Skip to content

F5 Fixes Major BIG-IP Load Balancer Security Flaw Before PCI Deadline

F5 acts swiftly to patch a high-risk vulnerability in its BIG-IP Load Balancer. Users must apply the fix to avoid PCI compliance failure and protect sensitive data.

In this image I can see a box full of cookies. To the cap of the box there is some text and design...
In this image I can see a box full of cookies. To the cap of the box there is some text and design on it.

F5 Fixes Major BIG-IP Load Balancer Security Flaw Before PCI Deadline

F5 Networks has addressed a significant security flaw in its BIG-IP Load Balancer. The vulnerability, identified as QID 86725, involves the disclosure of internal IP addresses. This issue will result in a PCI failure starting May 1, 2018.

F5 published the solution before May 1, 2018, on their support website. They offer multiple remediation methods to mitigate the risk. The vulnerability, known as 'F5 BIG-IP Load Balancer Internal IP Address Disclosure', occurs due to the encoding of private IP addresses in persistent cookies. Attackers can collect and decode these cookies, exposing sensitive information.

The encoding and decoding process is well-documented and relatively simple, contributing to a high Common Vulnerability Scoring System (CVSS) score. This high score indicates a severe impact on confidentiality and integrity.

F5 Networks has provided remedies for the QID 86725 vulnerability in their BIG-IP Load Balancer. Users should apply these solutions promptly to avoid PCI compliance failure and protect their systems from potential attacks.

Read also:

Latest