Lucene search

K
f5F5F5:K11330536
HistoryJul 01, 2019 - 12:00 a.m.

K11330536 : BIG-IP Appliance mode vulnerability CVE-2019-6635

2019-07-0100:00:00
my.f5.com
16

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.9%

Security Advisory Description

When the BIG-IP system is licensed for Appliance mode, a user with either the Administrator or the Resource Administrator role can bypass Appliance mode restrictions. (CVE-2019-6635)

Impact

BIG-IP

This vulnerability allows local attackers with high-level privileges to overwrite arbitrary files. This behavior is possible only when the BIG-IP system runs in Appliance mode on any of the hardware platforms, and the user account is configured with Administrator or Resource Administrator role. Resource Administrator roles must have TMOS Shell (tmsh) access to perform the attack. Appliance mode is a licensed feature. This vulnerability does not affect the virtual platforms.

Enterprise Manager / BIG-IQ / F5 iWorkflow / Traffix SDC

There is no impact; F5 products are not affected by this vulnerability.

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.9%

Related for F5:K11330536