← Back

CVE-2015-8611

nvd nist
Published: Jan 12, 2016Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, and PEM 12.0.0 before HF1 on the 2000, 4000, 5000, 7000, and 10000 platforms do not properly sync passwords with the Always-On Management (AOM) subsystem, which might allow remote attackers to obtain login access to AOM via an (1) expired or (2) default password.

Affected (9)

9 products
Big Ip Domain Name System
Big Ip Link Controller
Big Ip Policy Enforcement Manager
Big Ip Advanced Firewall Manager
Big Ip Local Traffic Manager
Big Ip Access Policy Manager
Big Ip Analytics
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0.0
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0.0
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0.0
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0.0
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0.0

Related CWEs

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.