Forum Discussion
CVE-2015-1793
Hi,
Does anyone know if F5 devices are affected by this OpenSSL vulnerability, CVE-2015-1793?
Thanks!
2 Replies
- steigman1978_87
Nimbostratus
Hi Nolipineda, there is a SOL available for CVE-2015-1793 but currently it´s not showing any more details i.e. Version or Vulnerable component.
SOL16937 https://support.f5.com/kb/en-us/solutions/public/16000/900/sol16937.html
F5 is still researching, so it´s up to us of waiting for any SOL Updates.
Would be also interesting to know whether the use of “native” Cipher will mitigate that vulnerability as they have been implemented into hardware.
https://support.f5.com/kb/en-us/solutions/public/13000/100/sol13163.html
Additional to CVE-2015-1793 another SOL for CVE-2015-1788 which might be worth to have a look in: https://support.f5.com/kb/en-us/solutions/public/16000/900/sol16938.html?ref=rss
cheers, Steigman
- John_Heyer_1508
Cirrostratus
The affected OpenSSL versions have been out less than a month:
https://www.openssl.org/news/openssl-1.0.2-notes.html
https://www.openssl.org/news/openssl-1.0.1-notes.html
I doubt any vendor has based their software off these version. Also, this really more of a client side vulnerability than server, so you'd have to trick the device in to opening a connection to a non-trusted site, which is not going to be easy.
In short, nothing to see here, move along...
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com