For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

MDPF5_152674's avatar
MDPF5_152674
Icon for Altostratus rankAltostratus
Jun 10, 2014

Question about Vulnerability on BIG IP System CVE-2014-0224

Hi Community,

 

Vulnerabilty: CVE-2014-0224

 

The question is: If i have BIG IP System that runs 11.2.1 Version with the LTM and ASM module currently active,

 

Is my BIG IP System affected by this Vulnerability? Because the version 11.2.1 isn't listed in the "versions known to be vulnerable"

 

Current OpenSSL Version: 0.9.8u (command openssl version on CLI) http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15325.html

 

What is the possible way to fix this Vulnerabilty?

 

Thanks in advance,

 

M.

 

4 Replies

    • MDPF5_152674's avatar
      MDPF5_152674
      Icon for Altostratus rankAltostratus
      But a) range and b) range are listed on : Versions known to be not vulnerable
    • Sven_Leupold_85's avatar
      Sven_Leupold_85
      Icon for Cirrus rankCirrus
      You're right! In that case I would say that you are not affected at all. Your's is in "Versions known to be not vulnerable" range (a).
    • MDPF5_152674's avatar
      MDPF5_152674
      Icon for Altostratus rankAltostratus
      Ok, but i think that my OpenSSL version 0.9.8u is vulnerable (that it's what the documentation says) So, is a documentation error? Or is my fault? Thank You