Our takeF5 published an advisory for a DoS vulnerability in BIG-IP DNS (CVSS 7.5). Patch if you run it; most smaller teams use cloud or third-party DNS and can ignore this one.Cyber Resilience desk
Sources (4)
- govcert_hk · govcert_hk
- govcert_hk · govcert_hk
- hkcert · hkcert
- auscert_bulletins · auscert_bulletins
What this means for you — Security leader:Patch F5 BIG-IP DNS to the fixed version listed in the advisory if you self-host it. Most enterprises using BIG-IP Next for Kubernetes should also review and apply the separate advisory.
What this means for you — Lean IT orgs:If you run an on-premise F5 BIG-IP DNS appliance, apply the vendor patch immediately. Most smaller teams use cloud services or different load balancers and can ignore this.
What this means for you — MSP:Check every client running on-premise F5 BIG-IP DNS and apply the published patch; also review any BIG-IP Next for Kubernetes deployments against the second advisory.
What this means for you — Researcher:F5 published two related advisories covering a DoS vulnerability in BIG-IP DNS (CVSS 7.5) and a separate issue in BIG-IP Next for Kubernetes.