BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in a complete compromise of the system. This issue only impacts specific engineering hotfixes using the aforementioned authentication configuration. (CVE-2019-6675)
Impact
Remote users authenticating to the BIG-IP system using LDAP, Active Directory, or Client Certificate LDAP are able to log in with incorrect credentials resulting in a complete compromise of the BIG-IP system.
Important: This vulnerability impacts only BIG-IP Engineering Hotfixes you obtained from F5 Support. Refer to the table in the following section for the list of affected versions. To verify if you are running an affected version from this list, perform the procedure in theRecommended Actions section. This vulnerability does not affect any of the BIG-IP major, minor, or maintenance releases you obtained from downloads.f5.com.