Overview
F5 Networks has reported a flaw in the BIG-IP APM and the FirePass client-side F5-signed Edge Client components. The components may leak information from memory. (CWE-200)
Description
F5 Networks has reported a flaw in the BIG-IP APM and the FirePass client-side F5-signed Edge Client components. The components may leak information from memory. Additional details may be found in the F5 SOL14969 security advisory. |
Impact
A local attacker may be able to access sensitive information from Edge Client memory. |
Solution
Apply an Update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4.4 | AV:L/AC:M/Au:S/C:C/I:N/A:N |
Temporal | 3.6 | E:F/RL:OF/RC:C |
Environmental | 6.2 | CDP:MH/TD:H/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Giorgio Casali and Simone Cecchini with Verizon Enterprise Solutions GCIS Threat and Vulnerability Management for discovering this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2013-6024 |
Date Public: | 2013-02-04 |
Date First Published: | 2014-02-06 |
Date Last Updated: | 2014-02-06 19:01 UTC |
Document Revision: | 13 |