Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Big-ip_local_traffic_manager | F5 | 12.1.3 (including) | 12.1.4 (including) |
Big-ip_local_traffic_manager | F5 | 13.0.0 (including) | 13.1.2 (including) |
Big-ip_local_traffic_manager | F5 | 14.0.0 (including) | 14.0.0 (including) |
Big-ip_local_traffic_manager | F5 | 14.1.0 (including) | 14.1.0 (including) |