CVE-2016-5736
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP DNS 12.x before 12.0.0 HF2; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.1 before HF16; BIG-IP GTM 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, and 11.6.x before 11.6.1; and BIG-IP PSM 11.4.0 through 11.4.1 improperly enables the anonymous IPsec IKE peer configuration object, which allows remote attackers to establish an IKE Phase 1 negotiation and possibly conduct brute-force attacks against Phase 2 negotiations via unspecified vectors.
Affected (94)
Products: F5: Big Ip Application Acceleration Manager, Big Ip Webaccelerator, Big Ip Analytics, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Local Traffic Manager, Big Ip Advanced Firewall Manager, Big Ip Websafe, Big Ip Policy Enforcement Manager, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Protocol Security Module, Big Ip Wan Optimization Manager, Big Ip Access Policy Manager, Big Ip Application Security Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.6.0 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 | |
| Version 11.2.1 |
References (4)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.