Improper access control in F5 Networks products - CVE-2019-6665
Published: November 29, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker with access to the device communication between the BIG-IP ASM Central Policy Builder and the BIG-IQ/Enterprise Manager/F5 iWorkflow can set up the proxy the same way and intercept the traffic.
This may lead to incorrect policy building suggestions or a partial denial-of-service (DoS).
Affected software
BIG-IQ Centralized Management
Enterprise Manager
BIG-IP ASM
How to mitigate CVE-2019-6665
BIG-IP ASM - addressed in versions 13.1.3.2, 14.0.1.1, 14.1.2.1, 15.0.1.1