PT-2018-12973 · F5 · F5 Big-Iq+3

Published

2018-12-12

·

Updated

2019-01-09

·

CVE-2018-15328

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 11.x through 14.0.x F5 Enterprise Manager version 3.1.1 F5 BIG-IQ versions 4.x through 6.x F5 iWorkflow version 2.x
Description The issue concerns the handling of passphrases for SNMPv3 users and trap destinations used for authentication and privacy. These passphrases are not protected by the Secure Vault feature of the BIG-IP system and are instead written in plain text to various configuration files.
Recommendations For F5 BIG-IP versions 11.x through 14.0.x, consider restricting access to configuration files to minimize the risk of passphrase exposure. For F5 Enterprise Manager version 3.1.1, restrict access to the configuration files that contain the passphrases. For F5 BIG-IQ versions 4.x through 6.x, limit access to the areas where the passphrases are stored in plain text. For F5 iWorkflow version 2.x, avoid using the affected SNMPv3 functionality until a secure method of handling passphrases is implemented.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15328

Affected Products

F5 Big-Ip
F5 Big-Iq
F5 Enterprise Manager
F5 Iworkflow