Forum Discussion

eben's avatar
eben
Icon for Nimbostratus rankNimbostratus
Feb 26, 2018

iHealth CVE Report

Hi All,

 

I am about to upgrade a client's TMOS version based on vulnerability heuristics report from . Now here's my Q. For one of the critical CVE, it says fixes are introduced in version 11.6 HF2, 12.1 HF1. Does this mean the fix is not in version 12.0?

 

Thanks.

 

1 Reply

  • v12.0 went EoSD on the release date of v12.1, so it's quite likely that the fix has not been rolled into the v12.0 branch.

     

    From K5903: BIG-IP software support policy:

     

    "At the end of a release’s Standard Support phase, the release enters its EoSD phase. Software versions that have reached their EoSD date are no longer supported with active software development. These software versions will continue to receive reasonable effort configuration support until reaching their EoTS date. However, F5 will not provide software fixes (hotfixes) or consulting services for that version during the EoSD phase."