For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Carlos_13563's avatar
Apr 08, 2014

CVE-2014-0160 notification just came out.

Is F5 affected by this CVE-2014-0160?

 

6 Replies

  • Joe_M's avatar
    Joe_M
    Icon for Nimbostratus rankNimbostratus

    only 11.5.0 is affected and only if you are using the compat cipher suite instead of the native suite. Below is a copy of an email from an F5 field engineer.

     

    Only TMOS 11.5.0 is vulnerable to CVE-2014-0160, and then only on management or on VIPS using the 'COMPAT' ciphers. VIPS using the NATIVE ciphers, which is the default, are not affected. TMOS less than 11.5.0 is not affected. ID456033 is open for this CVE and I'm working on getting a SOL created.

     

    Also, here is some more info on the vulnerability.

     

    http://www.openssl.org/news/vulnerabilities.html2014-0160 http://www.openssl.org/news/secadv_20140407.txt http://support.f5.com/kb/en-us/solutions/public/14000/400/sol14457.html http://heartbleed.com/ http://filippo.io/Heartbleed/ https://devcentral.f5.com/questions/openssl-and-heart-bleed-vuln

     

  • goldie_01_14551's avatar
    goldie_01_14551
    Historic F5 Account

    see below solution article for official answer from F5.

     

    http://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html

     

    • foo_98658's avatar
      foo_98658
      Icon for Nimbostratus rankNimbostratus
      Hi IheartF5, please read the SOL more closely. Focusing solely on LTM only 11.5.0 - 11.5.1 are vulnerable. Older 10.x are not vulnerable to this exploit.
  • Sorry you were right! It says it's affected at the top and then further down says it's not.

     

  • Jeff_Costlow_10's avatar
    Jeff_Costlow_10
    Historic F5 Account

    The "Applies to" box is meant to show you which products from F5 are included in the solution note. E.g. if a SOL only applied to FirePass, then it would be in the Applies To box.

     

    In this case, no F5 product is vulnerable to CVE-2014-0160 except those identified in the table in the Status section.