PT-2007-1672 · F5 · F5 Firepass
Published
2007-01-11
·
Updated
2008-09-05
·
CVE-2007-0188
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
F5 FirePass versions 5.4 through 5.5.1
Description
The issue arises from the improper enforcement of host access restrictions when a client uses a single integer representation of an IP address, also known as a "dotless IP address". This allows remote authenticated users to connect to the administrator console and certain other network resources.
Recommendations
For F5 FirePass versions 5.4 through 5.5.1, consider restricting access to the administrator console and other sensitive network resources until a proper fix is applied. As a temporary workaround, restrict the use of dotless IP addresses to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
F5 Firepass