Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
F5 heeft kwetsbaarheden verholpen in BIG-IP.
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Omzeilen van een beveiligingsmaatregel
- Uitvoer van willekeurige code (Root/admin)
- Uitvoer van willekeurige code (Gebruiker)
- Toegang tot gevoelige gegevens
- Oplossingen
F5 heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-772
Missing Release of Resource after Effective Lifetime
- CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
- CWE-311
Missing Encryption of Sensitive Data
- CWE-426
Untrusted Search Path
- CWE-345
Insufficient Verification of Data Authenticity
- CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-190
Integer Overflow or Wraparound
- CWE-693
Protection Mechanism Failure
- CWE-125
Out-of-bounds Read
- CWE-401
Missing Release of Memory after Effective Lifetime
- CWE-476
NULL Pointer Dereference
- CWE-400
Uncontrolled Resource Consumption
- CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CWE-787
Out-of-bounds Write
- CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CWE-20
Improper Input Validation
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard