PT-2019-6465 · F5+1 · F5 Big-Ip Application Security Manager+1
CVE-2019-12168
·
Publicado
2019-05-17
·
Atualizado
2024-09-21
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Four-Faith Wireless Mobile Router F3x24 version 1.0
F5 BIG-IP Application Security Manager versions prior to 14.1.4.6
F5 BIG-IP Application Security Manager versions prior to 15.1.5.1
Description
The issue is related to a lack of authorization in the software of Four-Faith F3x24 routers, which can allow a remote attacker to execute arbitrary code. The vulnerability can be exploited via the Command Shell screen, also known as Administration > Commands.
Recommendations
For Four-Faith Wireless Mobile Router F3x24 version 1.0, consider disabling remote access to the Command Shell until a patch is available.
For F5 BIG-IP Application Security Manager versions prior to 14.1.4.6, update to version 14.1.4.6 or later.
For F5 BIG-IP Application Security Manager versions prior to 15.1.5.1, update to version 15.1.5.1 or later.
Exploit
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
F5 Big-Ip Application Security Manager
Four-Faith Wireless Mobile Router F3X24