Lucene search

K
cveF5CVE-2017-6167
HistoryDec 21, 2017 - 5:29 p.m.

CVE-2017-6167

2017-12-2117:29:00
CWE-362
f5
web.nvd.nist.gov
41
f5
big-ip
ltm
aam
afm
analytics
apm
asm
dns
link controller
pem
websafe
cve-2017-6167
icontrol rest
privilege level
race conditions
command execution
security vulnerability
nvd

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

35.4%

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to commands being executed with different privilege levels than expected.

Affected configurations

Nvd
Node
f5big-ip_local_traffic_managerRange12.1.012.1.2
OR
f5big-ip_local_traffic_managerMatch13.0.0
Node
f5big-ip_application_acceleration_managerRange12.1.012.1.2
OR
f5big-ip_application_acceleration_managerMatch13.0.0
Node
f5big-ip_advanced_firewall_managerRange12.1.012.1.2
OR
f5big-ip_advanced_firewall_managerMatch13.0.0
Node
f5big-ip_analyticsRange12.1.012.1.2
OR
f5big-ip_analyticsMatch13.0.0
Node
f5big-ip_access_policy_managerRange12.1.012.1.2
OR
f5big-ip_access_policy_managerMatch13.0.0
Node
f5big-ip_application_security_managerRange12.1.012.1.2
OR
f5big-ip_application_security_managerMatch13.0.0
Node
f5big-ip_dnsRange12.1.012.1.2
OR
f5big-ip_dnsMatch13.0.0
Node
f5big-ip_link_controllerRange12.1.012.1.2
OR
f5big-ip_link_controllerMatch13.0.0
Node
f5big-ip_policy_enforcement_managerRange12.1.012.1.2
OR
f5big-ip_policy_enforcement_managerMatch13.0.0
Node
f5big-ip_websafeRange12.1.012.1.2
OR
f5big-ip_websafeMatch13.0.0
VendorProductVersionCPE
f5big-ip_local_traffic_manager*cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
f5big-ip_local_traffic_manager13.0.0cpe:2.3:a:f5:big-ip_local_traffic_manager:13.0.0:*:*:*:*:*:*:*
f5big-ip_application_acceleration_manager*cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
f5big-ip_application_acceleration_manager13.0.0cpe:2.3:a:f5:big-ip_application_acceleration_manager:13.0.0:*:*:*:*:*:*:*
f5big-ip_advanced_firewall_manager*cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
f5big-ip_advanced_firewall_manager13.0.0cpe:2.3:a:f5:big-ip_advanced_firewall_manager:13.0.0:*:*:*:*:*:*:*
f5big-ip_analytics*cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
f5big-ip_analytics13.0.0cpe:2.3:a:f5:big-ip_analytics:13.0.0:*:*:*:*:*:*:*
f5big-ip_access_policy_manager*cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
f5big-ip_access_policy_manager13.0.0cpe:2.3:a:f5:big-ip_access_policy_manager:13.0.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CNA Affected

[
  {
    "product": "BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, WebSafe",
    "vendor": "F5 Networks, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "13.0.0"
      },
      {
        "status": "affected",
        "version": "12.1.0 - 12.1.2"
      }
    ]
  }
]

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

35.4%

Related for CVE-2017-6167