PT-2017-2231 · F5 · F5 Big-Ip
Published
2017-05-23
·
Updated
2017-07-08
·
CVE-2017-6131
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 12.0.0 through 12.1.2
F5 BIG-IP versions 13.0.0
Description
The issue arises due to insufficient protection of registration data, which could allow an attacker to remotely access the BIG-IP host via SSH. This affects various BIG-IP components, including Application Security Manager, Access Policy Manager, Link Controller, Policy Enforcement Manager, Local Traffic Manager, DNS, WebSafe, Advanced Firewall Manager, and Application Acceleration Manager. The impacted administrative account is the Azure instance administrative user created at deployment, while the root and admin accounts are not vulnerable.
Recommendations
For F5 BIG-IP versions 12.0.0 through 12.1.2, consider changing the default administrative password to prevent unauthorized access.
For F5 BIG-IP version 13.0.0, change the default administrative password to mitigate the risk of remote access via SSH.
As a temporary workaround, restrict SSH access to the BIG-IP host until the default password is changed.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F5 Big-Ip