CVE-2017-6131
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into the BIG-IP system. The impacted administrative account is the Azure instance administrative user that was created at deployment. The root and admin accounts are not vulnerable. An attacker may be able to remotely access the BIG-IP host via SSH.
Affected (45)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
References (4)
Source: f5sirt@f5.com
Source: f5sirt@f5.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Timeline
No history available yet.