Forum Discussion
CVE-2014-0160 notification just came out.
only 11.5.0 is affected and only if you are using the compat cipher suite instead of the native suite. Below is a copy of an email from an F5 field engineer.
Only TMOS 11.5.0 is vulnerable to CVE-2014-0160, and then only on management or on VIPS using the 'COMPAT' ciphers. VIPS using the NATIVE ciphers, which is the default, are not affected. TMOS less than 11.5.0 is not affected. ID456033 is open for this CVE and I'm working on getting a SOL created.
Also, here is some more info on the vulnerability.
http://www.openssl.org/news/vulnerabilities.html2014-0160 http://www.openssl.org/news/secadv_20140407.txt http://support.f5.com/kb/en-us/solutions/public/14000/400/sol14457.html http://heartbleed.com/ http://filippo.io/Heartbleed/ https://devcentral.f5.com/questions/openssl-and-heart-bleed-vuln
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com