Forum Discussion

Fred_A_30606's avatar
Fred_A_30606
Icon for Nimbostratus rankNimbostratus
May 13, 2014

Security Mailing List Updates

I have been subscribed to the F5 security mailing list for some time now (security-subscribe@lists.f5.com) but only ever seem to get updates regarding ASM attack signatures and not any vulnerabilities.

 

One recent example is SOL15220: iControl vulnerability CVE-2014-2928 which was received via AUSCERT but nothing from the F5 security mailing list.

 

Does anyone else experience the same thing for monitoring F5 vulnerabilities?

 

6 Replies

  • on 4/9/14, I got one for the OpenSSL vulnerability. Did you get that one? I'm not sure why that one that you post there wouldn't have been sent out as a security.

     

  • Yes, you're right James I did get that one for Heartbleed Subject: OpenSSL vulnerability CVE-2014-0160 (VU720951) aka Heartbleed

     

  • same here, mainly ASM updates, heartbleed was pretty much the exception recently.

     

  • I logged Service Request : C1576287 for this and will contact our account manager too. It seems logical that the security mailing list should be sending notices regarding F5 vulnerabilities.

     

    Thanks for your responses and I will let you know what happens.

     

    • Jason_Cohen_417's avatar
      Jason_Cohen_417
      Historic F5 Account
      Has there been any progress on this? I'd be interested in getting updates from this list anytime there is new information about and F5 related vulnerability.
    • Fred_A_30606's avatar
      Fred_A_30606
      Icon for Nimbostratus rankNimbostratus
      Cohen - On the same day you posted your comment I received a security list email regarding CVE-2014-2927. Did you get that one? F5 told me that my service request regarding the F5 security list has sparked some internal discussion - perhaps they will be providing more vulnerabilities via this method in the future however for now they informed me that he RSS feeds are the best way to track vulns. Below is some info from the case I can share. According to your needs I believe that the RSS solution is the quickest way to receive the security advisory solutions: RSS feed for Security Advisory Solutions specifically (new and/or updated ones): http://support.f5.com/kb/en-us/rss.rss.doctype-securityadvisorypage.pageStatus-new.xml For further customization you can select amongst the categories here: http://support.f5.com/kb/en-us/rss.html Coming now to Outlook configuration, I searched on the Internet and for example you could use the sample configuration from the article below to set it up: http://blogmines.com/blog/how-to-use-outlook-2010-as-a-rss-reader/ The TechNews mailing list is an alternative but only if you prefer to receive updates weekly.