PT-2018-12979 · F5 · Big-Ip

Publicado

2018-12-28

·

Atualizado

2019-10-23

·

CVE-2018-15333

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 11.2.1 and greater
Description The issue allows a BIG-IP system's user with any role, including the Guest Role, to access and download previously generated snapshot files, such as QKView and TCPDumps, through unrestricted Snapshot File Access in the BIG-IP configuration utility.
Recommendations For versions 11.2.1 and greater, restrict access to the Snapshot File Access feature to minimize the risk of unauthorized access to sensitive files. Consider limiting the roles that can access snapshot files to only those that require it, and remove access for the Guest Role.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-15333

Produtos afetados

Big-Ip