CVE-2012-1493
7.8
Vector
AV:N/AC:L/Au:N/C:C/I:N/A:N
Exploitability: 10.0 / Impact: 6.9
Source: NVD
Description
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
Affected (114)
Products: F5: Big Ip Application Security Manager, Big Ip Global Traffic Manager, Big Ip Local Traffic Manager, Tmos, Big Ip 1000, Big Ip 11000, Big Ip 11050, Big Ip 1500, Big Ip 1600, Big Ip 2400, Big Ip 3400, Big Ip 3410, Big Ip 3600, Big Ip 3900, Big Ip 4100, Big Ip 5100, Big Ip 5110, Big Ip 6400, Big Ip 6800, Big Ip 6900, Big Ip 8400, Big Ip 8800, Big Ip 8900, Big Ip 8950, Enterprise Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0.0 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Related CWEs
References (8)
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
ExploitPatch
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.