Forum Discussion
Any official statement on latest openssl vulnerability CVE-2014-3569 ?
Are any versions impacted for CVE-2014-3569 ?
The NVD score is Medium but it seems so easy to exploit this remotely and it is also pre-authentication so mandatory client certificates will not help you either.
Any iRule logic to identify the signature via binary scan ?
Best.
2 Replies
- Brad_Parker
Cirrus
Since it is OpenSSL I would assume it would only affect the management GUI and potentially SSL profiles that use COMPAT ciphers. As with many OpenSSL vulnerabilities, one would assume if you are using the NATIVE cipher stack, the traffic interface shouldn't be affected.
- Pascal_Tene_910Historic F5 Account
This only affects OpenSSL 1.0.1j. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3569 You can check which openSSL version you are using from CLI by running the command openssl version. BigIP version 11.6.0 uses OpenSSL 1.0.1h. it is highly probable that no BigIP version is affected by this CVE. No Official statement at the moment.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com