Rewterz

Rewterz Threat Alert – E-Invoice dropping Danabot Banking Trojan

July 3, 2019
Rewterz

Rewterz Threat Advisory – CVE-2019-6819 – Schneider Electric Modicon Controllers Denial of Service Vulnerability

July 4, 2019

Rewterz Threat Advisory – CVE-2019-6623 – F5 Multiple BIG-IP Products Denial of Service Vulnerability

Severity

Medium

Analysis Summary

An error when handling certain traffic related to BIG-IP iSession virtual can be exploited to can be exploited to cause a restart of the Traffic Management Microkernel (TMM).

Impact

Denial of Service

Affected Vendors

F5

Affected Products

  • F5 BIG-IP Local Traffic Manager (LTM) 12.x
  • F5 BIG-IP Application Security Manager (ASM) 12.x
  • F5 BIG-IP Local Traffic Manager (LTM) 13.x
  • F5 BIG-IP Application Security Manager (ASM) 13.x
  • F5 BIG-IP Local Traffic Manager (LTM) 14.x
  • F5 BIG-IP Access Policy Manager (APM) 12.x
  • F5 BIG-IP Access Policy Manager (APM) 13.x
  • F5 BIG-IP Advanced Firewall Manager (AFM) 12.x
  • F5 BIG-IP Advanced Firewall Manager (AFM) 13.x
  • F5 TMOS 12.x
  • F5 BIG-IP DNS (formerly Global Traffic Manager (GTM)) 12.x

Remediation

Update to version 12.1.4.1, 13.1.1.5, 14.0.0.5, or 14.1.0.6.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.