Permissions, Privileges, and Access Controls in F5 Networks products - CVE-2019-6664

 

Permissions, Privileges, and Access Controls in F5 Networks products - CVE-2019-6664

Published: November 26, 2019


Vulnerability identifier: #VU22977
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6664
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to otherwise restricted functionality.

The vulnerability exists due to network protections on the management port do not follow current best practices, under certain conditions. The default firewall rules for the management interface are not reliably reinstalled after first boot. As a result, a remote attacker can expose the management interface.


Affected software

BIG-IP Analytics
BIG-IP FPS
BIG-IP ASM
BIG-IP GTM
BIG-IP APM
BIG-IP AFM
BIG-IP PEM
BIG-IP LTM
BIG-IP Edge Gateway
BIG-IP DNS
BIG-IP Link Controller
BIG-IP AAM
BIG-IP WebAccelerator
BIG-IP

How to mitigate CVE-2019-6664

Install updates from vendor's website.

BIG-IP Analytics - addressed in versions 14.1.2, 15.1.0
BIG-IP FPS - addressed in versions 14.1.2, 15.1.0
BIG-IP Edge Gateway - addressed in versions 14.1.2, 15.1.0
BIG-IP DNS - addressed in versions 14.1.2, 15.1.0
BIG-IP - addressed in versions 14.1.2, 15.0.1
BIG-IP ASM - addressed in versions 14.1.2, 15.1.0
BIG-IP GTM - addressed in versions 14.1.2, 15.1.0
BIG-IP APM - addressed in versions 14.1.2, 15.1.0
BIG-IP Link Controller - addressed in versions 14.1.2, 15.1.0
BIG-IP AFM - addressed in versions 14.1.2, 15.0.1
BIG-IP PEM - addressed in versions 14.1.2, 15.1.0
BIG-IP AAM - addressed in versions 14.1.2, 15.0.1
BIG-IP LTM - addressed in versions 14.1.2, 15.0.1
BIG-IP WebAccelerator - addressed in versions 14.1.2, 15.1.0

External References

Related Security Bulletins