Last Modified: May 29, 2024
Affected Product(s):
F5OS Velos
Known Affected Versions:
F5OS-A 1.0.0, F5OS-A 1.0.1, F5OS-A 1.1.0, F5OS-A 1.1.1, F5OS-A 1.2.0, F5OS-A 1.3.0, F5OS-A 1.3.1, F5OS-A 1.3.2, F5OS-A 1.5.0, F5OS-A 1.5.1, F5OS-A 1.5.2, F5OS-C 1.0.0, F5OS-C 1.1.0, F5OS-C 1.1.1, F5OS-C 1.1.2, F5OS-C 1.1.3, F5OS-C 1.1.4, F5OS-C 1.3.0, F5OS-C 1.3.1, F5OS-C 1.3.2
Fixed In:
F5OS-C 1.6.0, F5OS-A 1.4.0
Opened: Nov 04, 2022 Severity: 3-Major
On add server screen of radius server group, the secret key field is not a mandatory field, which allows the user to add a server without any secret key.
If no secret key is provided by user as the field is not mandatory, the timeout value is read as a secret key for server, which is not correct.
User created a server group of type radius and tries to add a server in that group.
User can provide a secret key even though it is not mandatory on the webUI.
Secret key field is made a mandatory field now, so the user must enter a secret key before saving the form.