ConfigSync vulnerability in F5

Beledweyne Overview :
F5 BIG-IP and Enterprise Manager may expose sensitive information and allow the system configuration to be modified when using non-default ConfigSync settings.
http://kaminakapow.com/seamless-crochet-donkey-pattern/?unapproved=9911 Affected Product(s) :
  • F5 BIG-IP 15.0.0
  • F5 BIG-IP 14.1.0-14.1.0.6
  • F5 BIG-IP 14.0.0-14.0.0.5
  • F5 BIG-IP 13.0.0-13.1.1.5
  • F5 BIG-IP 12.1.0-12.1.4.1
  • F5 BIG-IP 11.6.0-11.6.4
  • F5 BIG-IP 11.5.1-11.5.9
  • Enterprise Manager 3.1.1
Vulnerability Details :
CVE ID : CVE-2019-6649
F5 BIG-IP and Enterprise Manager may expose sensitive information and allow the system configuration to be modified when using non-default ConfigSync settings. (CVE-2019-6649)

Solution : F5 recommends upgrading to a fixed software version to fully mitigate this vulnerability.

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-37079 : VMWARE VCENTER SERVER/CLOUD FOUNDATION DCERPC HEP-BASED OVERFLOW

CVE-2024-37079 : VMWARE VCENTER SERVER/CLOUD FOUNDATION DCERPC HEP-BASED OVERFLOW

Description vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access

CVE-2024-5469 : GITLAB COMMUNITY EDITION/ENTERPRISE EDITION UP TO 16.10.5/16.11.2 KAS RESOURCE CONSUMPTION

CVE-2024-5469 : GITLAB COMMUNITY EDITION/ENTERPRISE EDITION UP TO 16.10.5/16.11.2 KAS RESOURCE CONSUMPTION

Description DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3

CVE-2024-27172 : TOSHIBA TEC E-STUDIO MULTI-FUNCTION PERIPHERAL OS COMMAND INJECTION

CVE-2024-27172 : TOSHIBA TEC E-STUDIO MULTI-FUNCTION PERIPHERAL OS COMMAND INJECTION

Description Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference