PT-2017-16917 · F5 · F5 Big-Ip

Published

2017-10-27

·

Updated

2019-10-03

·

CVE-2017-6157

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP software versions 11.5.0 through 11.5.4 F5 BIG-IP software versions 11.6.0 through 11.6.1 F5 BIG-IP software versions 12.0.0 through 12.1.1
Description The issue affects F5 BIG-IP systems with virtual servers configured using the HTTP Explicit Proxy functionality and/or SOCKS profile, allowing an unauthenticated, remote attack. This attack can lead to modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the BIG-IP system.
Recommendations For versions 11.5.0 through 11.5.4, update to a version outside of this range to resolve the issue. For versions 11.6.0 through 11.6.1, update to a version outside of this range to resolve the issue. For versions 12.0.0 through 12.1.1, update to a version outside of this range to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-6157

Affected Products

F5 Big-Ip