PT-2019-18199 · F5 · F5 Big-Ip

Rich Mirch

·

Published

2019-05-03

·

Updated

2023-02-16

·

CVE-2019-6617

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 11.5.2 through 11.5.8 F5 BIG-IP versions 11.6.1 through 11.6.3.4 F5 BIG-IP versions 12.1.0 through 12.1.4 F5 BIG-IP versions 13.0.0 through 13.1.1.4 F5 BIG-IP versions 14.0.0 through 14.1.0.1
Description A user with the Resource Administrator role can overwrite sensitive low-level files, such as /etc/passwd, using SFTP to modify user permissions without Advanced Shell access. This is contrary to the definition for the Resource Administrator role restrictions.
Recommendations For F5 BIG-IP versions 11.5.2 through 11.5.8, restrict SFTP access for users with the Resource Administrator role to prevent modification of sensitive files. For F5 BIG-IP versions 11.6.1 through 11.6.3.4, restrict SFTP access for users with the Resource Administrator role to prevent modification of sensitive files. For F5 BIG-IP versions 12.1.0 through 12.1.4, restrict SFTP access for users with the Resource Administrator role to prevent modification of sensitive files. For F5 BIG-IP versions 13.0.0 through 13.1.1.4, restrict SFTP access for users with the Resource Administrator role to prevent modification of sensitive files. For F5 BIG-IP versions 14.0.0 through 14.1.0.1, restrict SFTP access for users with the Resource Administrator role to prevent modification of sensitive files.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2019-6617

Affected Products

F5 Big-Ip