Permissions, Privileges, and Access Controls in F5 Networks products - CVE-2019-6664

 

Permissions, Privileges, and Access Controls in F5 Networks products - CVE-2019-6664

Published: November 26, 2019


Vulnerability identifier: #VU22977
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-6664
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: F5 Networks
Affected software:
BIG-IP
BIG-IP LTM
BIG-IP AFM
BIG-IP Analytics
BIG-IP APM
BIG-IP ASM
BIG-IP FPS
BIG-IP GTM
BIG-IP PEM
BIG-IP AAM
BIG-IP DNS
BIG-IP Edge Gateway
BIG-IP Link Controller
BIG-IP WebAccelerator

Detailed vulnerability description

The vulnerability allows a remote attacker to gain access to otherwise restricted functionality.

The vulnerability exists due to network protections on the management port do not follow current best practices, under certain conditions. The default firewall rules for the management interface are not reliably reinstalled after first boot. As a result, a remote attacker can expose the management interface.


How to mitigate CVE-2019-6664

Install updates from vendor's website.

Sources