Lucene search

K
cveF5CVE-2019-6654
HistorySep 25, 2019 - 7:15 p.m.

CVE-2019-6654

2019-09-2519:15:10
CWE-20
f5
web.nvd.nist.gov
34
cve-2019-6654
big-ip
martian address filtering
rfc 1812
spoofed source addresses
nvd
security advisory

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:A/AC:L/Au:N/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

25.0%

On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian Address Filtering (As defined in RFC 1812 section 5.3.7) on the control plane (management interface). This may allow attackers on an adjacent system to force BIG-IP into processing packets with spoofed source addresses.

Affected configurations

Nvd
Node
f5big-ip_local_traffic_managerRange11.5.111.6.5
OR
f5big-ip_local_traffic_managerRange12.1.012.1.5
OR
f5big-ip_local_traffic_managerRange13.0.013.1.3
OR
f5big-ip_local_traffic_managerRange14.0.014.1.2
Node
f5big-ip_advanced_firewall_managerRange11.5.111.6.5
OR
f5big-ip_advanced_firewall_managerRange12.1.012.1.5
OR
f5big-ip_advanced_firewall_managerRange13.0.013.1.3
OR
f5big-ip_advanced_firewall_managerRange14.0.014.1.2
Node
f5big-ip_application_acceleration_managerRange11.5.111.6.5
OR
f5big-ip_application_acceleration_managerRange12.1.012.1.5
OR
f5big-ip_application_acceleration_managerRange13.0.013.1.3
OR
f5big-ip_application_acceleration_managerRange14.0.014.1.2
Node
f5big-ip_analyticsRange11.5.111.6.5
OR
f5big-ip_analyticsRange12.1.012.1.5
OR
f5big-ip_analyticsRange13.0.013.1.3
OR
f5big-ip_analyticsRange14.0.014.1.2
Node
f5big-ip_access_policy_managerRange11.5.111.6.5
OR
f5big-ip_access_policy_managerRange12.1.012.1.5
OR
f5big-ip_access_policy_managerRange13.0.013.1.3
OR
f5big-ip_access_policy_managerRange14.0.014.1.2
Node
f5big-ip_application_security_managerRange11.5.111.6.5
OR
f5big-ip_application_security_managerRange12.1.012.1.5
OR
f5big-ip_application_security_managerRange13.0.013.1.3
OR
f5big-ip_application_security_managerRange14.0.014.1.2
Node
f5big-ip_edge_gatewayRange11.5.111.6.5
OR
f5big-ip_edge_gatewayRange12.1.012.1.5
OR
f5big-ip_edge_gatewayRange13.0.013.1.3
OR
f5big-ip_edge_gatewayRange14.0.014.1.2
Node
f5big-ip_fraud_protection_serviceRange11.5.111.6.5
OR
f5big-ip_fraud_protection_serviceRange12.1.012.1.5
OR
f5big-ip_fraud_protection_serviceRange13.0.013.1.3
OR
f5big-ip_fraud_protection_serviceRange14.0.014.1.2
Node
f5big-ip_global_traffic_managerRange11.5.111.6.5
OR
f5big-ip_global_traffic_managerRange12.1.012.1.5
OR
f5big-ip_global_traffic_managerRange13.0.013.1.3
OR
f5big-ip_global_traffic_managerRange14.0.014.1.2
Node
f5big-ip_link_controllerRange11.5.111.6.5
OR
f5big-ip_link_controllerRange12.1.012.1.5
OR
f5big-ip_link_controllerRange13.0.013.1.3
OR
f5big-ip_link_controllerRange14.0.014.1.2
Node
f5big-ip_policy_enforcement_managerRange11.5.111.6.5
OR
f5big-ip_policy_enforcement_managerRange12.1.012.1.5
OR
f5big-ip_policy_enforcement_managerRange13.0.013.1.3
OR
f5big-ip_policy_enforcement_managerRange14.0.014.1.2
Node
f5big-ip_webacceleratorRange11.5.111.6.5
OR
f5big-ip_webacceleratorRange12.1.012.1.5
OR
f5big-ip_webacceleratorRange13.0.013.1.3
OR
f5big-ip_webacceleratorRange14.0.014.1.2
Node
f5big-ip_domain_name_systemRange11.5.111.6.5
OR
f5big-ip_domain_name_systemRange12.1.012.1.5
OR
f5big-ip_domain_name_systemRange13.0.013.1.3
OR
f5big-ip_domain_name_systemRange14.0.014.1.2
VendorProductVersionCPE
f5big-ip_local_traffic_manager*cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
f5big-ip_advanced_firewall_manager*cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
f5big-ip_application_acceleration_manager*cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
f5big-ip_analytics*cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
f5big-ip_access_policy_manager*cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
f5big-ip_application_security_manager*cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
f5big-ip_edge_gateway*cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
f5big-ip_fraud_protection_service*cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
f5big-ip_global_traffic_manager*cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
f5big-ip_link_controller*cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CNA Affected

[
  {
    "product": "BIG-IP",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, 11.5.1-11.6.5"
      }
    ]
  }
]

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:A/AC:L/Au:N/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

25.0%

Related for CVE-2019-6654