Privilege escalation in F5 Networks products - CVE-2016-9251
Published: May 12, 2017
Vulnerability identifier: #VU6530
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9251
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to gain elevated privileges on the target system.
The weakness exists due to insufficient security controls. A remote attacker can use a specially crafted iControl REST connection, gain elevated privileges and conduct further attacks.
Successful exploitation of the vulnerability may result in access to the system.
The weakness exists due to insufficient security controls. A remote attacker can use a specially crafted iControl REST connection, gain elevated privileges and conduct further attacks.
Successful exploitation of the vulnerability may result in access to the system.
Affected software
BIG-IP WebSafe
BIG-IP DNS
BIG-IP Link Controller
BIG-IP AAM
BIG-IP ASM
BIG-IP APM
BIG-IP LTM
BIG-IP Analytics
BIG-IP AFM
BIG-IP PEM
BIG-IP DNS
BIG-IP Link Controller
BIG-IP AAM
BIG-IP ASM
BIG-IP APM
BIG-IP LTM
BIG-IP Analytics
BIG-IP AFM
BIG-IP PEM
How to mitigate CVE-2016-9251
Install update from vendor's website.