C
月内に
F5社は、BIG-IP、BIG-IQ、NGINX製品、およびAPMクライアントにおける複数の脆弱性に関するセキュリティアドバイザリ
📌 一言でいうと
F5社は、BIG-IP、BIG-IQ、NGINX製品、およびAPMクライアントにおける複数の脆弱性に関するセキュリティアドバイザリを公開しました。影響を受けるバージョンは多岐にわたり、管理者は速やかに最新の修正バージョンへのアップデートを適用することが推奨されています。詳細な修正内容はベンダーの公式通知(K000162872)で確認可能です。
🔍該当判定
- F5社の製品『BIG-IP』を導入しており、バージョンが 17.1.3.4 / 17.5.1.8 / 21.0.0.3 / 21.1.0.1 より古い
- F5社の製品『BIG-IQ』を導入しており、バージョンが 8.4.2.1 より古い
- 『NGINX Gateway Fabric』『NGINX Ingress Controller』『NGINX JavaScript』のいずれかを利用している
- 『APM Clients』を導入しており、バージョンが 7.2.6 より古い
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ベンダーの公式アドバイザリ(K000162872)を確認し、利用している製品のバージョンが対象であるかを確認した上で、最新の修正バージョンへアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】F5製品 (BIG-IP, BIG-IQ, NGINX) 脆弱性対応について
お疲れさまです。F5製品の脆弱性に関する情報共有です。
■ 概要
F5のBIG-IP、BIG-IQ、NGINX製品、およびAPMクライアントにおいて脆弱性が確認されました。詳細な脆弱性内容はベンダーのセキュリティ通知にて公開されています。
■ 影響範囲
- BIG-IP (all modules): 17.1.3.4, 17.5.1.8, 21.0.0.3, 21.1.0.1 未満
- BIG-IQ: 8.4.2.1 未満
- NGINX Gateway Fabric: 2.6.8 未満
- NGINX Ingress Controller: 2026-lts-r5, 5.6.0 未満
- NGINX JavaScript: 1.0.1 未満
- APM Clients: 7.2.6 未満
- BIG-IP APM: 複数バージョン
■ 対応手順
1. 自社で利用しているF5製品のバージョンを確認してください。
2. 影響を受けるバージョンである場合、ベンダーが提供する最新の修正バージョンへアップデートを適用してください。
■ 参考情報
- F5 Security Notification K000162872
対応優先度: 高
対応期限: 速やかに
お疲れさまです。F5製品の脆弱性に関する情報共有です。
■ 概要
F5のBIG-IP、BIG-IQ、NGINX製品、およびAPMクライアントにおいて脆弱性が確認されました。詳細な脆弱性内容はベンダーのセキュリティ通知にて公開されています。
■ 影響範囲
- BIG-IP (all modules): 17.1.3.4, 17.5.1.8, 21.0.0.3, 21.1.0.1 未満
- BIG-IQ: 8.4.2.1 未満
- NGINX Gateway Fabric: 2.6.8 未満
- NGINX Ingress Controller: 2026-lts-r5, 5.6.0 未満
- NGINX JavaScript: 1.0.1 未満
- APM Clients: 7.2.6 未満
- BIG-IP APM: 複数バージョン
■ 対応手順
1. 自社で利用しているF5製品のバージョンを確認してください。
2. 影響を受けるバージョンである場合、ベンダーが提供する最新の修正バージョンへアップデートを適用してください。
■ 参考情報
- F5 Security Notification K000162872
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] F5 Products (BIG-IP, BIG-IQ, NGINX) Vulnerability Mitigation
Dear Team,
This is a notification regarding security vulnerabilities identified in F5 products.
■ Overview
Vulnerabilities have been reported affecting BIG-IP, BIG-IQ, NGINX products, and APM clients. Please refer to the vendor's security notification for technical details.
■ Affected Scope
- BIG-IP (all modules): Prior to 17.1.3.4, 17.5.1.8, 21.0.0.3, 21.1.0.1
- BIG-IQ: Prior to 8.4.2.1
- NGINX Gateway Fabric: Prior to 2.6.8
- NGINX Ingress Controller: Prior to 2026-lts-r5, 5.6.0
- NGINX JavaScript: Prior to 1.0.1
- APM Clients: Prior to 7.2.6
- BIG-IP APM: Multiple versions
■ Mitigation Steps
1. Verify the current versions of F5 products deployed in our environment.
2. If affected, update to the latest patched versions as recommended by the vendor.
■ Reference
- F5 Security Notification K000162872
Priority: High
Deadline: Immediate
Dear Team,
This is a notification regarding security vulnerabilities identified in F5 products.
■ Overview
Vulnerabilities have been reported affecting BIG-IP, BIG-IQ, NGINX products, and APM clients. Please refer to the vendor's security notification for technical details.
■ Affected Scope
- BIG-IP (all modules): Prior to 17.1.3.4, 17.5.1.8, 21.0.0.3, 21.1.0.1
- BIG-IQ: Prior to 8.4.2.1
- NGINX Gateway Fabric: Prior to 2.6.8
- NGINX Ingress Controller: Prior to 2026-lts-r5, 5.6.0
- NGINX JavaScript: Prior to 1.0.1
- APM Clients: Prior to 7.2.6
- BIG-IP APM: Multiple versions
■ Mitigation Steps
1. Verify the current versions of F5 products deployed in our environment.
2. If affected, update to the latest patched versions as recommended by the vendor.
■ Reference
- F5 Security Notification K000162872
Priority: High
Deadline: Immediate