Forum Discussion
BIND vulnerability CVE-2024-1975 and CVE-2024-1737
Hello,
These vulnerabilities related to BIND.
https://kb.isc.org/docs/cve-2024-1737
https://kb.isc.org/docs/cve-2024-1975
Checked that the latest F5 version also using the affected BIND version.
https://my.f5.com/manage/s/article/K11398383
Please help to confirm if F5 will be affected to above vulnerabilities or not, if yes, please provide solution or mitigation measures.
- Aswin_mkCumulonimbus
Please find the solution for CVE-2024-1737
https://my.f5.com/manage/s/article/K000140732
FyI - DNS modules only vulnerable relating this vulnerability. Other CVE not having any document still.
- Aswin_mkCumulonimbus
Please find the details of CVE-2024-1975
Solution is following the best practice of not using the F5 Bind to directly resolve DNS, instead use Wide IP (GSLB) and DNS Express.
If you are not using F5 DNS you may not be affected.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com