CVE-2019-6687

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
23/12/2019
Last modified:
24/08/2020

Description

On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* 15.0.0 (including) 15.1.0 (excluding)


References to Advisories, Solutions, and Tools