PT-2017-10510 · F5 · F5 Ssl Intercept Iapp+1
Published
2017-04-06
·
Updated
2019-10-03
·
CVE-2017-0305
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
F5 SSL Intercept iApp versions 1.5.0 through 1.5.7
Description
The issue allows for an unauthenticated, remote attack. This may enable modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deployed using the Explicit Proxy feature plus SNAT Auto Map option for egress traffic.
Recommendations
For F5 SSL Intercept iApp versions 1.5.0 through 1.5.7, consider disabling the Explicit Proxy feature with SNAT Auto Map option for egress traffic until a patch is available. Restrict access to sensitive system files and configuration to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Big-Ip
F5 Ssl Intercept Iapp