SB2016092904 - Security restrictions bypass in F5 BIG-IP products 



SB2016092904 - Security restrictions bypass in F5 BIG-IP products

Published: September 29, 2016

Security Bulletin ID SB2016092904
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2016-5700)

The vulnerability allows a remote unauthenticated user to cause arbitrary commands execution on the target system.
The weakness exists due to access control error and affects BIG-IP virtual servers with a configuration using the HTTP Explicit Proxy functionality and/or SOCKS profile. Such flaw allows a malicious user to trigger modification of BIG-IP system configuration, information disclosure that may lead to arbitrary commands execution.
Successful exploitation of the vulnerability may result in certain consequences including arbitrary commands execution on the vulnerable system.

Remediation

Install update from vendor's website.