CVE-2019-6675
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in a complete compromise of the system. This issue only impacts specific engineering hotfixes using the aforementioned authentication configuration. NOTE: This vulnerability does not affect any of the BIG-IP major, minor or maintenance releases you obtained from downloads.f5.com. The affected Engineering Hotfix builds are as follows: Hotfix-BIGIP-14.1.0.3.0.79.6-ENG.iso, Hotfix-BIGIP-14.1.0.3.0.97.6-ENG.iso, Hotfix-BIGIP-14.1.0.3.0.99.6-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.15.5-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.36.5-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.40.5-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.11.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.14.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.68.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.70.9-ENG.iso, Hotfix-BIGIP-14.1.2.0.11.37-ENG.iso, Hotfix-BIGIP-14.1.2.0.18.37-ENG.iso, Hotfix-BIGIP-14.1.2.0.32.37-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.46.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.14.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.16.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.34.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.97.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.99.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.105.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.111.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.115.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.122.4-ENG.iso, Hotfix-BIGIP-15.0.1.0.33.11-ENG.iso, Hotfix-BIGIP-15.0.1.0.48.11-ENG.iso
Affected (264)
Products: F5: Big Ip Link Controller, Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Fraud Protection Service, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Analytics, Big Ip Domain Name System, Big Ip Global Traffic Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0.1.0.33.11-eng_hotfix to 15.0.1.0.48.11-eng_hotfix |
References (4)
Source: f5sirt@f5.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.