F5OS-C
cpe:2.3:a:f5:f5os-c:*:*:*:*:*:*:*, +1 more
- >= 1.8.0, <= 1.8.1
- >= 1.6.0, <= 1.6.2
A denial-of-service vulnerability has been identified in the F5OS-C partition control plane. When the Allowed IP Addresses feature is set to 'All' for the 'Port' option, undisclosed traffic can cause multiple containers to terminate. This issue disrupts data plane traffic while the containers restart, but it is not exposed to the data plane itself.
Exploitation of this vulnerability leads to a denial-of-service condition on the F5OS-C partition, causing disrupted data plane traffic while the affected containers restart.
To address this vulnerability, users should avoid configuring the Allowed IP Addresses feature with 'All' for the Port setting in the F5OS-C partition. Instead, allow only the ports specific to security requirements for the F5OS-C partition. For guidance on configuring the Allowed IP Addresses feature, refer to the F5 knowledge article K000138750.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.