Lucene search

K
cveMitreCVE-2008-6474
HistoryMar 16, 2009 - 4:30 p.m.

CVE-2008-6474

2009-03-1616:30:00
CWE-94
mitre
web.nvd.nist.gov
29
2
f5
big-ip
cve-2008-6474
code injection
remote authentication
nvd

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.003

Percentile

68.9%

The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings related to Perl EP3 with templates, probably triggering static code injection.

Affected configurations

Nvd
Node
f5tmosMatch9.4.3
VendorProductVersionCPE
f5tmos9.4.3cpe:2.3:o:f5:tmos:9.4.3:*:*:*:*:*:*:*

Social References

More

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.003

Percentile

68.9%

Related for CVE-2008-6474