 受影響之系統或技術暫無可修補 CVE-2026-42534 的修補程式。因此,風險等級評為高度風險。   影響 阻斷服務 受影...