Security restrictions bypass in BIG-IP - CVE-2016-5700
Published: September 30, 2016 / Updated: April 2, 2018
Vulnerability identifier: #VU697
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-5700
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: F5 Networks
Affected software:
BIG-IP
BIG-IP
Detailed vulnerability description
The vulnerability allows a remote unauthenticated user to cause arbitrary commands execution on the target system.
The weakness exists due to access control error and affects BIG-IP virtual servers with a configuration using the HTTP Explicit Proxy functionality and/or SOCKS profile. Such flaw allows a malicious user to trigger modification of BIG-IP system configuration, information disclosure that may lead to arbitrary commands execution.
Successful exploitation of the vulnerability may result in certain consequences including arbitrary commands execution on the vulnerable system.
The weakness exists due to access control error and affects BIG-IP virtual servers with a configuration using the HTTP Explicit Proxy functionality and/or SOCKS profile. Such flaw allows a malicious user to trigger modification of BIG-IP system configuration, information disclosure that may lead to arbitrary commands execution.
Successful exploitation of the vulnerability may result in certain consequences including arbitrary commands execution on the vulnerable system.
How to mitigate CVE-2016-5700
Update to 12.1.1.