← Back

CVE-2019-6609

nvd nist
Published: Apr 15, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) versions 14.0.0-14.1.0.1, 13.0.0-13.1.1.3, and 12.1.1 HF2-12.1.4, the secureKeyCapable attribute was not set which causes secure vault to not use the F5 hardware support to store the unit key. Instead the unit key is stored in plaintext on disk as would be the case for Z100 systems. Additionally this causes the unit key to be stored in UCS files taken on these platforms.

Affected (52)

14 products
Big Ip Local Traffic Manager
Big Ip Advanced Firewall Manager
Big Ip Analytics
Big Ip Access Policy Manager
Big Ip Domain Name System
Big Ip Edge Gateway
Big Ip Fraud Protection Service
Big Ip Global Traffic Manager
Big Ip Link Controller
Big Ip Policy Enforcement Manager
Big Ip Webaccelerator
Big Ip Webaccelerator12.1.1
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration E
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration F
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration G
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration H
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration I
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration J
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration K
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration L
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version 12.1.1 hf2
Configuration M
4 vulnerable · 23 platform
Vulnerable SoftwareAffected Versions
F5
From 12.1.2 to 12.1.4.1
From 13.0.0 to 13.1.1.4
From 14.0.0 to 14.1.0.2
Version hf2
Running on/withPlatform Versions
F5
Big Ip I10600
All versions
F5
Big Ip I10800
All versions
F5
Big Ip I11600
All versions
F5
Big Ip I11800
All versions
F5
Big Ip I15600
All versions
F5
Big Ip I15800
All versions
F5
Big Ip I2000s
All versions
F5
Big Ip I2200s
All versions
F5
Big Ip I4000s
All versions
F5
Big Ip I4200v
All versions
F5
Big Ip I5000s
All versions
F5
Big Ip I5050s
All versions
F5
Big Ip I5200v
All versions
F5
Big Ip I5250v
All versions
F5
Big Ip I5250v Fips
All versions
F5
Big Ip I7000
All versions
F5
Big Ip I7050s
All versions
F5
Big Ip I7055s
All versions
F5
Big Ip I7200v
All versions
F5
Big Ip I7200v Ssl
All versions
F5
Big Ip I7200v Fips
All versions
F5
Big Ip I7250v
All versions
F5
Big Ip I7255s
All versions

References (2)

Source: f5sirt@f5.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.