In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.
2020-04-24T14:15:14.233
2024-11-21T05:34:44.170
Modified
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | f5 | big-iq_centralized_management | ≤ 5.4.0 | Yes |
Application | f5 | big-iq_centralized_management | ≤ 6.1.0 | Yes |
Application | f5 | big-iq_centralized_management | < 7.1.0 | Yes |