PT-2019-18261 · F5 · Big-Ip

Published

2019-12-23

·

Updated

2020-01-02

·

CVE-2019-6679

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions BIG-IP versions 11.5.9 through 11.5.10 BIG-IP versions 11.6.4 through 11.6.5 BIG-IP versions 12.1.4.1 through 12.1.5 BIG-IP versions 13.1.1.5 through 13.1.3.1 BIG-IP versions 14.0.0.5 through 14.0.1 BIG-IP versions 14.1.0.2 through 14.1.2.2 BIG-IP versions 15.0.0 through 15.0.1
Description The issue arises from improper enforcement of access controls for paths that are symlinks, as implemented by scp.whitelist and scp.blacklist. This allows authenticated users with SCP access to overwrite certain configuration files that would otherwise be restricted.
Recommendations For BIG-IP versions 11.5.9 through 11.5.10, consider restricting SCP access until a patch is available. For BIG-IP versions 11.6.4 through 11.6.5, consider restricting SCP access until a patch is available. For BIG-IP versions 12.1.4.1 through 12.1.5, consider restricting SCP access until a patch is available. For BIG-IP versions 13.1.1.5 through 13.1.3.1, consider restricting SCP access until a patch is available. For BIG-IP versions 14.0.0.5 through 14.0.1, consider restricting SCP access until a patch is available. For BIG-IP versions 14.1.0.2 through 14.1.2.2, consider restricting SCP access until a patch is available. For BIG-IP versions 15.0.0 through 15.0.1, consider restricting SCP access until a patch is available.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6679

Affected Products

Big-Ip