#VU22977 Permissions, Privileges, and Access Controls in F5 Networks products - CVE-2019-6664

 

#VU22977 Permissions, Privileges, and Access Controls in F5 Networks products - CVE-2019-6664

Published: November 26, 2019


Vulnerability identifier: #VU22977
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-6664
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
BIG-IP
BIG-IP LTM
BIG-IP AFM
BIG-IP Analytics
BIG-IP APM
BIG-IP ASM
BIG-IP FPS
BIG-IP GTM
BIG-IP PEM
BIG-IP AAM
BIG-IP DNS
BIG-IP Edge Gateway
BIG-IP Link Controller
BIG-IP WebAccelerator
Software vendor:
F5 Networks

Description

The vulnerability allows a remote attacker to gain access to otherwise restricted functionality.

The vulnerability exists due to network protections on the management port do not follow current best practices, under certain conditions. The default firewall rules for the management interface are not reliably reinstalled after first boot. As a result, a remote attacker can expose the management interface.


Remediation

Install updates from vendor's website.

External links