PT-2017-3145 · F5 · F5 Big-Ip

Publicado

2017-07-13

·

Atualizado

2017-11-15

·

CVE-2017-6145

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 12.0.0 through 12.1.2 F5 BIG-IP versions 13.0.0
Description The issue is related to the iControl REST service in F5 BIG-IP products, which improperly re-validates cookies when converting them to X-F5-Auth-Token tokens. This allows once-valid but now expired cookies to be converted to valid tokens, potentially granting unauthorized access to the iControl REST interface.
Recommendations For versions 12.0.0 through 12.1.2, update to a version outside of this range to resolve the issue. For version 13.0.0, update to a version later than 13.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the iControl REST interface to minimize the risk of exploitation.

Correção

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02557
CVE-2017-6145

Produtos afetados

F5 Big-Ip