Forum Discussion
CVE-2015-1793
Hi,
Does anyone know if F5 devices are affected by this OpenSSL vulnerability, CVE-2015-1793?
Thanks!
- steigman1978_87Nimbostratus
Hi Nolipineda, there is a SOL available for CVE-2015-1793 but currently it´s not showing any more details i.e. Version or Vulnerable component.
SOL16937 https://support.f5.com/kb/en-us/solutions/public/16000/900/sol16937.html
F5 is still researching, so it´s up to us of waiting for any SOL Updates.
Would be also interesting to know whether the use of “native” Cipher will mitigate that vulnerability as they have been implemented into hardware.
https://support.f5.com/kb/en-us/solutions/public/13000/100/sol13163.html
Additional to CVE-2015-1793 another SOL for CVE-2015-1788 which might be worth to have a look in: https://support.f5.com/kb/en-us/solutions/public/16000/900/sol16938.html?ref=rss
cheers, Steigman
- John_Heyer_1508Cirrostratus
The affected OpenSSL versions have been out less than a month:
https://www.openssl.org/news/openssl-1.0.2-notes.html
https://www.openssl.org/news/openssl-1.0.1-notes.html
I doubt any vendor has based their software off these version. Also, this really more of a client side vulnerability than server, so you'd have to trick the device in to opening a connection to a non-trusted site, which is not going to be easy.
In short, nothing to see here, move along...
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com