Lucene search

K
f5F5F5:K55655944
HistoryNov 25, 2019 - 12:00 a.m.

K55655944 : BIG-IP Engineering Hotfix authentication bypass vulnerability CVE-2019-6675

2019-11-2500:00:00
my.f5.com
17

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

53.0%

Security Advisory Description

BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in a complete compromise of the system. This issue only impacts specific engineering hotfixes using the aforementioned authentication configuration. (CVE-2019-6675)

Impact

Remote users authenticating to the BIG-IP system using LDAP, Active Directory, or Client Certificate LDAP are able to log in with incorrect credentials resulting in a complete compromise of the BIG-IP system.

Important: This vulnerability impacts only BIG-IP Engineering Hotfixes you obtained from F5 Support. Refer to the table in the following section for the list of affected versions. To verify if you are running an affected version from this list, perform the procedure in theRecommended Actions section. This vulnerability does not affect any of the BIG-IP major, minor, or maintenance releases you obtained from downloads.f5.com.

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

53.0%

Related for F5:K55655944