NCSC-NL/spring4shell

F5 listing incorrect

Closed this issue · 1 comments

In the software overview F5 is shown as "Not applicable" and "Not Vulnerable" for all products, but that is incorrect based on the information available; In https://support.f5.com/csp/article/K11510688 the company states that only all products related to NGINX are not affected and "not applicable", all other F5 products are still under investigation as marked with double star (**) in the table.

As per the F5 knowledge article:

** Confirmation of vulnerability or non-vulnerability is not presently available. F5 is still researching the issue for the products indicated, and will update this article with the most current information as soon as it has been confirmed. F5 Support has no additional information on this issue.

pbeij commented

Hi Jeffry, Thanks for pointing out this issue.
Changed the software overview.

If you have comments, please let me know.