Lucene search

K
cveMitreCVE-2015-4637
HistoryJul 16, 2015 - 2:59 p.m.

CVE-2015-4637

2015-07-1614:59:04
CWE-17
CWE-310
mitre
web.nvd.nist.gov
35
f5
big-iq
cloud
device
security
rest api
authentication token
ldap
cve-2015-4637
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

57.6%

The REST API in F5 BIG-IQ Cloud, Device, and Security 4.4.0 and 4.5.0 before HF2 and ADC 4.5.0 before HF2, when configured for LDAP remote authentication and the LDAP server allows anonymous BIND operations, allows remote attackers to obtain an authentication token for arbitrary users by guessing an LDAP user account name.

Affected configurations

Nvd
Node
f5big-iq_adcMatch4.5.0
OR
f5big-iq_cloudMatch4.4.0
OR
f5big-iq_cloudMatch4.5.0
OR
f5big-iq_deviceMatch4.4.0
OR
f5big-iq_deviceMatch4.5.0
OR
f5big-iq_securityMatch4.4.0
OR
f5big-iq_securityMatch4.5.0
VendorProductVersionCPE
f5big-iq_adc4.5.0cpe:2.3:a:f5:big-iq_adc:4.5.0:*:*:*:*:*:*:*
f5big-iq_cloud4.4.0cpe:2.3:a:f5:big-iq_cloud:4.4.0:*:*:*:*:*:*:*
f5big-iq_cloud4.5.0cpe:2.3:a:f5:big-iq_cloud:4.5.0:*:*:*:*:*:*:*
f5big-iq_device4.4.0cpe:2.3:a:f5:big-iq_device:4.4.0:*:*:*:*:*:*:*
f5big-iq_device4.5.0cpe:2.3:a:f5:big-iq_device:4.5.0:*:*:*:*:*:*:*
f5big-iq_security4.4.0cpe:2.3:a:f5:big-iq_security:4.4.0:*:*:*:*:*:*:*
f5big-iq_security4.5.0cpe:2.3:a:f5:big-iq_security:4.5.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

57.6%

Related for CVE-2015-4637