PT-2018-12973 · F5 · F5 Big-Iq+3
Published
2018-12-12
·
Updated
2019-01-09
·
CVE-2018-15328
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 11.x through 14.0.x
F5 Enterprise Manager version 3.1.1
F5 BIG-IQ versions 4.x through 6.x
F5 iWorkflow version 2.x
Description
The issue concerns the handling of passphrases for SNMPv3 users and trap destinations used for authentication and privacy. These passphrases are not protected by the Secure Vault feature of the BIG-IP system and are instead written in plain text to various configuration files.
Recommendations
For F5 BIG-IP versions 11.x through 14.0.x, consider restricting access to configuration files to minimize the risk of passphrase exposure.
For F5 Enterprise Manager version 3.1.1, restrict access to the configuration files that contain the passphrases.
For F5 BIG-IQ versions 4.x through 6.x, limit access to the areas where the passphrases are stored in plain text.
For F5 iWorkflow version 2.x, avoid using the affected SNMPv3 functionality until a secure method of handling passphrases is implemented.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F5 Big-Ip
F5 Big-Iq
F5 Enterprise Manager
F5 Iworkflow