Improper Certificate Validation in BIG-IP ASM - CVE-2019-6687
Published: December 20, 2019
BIG-IP ASM
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a man-in-the-middle attack.
The vulnerability exists due to the Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints. A remote attacker can perform a man-in-the-middle attack, intercept traffic destined for cloud services and read and modify data that is in transit.