Description
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and 7.x, an authenticated, high-privileged attacker with no bash access may be able to access Certificate and Key files using Secure Copy (SCP) protocol from a remote system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- F5 / BIG-IP12.1.x – 12.1.x
- F5 / BIG-IP11.6.x – 11.6.x
- F5 / BIG-IP17.0.0 – 17.0.x*
- F5 / BIG-IP16.1.x – 16.1.2.2
- F5 / BIG-IP15.1.x – 15.1.5.1
- F5 / BIG-IP14.1.x – 14.1.4.6
- F5 / BIG-IP13.1.x – 13.1.5
- F5 / BIG-IQ Centralized Management8.x – 8.x
- F5 / BIG-IQ Centralized Management7.x – 7.x