PT-2019-18213 · F5 · F5 Big-Ip

Published

2019-07-03

·

Updated

2023-02-16

·

CVE-2019-6631

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 11.5.1 through 11.6.4
Description The issue occurs when iRules perform HTTP header manipulation, potentially causing an interruption to service. This happens under specific circumstances when traffic is handled by a Virtual Server with an associated HTTP profile and the requests do not strictly conform to RFCs.
Recommendations For F5 BIG-IP versions 11.5.1 through 11.6.4, consider disabling iRules that perform HTTP header manipulation until a patch is available. Restrict access to Virtual Servers with associated HTTP profiles to minimize the risk of exploitation. Avoid using HTTP header manipulation in iRules for these versions until the issue is resolved.

Fix

Related Identifiers

CVE-2019-6631

Affected Products

F5 Big-Ip