← Back

CVE-2015-4637

nvd nist
Published: Jul 16, 2015Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The REST API in F5 BIG-IQ Cloud, Device, and Security 4.4.0 and 4.5.0 before HF2 and ADC 4.5.0 before HF2, when configured for LDAP remote authentication and the LDAP server allows anonymous BIND operations, allows remote attackers to obtain an authentication token for arbitrary users by guessing an LDAP user account name.

Affected (7)

4 products
Big Iq Adc
Big Iq Cloud
Big Iq Device
Big Iq Security
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.5.0
F5
Version 4.4.0
Version 4.5.0
F5
Version 4.4.0
Version 4.5.0
F5
Version 4.4.0
Version 4.5.0

References (2)

Timeline

No history available yet.