F5 Products Denial of Service Vulnerability
A vulnerability was identified in F5 Products. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.
Note:
No patch is currently available for CVE-2026-42534 of the affected products. Hence, the risk level is rated as High Risk.
Impact
- Denial of Service
System / Technologies affected
BIG-IP Next SPK
- 2.0.0 - 2.0.3
- 1.7.0 - 1.9.2
BIG-IP Next CNF
- 2.0.0 - 2.3.2
- 1.1.0 - 1.4.3
BIG-IP Next for Kubernetes
- 2.0.0 - 2.3.2
BIG-IP DNS
- 21.1.03
- 17.5.0 - 17.5.13
- 17.1.0 - 17.1.33
Solutions
Notes: No patch is currently available.
Workaround:
Mitigate the vulnerability of attacks by following workaround:
- Restrict upstream DNS servers. Ensure that the DNS cache resolvers on your BIG-IP systems are configured to query only trusted, internal DNS servers.
- Use DNS over Transport Layer Security (TLS). If supported, configure DNS resolution over TLS to prevent man-in-the-middle (MITM) attacks on the DNS path that could inject crafted Extension Mechanisms for DNS (EDNS) responses.
- Network segmentation: Isolate the DNS resolution path so that upstream DNS servers are on a trusted, protected network segment.
- Limit DNS features: If provisioning DNS or DNS cache resolution are not required, disable them to eliminate the attack surface entirely.
Please visit the vendor web-site for more details.
Apply workarounds issued by the vendor:
沒有留言:
發佈留言