← Back

CVE-2017-6131

nvd nist
Published: May 23, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into the BIG-IP system. The impacted administrative account is the Azure instance administrative user that was created at deployment. The root and admin accounts are not vulnerable. An attacker may be able to remotely access the BIG-IP host via SSH.

Affected (45)

9 products
Big Ip Local Traffic Manager
Big Ip Advanced Firewall Manager
Big Ip Access Policy Manager
Big Ip Domain Name System
Big Ip Link Controller
Big Ip Policy Enforcement Manager
Big Ip Websafe
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 12.0.0
Version 12.1.0
Version 12.1.1
Version 12.1.2
Version 13.0.0
Configuration B
5 vulnerable
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 12.0.0
Version 12.1.0
Version 12.1.1
Version 12.1.2
Version 13.0.0
Configuration D
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 12.0.0
Version 12.1.0
Version 12.1.1
Version 12.1.2
Version 13.0.0
Configuration E
5 vulnerable
Configuration F
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 12.0.0
Version 12.1.0
Version 12.1.1
Version 12.1.2
Version 13.0.0
Configuration G
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 12.0.0
Version 12.1.0
Version 12.1.1
Version 12.1.2
Version 13.0.0
Configuration H
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 12.0.0
Version 12.1.0
Version 12.1.1
Version 12.1.2
Version 13.0.0
Configuration I
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 12.0.0
Version 12.1.0
Version 12.1.1
Version 12.1.2
Version 13.0.0

References (4)

Source: f5sirt@f5.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory

Timeline

No history available yet.